Join us on a journey through the OT cybersecurity of a fictitious chemical plant in Germany where everything seems under control - until the regulators arrive. The IT team has done its best, the engineers trust their safety systems, and everyone is fairly confident that “nothing serious can happen here.” But as new regulatory demands start landing on the desk, the plant is forced to confront an uncomfortable question: is the plant actually secure, or merely hoping for the best? In this session, we follow a chemical plant as it navigates real European and German cybersecurity regulations, including KAS-51, TRBS 1115-1, and the EU Cyber Resilience Act. Along the way we explore OT risk assessments, safety instrumented systems, hazardous incident reporting and a lot more! Finally, we bring the lessons home to South Africa. As our own regulatory environment continues to develop, what should we copy, what should we avoid, and what should we design differently from the start? Attendees will leave with a practical, story-driven view of how cybersecurity regulation moves from policy documents into control rooms, engineering workshops, audit reports, and national resilience.