This session focuses on data driven techniques that detect a range of ICS threats without the need for signatures. It will demonstrate detections and alerting of a variety of attacks ranging from service degradation to complete compromise. Mr. Merza will present results and lessons learned from applying these techniques at two utility companies. Data from Historians and PLC's/RTU's are collected, simple statistics as well as predictive analytics are used to detect both security anomalies as well as operational anomalies. Past S4 talks have discussed this approach in theory, but this session will show results from operational systems.