Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Webinars
  • Securing Industrial Control Systems: Rethinking Privileged Access in OT and SCADA Environments current page
Link copied

Securing Industrial Control Systems: Rethinking Privileged Access in OT and SCADA Environments

with Derek A. Smith, Founder, National Cybersecurity Education Center; Gayatri Karthy, Product Marketing Manager
Webinars default
Securing Industrial Control Systems: Rethinking Privileged Access in OT and SCADA Environments

Get Instant Access to this Content

Learn more about how to secure your business from threats in places you didn't even know existed.

About the session

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

In IT environments, a security breach means data loss. In OT environments, it can mean equipment damage, production shutdown, or threats to human safety. The security models built for enterprise IT do not translate cleanly to industrial control systems — and applying them incorrectly can cause the very disruptions they are meant to prevent. Drawing on his certified OT/SCADA expertise and federal background, Dr. Smith walked through the privileged access risks specific to ICS and SCADA networks, how threat actors exploit vendor remote sessions and shared device credentials, and how to apply least-privilege principles to OT environments without sacrificing operational continuity.

Key Takeaways

  • How ICS/SCADA environments differ architecturally and operationally from IT — and why it matters for security
  • The top privileged access risk vectors in OT: vendor remote sessions, shared credentials, and persistent connections
  • Why standard IT security controls break in OT environments and what to do instead
  • Applying least-privilege and session governance to industrial control systems without disrupting operations
  • Real-world OT breach case studies and the access control failures that enabled them
  • How organizations are enabling secure, controlled, and auditable remote access to OT environments through Privileged Remote Access (PRA)

Meet the Speakers

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Derek A. Smith
Derek A. Smith
Founder, National Cybersecurity Education Center
Derek A. Smith is an expert at cybersecurity, cyber forensics, healthcare IT, SCADA security, physical security, investigations, organizational leadership and training. He is currently an IT Supervisor at the Internal Revenue Service. He is also owne ... read more

Derek A. Smith is an expert at cybersecurity, cyber forensics, healthcare IT, SCADA security, physical security, investigations, organizational leadership and training. He is currently an IT Supervisor at the Internal Revenue Service. He is also owner of The Intercessors Investigative and Training Group (www.theintercessorgroup.com). Formerly, Derek worked for several IT companies including Computer Sciences Corporation and Booz Allen Hamilton. Derek spent 18 years as a special agent for various government agencies and the military. He is also a cyber security professor at the University of Maryland, University College and Virginia University of Science and Technology and has taught for over 25 years. Derek is retired from the US Army and also served in the US Navy, and Air Force for a total of 24 years. He is completing his Doctorate Degree in Organizational Leadership and has completed an MBA, MS in IT Information Assurance, Masters in IT Project Management, and a BS in Education. Derek has written several books including Cybersense: The Leaders Guide to Protecting Critical Information, and its companion workbook, and he has contributed to several other books as an author and technical adviser.

Derek A. Smith is an expert at cybersecurity, cyber forensics, healthcare IT, SCADA security, physical security, investigations, organizational leadership and training. He is currently an IT Supervisor at the Internal Revenue Service. He is also owne ... read more
Derek A. Smith
Founder, National Cybersecurity Education Center

Derek A. Smith is an expert at cybersecurity, cyber forensics, healthcare IT, SCADA security, physical security, investigations, organizational leadership and training. He is currently an IT Supervisor at the Internal Revenue Service. He is also owner of The Intercessors Investigative and Training Group (www.theintercessorgroup.com). Formerly, Derek worked for several IT companies including Computer Sciences Corporation and Booz Allen Hamilton. Derek spent 18 years as a special agent for various government agencies and the military. He is also a cyber security professor at the University of Maryland, University College and Virginia University of Science and Technology and has taught for over 25 years. Derek is retired from the US Army and also served in the US Navy, and Air Force for a total of 24 years. He is completing his Doctorate Degree in Organizational Leadership and has completed an MBA, MS in IT Information Assurance, Masters in IT Project Management, and a BS in Education. Derek has written several books including Cybersense: The Leaders Guide to Protecting Critical Information, and its companion workbook, and he has contributed to several other books as an author and technical adviser.

×
Gayatri Karthy
Gayatri Karthy
Product Marketing Manager
Gayatri is a Product Marketing Manager at BeyondTrust for Privileged Remote Access. Prior to joining BeyondTrust, she worked across marketing functions, including channel marketing, customer marketing, and product marketing across large multinational ... read more

Gayatri is a Product Marketing Manager at BeyondTrust for Privileged Remote Access. Prior to joining BeyondTrust, she worked across marketing functions, including channel marketing, customer marketing, and product marketing across large multinational corporations and smaller, agile companies. Gayatri currently lives in SF and enjoys traveling, practicing yoga, and watching horror movies in her free time.

Gayatri is a Product Marketing Manager at BeyondTrust for Privileged Remote Access. Prior to joining BeyondTrust, she worked across marketing functions, including channel marketing, customer marketing, and product marketing across large multinational ... read more
Gayatri Karthy
Product Marketing Manager

Gayatri is a Product Marketing Manager at BeyondTrust for Privileged Remote Access. Prior to joining BeyondTrust, she worked across marketing functions, including channel marketing, customer marketing, and product marketing across large multinational corporations and smaller, agile companies. Gayatri currently lives in SF and enjoys traveling, practicing yoga, and watching horror movies in her free time.

×

Recommended Resources

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
On-Demand Webinar
Improving Confidence Beyond SSO and MFA
On-Demand Webinar
Understanding the 2026 Microsoft Vulnerability Landscape: Insights & Expert Panel Discussion
On-Demand Webinar
The Ghost in the Machine (Securing Non-Human Identities)​
Podcasts
Ep. 100 - 100th Episode Celebration!!
Podcasts
Ep. 99 – Breaches, Births and Battling BS // Rob Black
Podcasts
Ep. 98 – From Special Ops to Mob Boss // Dahvid Schloss
Blog
The AWS Bedrock API Keys Security Guide Part 1: Risks, Vulnerabilities, and Attack Techniques
Blog
Mastering the Modern Attack Surface: A Recap of Identity Security Insights Innovation in Q1
Blog
Detecting Hidden Privilege with Machine Learning: Anomaly Detection in BeyondTrust’s True Privilege Graph
Latest
  • The Ghost in the Machine (Securing Non-Human Identities)
    Jun 18, 2026 The Ghost in the Machine (Securing Non-Human Identities)
    Webinar
Related
  • Tech Talk Tuesday: Centralize and Transform Support with BeyondTrust and ServiceNow
    Jun 2, 2023 Tech Talk Tuesday: Centralize and Transform Support with BeyondTrust and ServiceNow
    On-demand we...
Share this Article
  • Link

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.