Security Resilience Challenges of Operators of essential services, applying Health and Safety success to them, then Dorset Branch AGM
Speaker
Cevn “Kev” Vibert
Agenda
18:30 - Start of presentation
19:30 - Estimated Finish of presentation
19:30 - Start of Dorset Branch AGM
20:30 - Estimated Finish of Dorset Branch AGM
Synopsis
Operators of Essential Services face an unusual cyber-security challenge. They must protect systems on which society depends, maintain safe and resilient operations, manage ageing and modern operational technology, satisfy regulatory expectations and, at the same time, continue running the business.
In this BCS presentation, Cevn “Kev” Vibert draws on his experience of industrial cyber security, critical infrastructure and NIS assurance to explore what cyber security and resilience look like when regulation, engineering and operational reality collide. His background includes establishing the UK NIS inspection programme for downstream gas and electricity and leading early NIS OT cyber inspections. The talk looks beyond the question “Are we compliant?” towards the much more important questions: Are we genuinely secure? Are we resilient? And could we demonstrate it? Using lessons and recurring themes from his career in industrial automation, OT cyber security, regulatory assurance and critical infrastructure, Cevn Vibert will examine the organisational and technical weaknesses that repeatedly undermine otherwise well-intentioned cyber-security programmes.
His work encompasses governance, risk management, compliance, audits, threat, risk and impact assessment, resilience and operational technology across sectors including energy, manufacturing, utilities, transport, nuclear, oil and gas, water and rail. The session will put NIS and the NCSC Cyber Assessment Framework (CAF) into practical perspective and consider the relationship between regulatory compliance, assurance and real operational resilience. The current draft also proposes discussion of forthcoming UK cyber-security and resilience legislation. Rather than presenting compliance as an end in itself, Cevn Vibert will challenge some familiar assumptions and excuses and explore what effective assurance can reveal about an organisation.
The evening will consider:
- why compliance and security are related, but are not the same thing
- what an experienced assessor looks for beyond policies and documentation
- recurring organisational and OT security weaknesses
- what NIS and CAF mean in practice for Operators of Essential Services
- why governance, people, process and technology all matter
- how assurance can become a tool for improvement rather than simply an exercise in satisfying an auditor
- what better cyber resilience could look like.
The presentation concludes with an open Q&A and discussion, giving participants an opportunity to explore the practical challenges of cyber assurance, regulation and operational resilience.
About the speakers
Cevn “Kev” Vibert 
Cevn “Kev” Vibert is an industrial cyber-security and NIS specialist with extensive experience spanning operational technology, critical infrastructure, regulatory assurance, governance, risk and resilience. Through Vibert Ltd, he provides senior and board-level OT cyber and NIS advisory, consultancy, training, compliance and assurance services. His experience spans critical national infrastructure and sectors including energy, manufacturing, utilities, transport, pharmaceutical, nuclear, oil and gas, water and rail. A former Principal Assurance specialist within the Ofgem NIS Competent Authority, Cevn Vibert established the UK NIS inspection programme for downstream gas and electricity and led early NIS OT cyber inspections. He has also trained NIS inspectors across Competent Authorities in multiple sectors. His wider career includes work as an OT cyber and Critical National Infrastructure specialist with Thales UK.
He is a Chartered Cyber Professional, Chartered IT Professional and Chartered Engineer, and a Fellow of BCS, the IET and the Institute of Measurement and Control. He was founding Chair of the InstMC Cyber SIG and was involved in the Cyber Alliance associated with the formation of the UK Cyber Security Council. Cevn Vibert also participates in industry and NCSC community discussions concerning critical-infrastructure cyber security and developing UK cyber-security and resilience policy.
His approach combines regulatory and assurance experience with the perspective of an engineer who has spent decades working with industrial information, automation and operational systems. The Vibert Ltd site describes more than 30 years' experience advising organisations and boards across IT, emergency management, situational awareness, industrial automation, MES, ICS information systems and critical-infrastructure protection.
Our events are for adults aged 16 years and over.
This meeting is conducted in accordance with the BCS Code of Conduct for Meetings.
BCS is a membership organisation. If you enjoy this event, please consider joining BCS. You’ll be very welcome. You’ll receive access to many exclusive career development tools, an introduction to a thriving professional community and also help us Make IT Good For Society. Join BCS today
Please note: if you have any accessibility needs, please let us know via groups@bcs.uk, and we’ll work with you to make suitable arrangements.
This event is brought to you by: Dorset branch