Save the date

The Inaugural Virtual AF OT Summit - 2026

Hosted by AfricaCERT: three days of hands-on operational technology security training, followed by a full day of talks on securing Africa's industrial and critical infrastructure.

SEP 1–4, 2026·100% VIRTUAL·PAN-AFRICAN AUDIENCE

Event overview

Bringing OT security practice to a continental audience

As digitalization reaches deeper into Africa's power, water, manufacturing, and transport systems, dependence on industrial control systems and the networks that connect them keeps growing, and so does the exposure that comes with it. Left unmanaged, this exposure becomes an operational and safety risk, not just an IT problem.

The Virtual AF OT Summit brings together OT/ICS engineers, CERT/CSIRT teams, infrastructure operators, researchers, and policymakers from across the continent for three days of practical training and a full day of talks, building the shared knowledge and coordination the region still lacks.

Why this matters now

Limited ICT and OT security literacy across much of the workforce
Few countries have dedicated legal or regulatory frameworks for OT security
Many states still lack a dedicated cybersecurity structure for industrial systems
No shared regional framework for coordinating strategy or incident response

1–4 September 2026 · Online

Program

Four days of hands-on training and tutorials across two tracks, followed by plenary sessions on 4 September. All times are given in UTC and US Central.

  1. Day 1
    ICS / OT Track

    10:00 – 15:00 UTC 05:00 – 10:00 US Central

    Introduction to Incident Response in OT/ICS Environments

    Training · Day 1 of 3

    Course outline
    Threat Intelligence sessions begin on Day 2.
  2. Day 2
    ICS / OT Track

    10:00 – 15:00 UTC 05:00 – 10:00 US Central

    Introduction to Incident Response in OT/ICS Environments

    Continued · Day 2 of 3

    Course outline
    Threat Intelligence

    15:00 – 16:30 UTC 10:00 – 11:30 US Central

    Africa Industrial Control Systems (ICS): IT/OT Threat Landscape 2026

    RESECURITY and AfricaCERT

    Read the abstract
  3. Day 3 Training and tutorials conclude; plenaries open.
    ICS / OT Track

    10:00 – 15:00 UTC 05:00 – 10:00 US Central

    Introduction to Incident Response in OT/ICS Environments

    Continued · Day 3 of 3

    Course outline
    Threat Intelligence

    15:00 – 16:30 UTC 10:00 – 11:30 US Central

    Turning Cyber Threat Intelligence into Detections

    Tutorial · MITRE Center for Threat-Informed Defense

    Read the abstract
    Plenaries

    Times to be announced

    Plenary sessions

    Full agenda published soon.

  4. Day 4 Plenary talks · speaker names to be announced separately.
    Plenaries

    08:00 – 09:00 UTC03:00 – 04:00 US Central

    Secretariat online

    Plenaries

    09:00 – 09:30 UTC04:00 – 04:30 US Central

    Using SOC CMM to Assess and Mature OT SOCs

    TLP:CLEAR
    Plenaries

    09:30 – 10:00 UTC04:30 – 05:00 US Central

    Regulation and Policy

    TLP:CLEAR
    Plenaries

    10:00 – 10:45 UTC05:00 – 05:45 US Central

    Scaling Industrial Cybersecurity: Reusable IEC 62443 Templates for Critical Infrastructure Expansion

    TLP:CLEAR
    Plenaries

    10:00 – 10:45 UTC05:00 – 05:45 US Central

    When IT Meets OT: Building Cyber Resilience That Works in Africa’s Critical Infrastructure

    Aviation cyber threat landscape

    TLP:AMBER
    Plenaries

    10:45 – 11:30 UTC05:45 – 06:30 US Central

    Should Africa Copy and Paste OT Cybersecurity Regulations.

    TLP:CLEAR
    11:30 – 11:45 UTC (06:30 – 06:45 US Central) · Health / coffee break
    Plenaries

    11:45 – 12:15 UTC06:45 – 07:15 US Central

    Protecting Africa’s Critical Infrastructure in the Era of IT/OT Convergence – Bridging EU Regulatory Framework and African Realities through CR-360

    TLP:CLEAR
    Plenaries

    12:15 – 13:00 UTC07:15 – 08:00 US Central

    Leading Secure and Cyber Resilient Engineering Operations

    TLP:CLEAR
    13:00 – 13:30 UTC (08:00 – 08:30 US Central) · Lunch break
    Plenaries

    13:30 – 14:00 UTC08:30 – 09:00 US Central

    Defending the Power Grid Against Modern Cyber Threats

    TLP:CLEAR
    Plenaries

    14:00 – 14:45 UTC09:00 – 09:45 US Central

    When IT Meets OT: Building Cyber Resilience That Works in Africa’s Critical Infrastructure

    TLP:CLEAR
    Plenaries

    14:45 – 15:30 UTC09:45 – 10:30 US Central

    From CII Mandate to Control-Room Resilience

    A Practical Africa-Wide Baseline for OT Assurance, Incident Coordination and Recovery

    TLP:CLEAR
    Plenaries

    15:15 – 15:45 UTC10:15 – 10:45 US Central

    AI in OT: Unlocking Innovation and Intelligence Without Losing Control

    TLP:CLEAR
    Plenaries

    15:15 – 15:45 UTC10:15 – 10:45 US Central

    IT/OT Convergence: Securing Critical Infrastructure in the Digital Era

    TLP:GREEN
    Plenaries

    15:45 – 16:00 UTC10:45 – 11:00 US Central

    Closing remarks & next steps

    TLP 2.0 definitions per first.org/tlp.

Session details

Training — Introduction to Incident Response in OT/ICS Environments

ICS / OT Track · 1–3 September 2026 · 10:00–15:00 UTC (05:00–10:00 US Central)

Cyberattacks affecting OT/ICS operations increase every year, and an incident is a question of when rather than if. Most teams are not prepared for what to do when one happens. These environments are complex, but defending them — and responding to incidents in them — does not have to be. IT and OT incident response share a lot at a high level, yet the differences matter: understanding them is what lets a team bring the plant back up quickly while keeping everyone safe.

Course modules

  1. Module 1 Course Introduction
    • About the instructor
    • Why we are here
    • Goals of the course
    • Course materials and other resources
  2. Module 2 Incident Response Overview
    • Where do we start?
    • Case study: Unitronics vs Cyber Av3ngers
    • The PICERL process end to end
  3. Module 3 Preparation
    • Asset inventory and visibility
    • Defining the incident response team
    • The B.A.S.I.C.s of OT/ICS cybersecurity
    • Building your OT incident response program
    • Retainer services for incident response
    • Designing and running a tabletop exercise (TTX)
  4. Module 4 Identification
    • Detecting network and host anomalies in OT
    • Analysing industrial protocols (Modbus, EtherNet/IP, S7, DNP3)
    • OT network log collection and correlation
    • Root cause analysis: cyber vs mechanical
    • Declaring and rating an OT cybersecurity incident
  5. Module 5 Containment
    • Network segmentation
    • Isolating systems without impacting safety
    • Preserving evidence
    • Falling back to manual operations
    • Environment lockdown procedures
  6. Module 6 Eradication
    • Plugging the gaps
    • Removing malware
    • Restoring PLCs from firmware to running logic
    • Validating device integrity
    • Coordinating with vendors and manufacturers
  7. Module 7 Recovery
    • Getting the plant up and running — safely
    • Phased system bring-up
    • Verifying process loops
    • Elevated continuous security monitoring
    • Formal return to full operations
  8. Module 8 Lessons Learned
    • Post-incident review
    • Documenting the timeline
    • Identifying opportunities for improvement
    • Updating the incident response program
    • Sharing and reporting
  9. Module 9 Putting It All Together
    • Tabletop exercise simulation
    • Cross-functional collaboration
    • Applying PICERL to your environment
    • Evaluating team responses
    • Wrap-up and next steps
Africa Industrial Control Systems (ICS): IT/OT Threat Landscape 2026

Threat Intelligence · RESECURITY and AfricaCERT · 2 September 2026 · 15:00–16:30 UTC (10:00–11:30 US Central)

This study evaluates how mature cybersecurity measures are for industrial control system assets across Africa. Adoption of new IT and OT solutions is an emerging driver of market growth as industrial operators look for better visibility and faster threat detection. Adversaries, meanwhile, are increasingly targeting national energy grids, power generation and transmission networks, nuclear facilities, upstream and downstream oil and gas, and mineral mining operators.

Tutorial — Turning Cyber Threat Intelligence into Detections

Threat Intelligence · MITRE Center for Threat-Informed Defense · 3 September 2026 · 15:00–16:30 UTC (10:00–11:30 US Central)

This session shows how to turn rich cyber threat intelligence into concrete, platform-aware detections, using ATT&CK v19 as the backbone. Attendees will see how the newest ATT&CK enhancements reshape the way practitioners map, prioritise and act on adversary behaviours, and how Detection Strategies (DETs), analytics and telemetry make that knowledge operational. The walkthrough covers practical steps for bridging CTI and detection engineering, so that what analysts surface drives directly what defenders design, deploy and measure.

Program subject to change. Speaker names and full session details for 4 September will be added here once confirmed by the Program Committee.

Objectives

What participants can expect

Knowledge exchange

Share best practices and lessons learned in OT/ICS security across Africa and beyond.

Collaboration

Connect incident responders, security teams, and government officials to strengthen collective resilience.

Capacity building

Hands-on training and workshops to build practical OT/ICS skills for engineers and decision-makers.

Policy development

Discuss and shape OT security policy aligned with international standards and regional realities.

Networking

Build lasting partnerships across the African OT/ICS security community and its international peers.

Call for speakers & trainers

Share your OT/ICS expertise

Open to the global community, with preference given to speakers and trainers with regional African experience.

01

ICS/SCADA incident response

02

OT network monitoring & anomaly detection

03

IT/OT convergence & segmentation

04

Vulnerability & patch management for OT

05

Standards & frameworks (IEC 62443, NIST CSF)

06

Policy, regulation & national OT strategy

Submit a proposal

Committee

The people shaping this program

The Advisory and Review team curates the agenda and reviews submissions; the Logistics team coordinates the Summit's operations.

Advisory and Review

JH

Jean-Robert Hountomey

MG

Michelle Govender

SG

Sirajo M Gidalo

SS

Sithembile Sonko

FC

Frank Chibesakunda

CN

Choolwe Nalubamba

CB

Christopher Banda

HA

Hakim Apithy

Logistics

IO

Idah Odeka

GB

Gamuchirai Blessing

Committee closed

Sponsors

Help shape the OT security ecosystem

Sponsorship helps us keep the Summit accessible while putting your brand in front of the decision-makers shaping OT security across the continent, with impact reaching beyond this event as we plan future gatherings, including in person.

Orchestrator
USD 8,000
Integrator
USD 4,000
Operator
USD 2,000
Observer
USD 1,000
Supporter
USD 500
View sponsorship tiers

We gratefully welcome all contributions, donations, and financial support.

Register

Reserve your seat for September 1–4

Registration is free and open to OT/ICS professionals, CERT/CSIRT teams, infrastructure operators, and policymakers across Africa and beyond.

Register interest

We gratefully welcome all contributions, donations, and financial support.