Christopher Hills, Chief Security Strategist at BeyondTrust, brings a focused cybersecurity perspective to the growing challenge of identity and privilege management in operational technology (OT) environments. His session examines how access that is already present within an OT environment can become a critical pathway for attackers, highlighting the importance of understanding identity exposure, privileged access, and security gaps across connected industrial infrastructure.
In his session, “They Didn't Hack In, They Logged In: BeyondTrust on Closing the Identity and Privilege Gaps in OT,” Christopher Hills walks through a phase-by-phase attack chain from 2026, examining how access and privilege gaps can contribute to significant OT security incidents. The discussion connects a coordinated strike on U.S. critical infrastructure with a separate AI-driven failure that shared the same underlying access-related weakness. The session focuses on five practical control categories that could have disrupted both attack paths without requiring new technology, emphasizing that effective OT cybersecurity is not only about detecting incidents but also about controlling identity, privilege, access, and what happens after a security gap is identified.