Do aliens exist? If so, why have we not had a confirmed visit? Why have there been so few examples of cyber attacks on ICS? We’ve seen examples of inadequate ICS cybersecurity’s harmful potential with the Ukrainian power hack in December 2015. It is likely similar attacks have achieved success, but remain unpublicized due to the lack of a disclosure mandate or other reasons. How do we keep our power plants and industrial facilities – as well as the people that rely on them – safe and secure? In this session, we’ll discuss what is missing from most ICS cybersecurity approaches today and best practices for mitigating cyber risk, whether from malicious attack or inadvertent engineering mistakes. We will focus specifically on gaining visibility into configuration information within proprietary control systems and smart field instrumentation. With configuration data that covers I/O cards, firmware, control logic, and more; we will describe how you can automatically detect unauthorized changes, identify vulnerabilities, and close the loop on patch management for this unique, proprietary class of endpoints. Finally, we’ll provide a case study of how one major energy company is taking measures today to ensure safe, secure, and compliant operations well into the future.