Session abstract
What you’ll learn
As software increasingly controls critical infrastructure, the intersection of secure coding and operational technology security has become a defining challenge for engineers. Water treatment systems, once isolated, are now connected through modern software stacks, cloud integrations, and remote access frameworks, expanding the attack surface for adversaries. High profile incidents have demonstrated how vulnerabilities in software and network design can directly impact public health and safety. This work explores how secure software engineering principles can be applied to protect municipal water infrastructure from evolving cyber threats. By integrating defense in depth strategies with modern development practices, engineers can build resilient systems that safeguard operational technology environments without compromising functionality. The discussion highlights practical approaches such as modular network segmentation, secure API design for control systems, and enforcing Zero Trust principles across both IT and OT layers. A key focus is placed on embedding security into the development lifecycle. Techniques including automated threat modeling, continuous monitoring, and anomaly detection using machine learning are examined as part of a proactive security posture. These approaches enable systems to identify abnormal behavior patterns in real time, reducing the risk of ransomware, insider misuse, and unauthorized remote access. The session also emphasizes the importance of aligning engineering practices with established frameworks such as NIST guidelines and industrial cybersecurity standards. Secure authentication mechanisms, encrypted communications, and controlled access pipelines are presented as essential building blocks for modern infrastructure systems. Attendees will gain actionable insights into how software developers and infrastructure engineers can collaborate to design secure, scalable, and resilient systems. Ultimately, protecting water infrastructure is not only a cybersecurity challenge but also a responsibility of the engineering community to ensure reliability, safety, and trust in systems that millions depend on daily.
