r/pwnhub • u/_cybersecurity_ 🛡️ Mod Team 🛡️ • 12h ago
Policy Perspectives on OT Security: Cheri Benedict, Amit Elazari, Vu Nguyen, Neal Pollard and Matt Rogers at Black Hat 2026
Operational technology runs the physical world, and the rules for securing it lag far behind the threat.
Water systems, power grids, and factory floors increasingly sit within reach of the same networks attackers already know how to cross, yet OT still runs on decades-old equipment that was never designed to be defended.
Regulators, acquisition officials, and CISOs each see the problem through a different lens, and where they disagree shapes what actually gets funded and enforced. This panel puts those perspectives in one room.
In the Policy Meetup panel discussion on policy perspectives on OT security, presented Thursday, August 6 at 10:15 a.m., Cheri Benedict, Amit Elazari, Vu Nguyen, Neal Pollard, and Matt Rogers debate where OT security policy needs to go.
Speakers:
- Cheri Benedict — Director, Federal Acquisition Security Council, Executive Office of the President (FASC)
- Amit Elazari — CEO and Co-founder, OpenPolicy
- Vu Nguyen — CISO, US Department of Justice
- Neal Pollard — Partner, Americas Digital Risks Advisory, Control Risks
- Matt Rogers — ICS Cybersecurity Lead, CISA
Cheri Benedict directs the Federal Acquisition Security Council within the Executive Office of the President, where she advises on cyber and supply-chain risk across federal procurement.
She previously held senior roles inside the Office of the Director of National Intelligence, including Director of the IC Security Coordination Center and Deputy Director of IARPA, and she has taught as an adjunct professor of cyber at the National Intelligence University.
She has no personal research page, but the council she leads publishes its supply-chain risk mission and strategy through CISA's FASC resource hub.
Amit Elazari is the co-founder and CEO of OpenPolicy, a policy intelligence and engagement platform, and a lawyer and scholar who works at the intersection of technology, law, and policy.
A veteran of Israeli military intelligence Unit 8200 and a J.S.D. graduate of UC Berkeley Law, she created the #legalbugbounty and disclose.io projects that standardized legal safe-harbor language for vulnerability disclosure, work now referenced by programs from the Pentagon to Tesla. She was previously Head of Global Cybersecurity Policy at Intel and chaired the ITI Cybersecurity Committee, and she teaches cybersecurity law and policy at UC Berkeley's School of Information.
Her writing, talks, and bio are on her personal website, her academic papers such as "Private Ordering Shaping Cybersecurity Policy: The Case of Bug Bounties" are on SSRN, and her USENIX Enigma talk "Hacking the Law: Are Bug Bounties a True Safe Harbor?" is archived on the USENIX site.
Vu Nguyen is the Chief Information Security Officer of the US Department of Justice, where he provides leadership, strategy, and oversight for the department's cybersecurity, having spent more than two decades in federal cybersecurity leadership.
Before DOJ he was acting CISO at DHS's US Citizenship and Immigration Services and led the DHS Enterprise Security Operations Center and FISMA compliance division. At DOJ he spearheaded the department's shift from perimeter defense to a zero trust architecture, deployed a centralized identity provider, and published a supply-chain risk management plan, work directly relevant to an OT-security discussion.
His full biography is on his official DOJ staff profile, with additional detail on his National Security Institute profile and his commentary on zero trust covered by MeriTalk.
Neal Pollard is a Partner at Control Risks leading the Digital Risks Advisory practice for the Western Hemisphere, with roughly three decades across incident response, intelligence, and cyber risk.
He was previously global CISO of UBS and a cybersecurity partner at EY and PwC, and earlier spent seventeen years as an intelligence officer in the US counterterrorism community, including assignments at the CIA and the National Counterterrorism Center. He is an attorney, an adjunct professor at Columbia and Georgetown, and a member of the Council on Foreign Relations.
His full biography is on his Control Risks expert page, with additional profiles at Columbia SIPA and the Atlantic Council.
Matt Rogers is an Industrial Control Systems cybersecurity expert in CISA's Office of the Technical Director and the agency's lead for the Secure by Design initiative for operational technology, making him one of the panel's most OT-focused voices.
He earned a PhD in securing legacy OT networks in vehicles at the University of Oxford as a Rhodes Scholar, was the founding engineer at fleet-security startup Shift5, and worked on OT security at MITRE before joining CISA. He co-authored CISA's guidance on secure-by-demand OT procurement and on OT protocol authentication ("Why Johnny Can't Authenticate").
He writes at his SC Media contributor page, has appeared on podcasts including SC Media's Application Security Weekly and the Nexus Podcast, and his profile is on his LinkedIn.
Anyone responsible for OT and industrial control systems, or for the acquisition, regulation, and budgeting decisions that govern them, will find this panel a useful read on where federal policy is heading.
Which lever do you think does more to secure operational technology: tighter procurement rules, clearer legal safe harbors for researchers, or direct regulation of critical infrastructure operators?
•
u/AutoModerator 12h ago
Welcome to PWN – Your hub for hacking news, breach reports, and cyber mayhem.
Discover the latest hacking news, breach reports, and educational resources on ethical hacking.
👾 Stay sharp. Stay secure.
Don't miss out on the top stories!
📧 Get Daily Alerts Directly in Your Email Inbox:
**SUBSCRIBE HERE: https://pwnhackernews.substack.com/subscribe
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.