Full Report
ISA hosted its third-annual OT Cybersecurity Summit in Brussels, Belgium, on 18-21 June 2025, and what a great event it was!
Analysis Summary
# Industry News: ISA's OT Cybersecurity Summit Highlights Standards and Practical Resilience
## Summary
The International Society of Automation (ISA) successfully hosted its third annual OT Cybersecurity Summit in Brussels, reinforcing the ISA/IEC 62443 standards as central to industrial cybersecurity. Key features included practical training like a ransomware-focused virtual escape room, discussions on integrating AI ethically, and advancements in site-level compliance through the new ISASecure ACSSA program.
## Key Details
- Date: June 18-21, 2025
- Companies Involved: International Society of Automation (ISA), Visco, ISAGCA, ISASecure, Lab539
- Category: Industry Event/Standards Advancement
## The Story
The 2025 ISA OT Cybersecurity Summit in Brussels gathered 250 attendees and 21 sponsors, focusing heavily on actionable insights related to the ISA/IEC 62443 standards. The event featured technical content tracks on threat intelligence and supply chain security. A standout feature was a virtual escape room simulation, developed by Visco, detailing a ransomware attack on an oil and gas unit, providing hands-on training for automation engineers. Keynote speakers emphasized the human element of protection ("protecting people from people") and advocated for pragmatic steps in building resilience, such as beginning with passive asset inventory. Strategic initiatives shared included the ISAGCA's white papers on mapping ISO/IEC 27001/2 to 62443, and the introduction of the forthcoming ISASecure Site Assessment (ACSSA) program aimed at certifying operating site compliance with ISA/IEC 62443.
## Business Impact
### For the Companies Involved
- **ISA/ISAGCA/ISASecure:** The summit successfully promoted their ecosystem—standards (62443), alliance activities, and new assurance programs (ACSSA)—positioning them as central authorities driving OT security maturity globally.
- **Visco:** Gaining significant visibility by programming a highly-rated, immersive training tool, potentially leading to future training engagements or technology licensing.
### For Competitors
- Competitors in the industrial training and standards certification space face pressure to offer equally engaging, standards-aligned, and operationally relevant learning experiences, especially site-level assessment programs, which ISASecure claims to be uniquely addressing.
### For Customers
- Customers gain immediate access to actionable strategies (e.g., starting with asset inventory) and advanced training (escape room), facilitating better security posture development aligned with globally recognized standards. The forthcoming ACSSA program provides a future mechanism for validating facility-level compliance.
### For the Market
- The strong emphasis on standards adoption, paired with practical application (training, site assessment), signals a maturing OT cybersecurity market shifting from theoretical discussions to mandated, measurable compliance. The focus on supply chain security reflects growing enterprise concern over third-party risk.
## Technical Implications
The event underscored the technical convergence of IT and OT frameworks, highlighted by the release of white papers merging ISO/IEC 27001/2 controls with the ISA/IEC 62443 series. The virtual escape room provided a realistic simulation of a serious OT threat (ransomware on an offshore platform), offering practical insight into incident response tailored for industrial control systems, aligning with the ICS4ICS program goals.
## Strategic Analysis
- Market Positioning: ISA solidifies its role as the nexus for OT security governance, linking standards development, regulatory engagement (via ISAGCA panels), and practical assurance/training.
- Competitive Advantage: The upcoming ISASecure Site Assessment (ACSSA) offers a significant differentiator by focusing solely on the operating site's adherence to 62443, a gap many current certifications may not fully cover.
- Challenges: Driving widespread adoption of the new site assessment program and ensuring the ISA/IEC 62443 standards remain agile enough to keep pace with rapidly evolving threats, such as those posed by unmanaged AI integration discussed by keynote speakers.
## Industry Reactions
- **Analyst Opinions:** The consistent positive feedback from international attendees suggests the ISA summit is establishing a reputation as the premier venue for in-depth, peer-to-peer discussion on OT standards implementation, superseding general IT security conferences for industrial audiences.
- **Expert Commentary:** Speakers stressed the urgency of foundational security measures ("Just start somewhere... start with a passive asset inventory"), reinforcing practical, achievable steps over perfect, delayed deployments.
## Future Outlook
- The announcement of the 2026 summit in Prague forecasts continued geographic expansion and commitment to routine industry collaboration. Watch for initial rollouts and early adopters of the ISASecure ACSSA program over the next 12-18 months to gauge its market acceptance relative to existing vendor-centric assurance schemes.
## For Security Professionals
Practitioners gained exposure to advanced standards implementation, practical incident response simulation, and critical guidance on integrating newer concepts like AI governance into existing OT risk management frameworks. The availability of IC32 and IC33 training provides clear pathways for technical skill enhancement in 62443 application.