BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Five Million Industrial Control Systems Walk Into a 
 Bar: What\n   IRONMAP Found When It Scanned the Whole Internet\n   Tags: I
 CS Village | Creator Talk/Panel\n   When: Sunday\, Aug 9\, 10:00 - 10:30 P
 DT\n   Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - [1]Map\n\n   De
 scription:\n\n   What does the global attack surface of operational techno
 logy actually\n   look like at internet scale? We built IRONMAP\, a purpos
 e-built OT/ICS\n   intelligence platform\, to find out — and the answer 
 is both larger\n   and more disturbing than we expected.\n\n   Over the co
 urse of this ongoing research project\, IRONMAP has\n   catalogued over 5.
 5 million ICS/OT-facing assets across the public\n   internet\, with more 
 than 2.25 million flagged as high-risk. Using deep\n   protocol fingerprin
 ting across all major industrial protocols —\n   EtherNet/IP (CIP)\, Mod
 bus TCP\, Siemens S7\, DNP3\, IEC 60870-5-104\,\n   OPC-UA\, BACnet/IP\, O
 mron FINS\, GE SRTP\, Tridium Fox\, and more —\n   IRONMAP goes well bey
 ond port scanning to perform authenticated\n   protocol enumeration\, live
  register reads\, and tag harvesting using\n   PLCDISCO\, our multi-protoc
 ol OT scanner.\n\n   This talk presents a ground-level statistical portrai
 t of the exposed\n   OT internet: which protocols dominate\, which sectors
  are most exposed\,\n   how vendor market share looks through the lens of 
 deep insight and\n   where in the world the highest concentrations of expo
 sed critical\n   infrastructure live (spoiler: it is not all China). We wi
 ll walk\n   through what over 242\,000 EtherNet/IP devices look like when 
 you\n   enumerate their CIP identity objects\, what ~500\,000 Modbus devic
 es\n   expose in their holding registers\, and what the live tag names of 
 real\n   PLCs tell you about what processes they are running.\n\n   We the
 n turn to a specific and underappreciated issue: Automatic Tank\n   Gauges
  (ATGs). IRONMAP found 149 confirmed ATG systems directly\n   exposed to t
 he internet\, the majority of them Veeder Root TLS-350 and\n   TLS-450 uni
 ts — the dominant ATG platform at commercial fueling\n   facilities acro
 ss North America. These systems\, reachable via the\n   Guardian ASP proto
 col on TCP/10001\, require no authentication on older\n   firmware and res
 pond to a simple serial-style command set with:\n\n     * Current fuel vol
 ume per tank\, in gallons\n\n     * Product type (Unleaded\, Premium\, Die
 sel\, Jet-A\, Heating Oil)\n\n     * Live alarm states (high water\, leak 
 detection\, low fuel\, overfill)\n\n     * Delivery event history and time
 stamps\n\n     * Up to 8 tank probes per unit\n\n   The implications are s
 ignificant. Exposed ATGs reveal not just that a\n   facility has fuel stor
 age\, but how much\, what kind\, and when\n   deliveries occur — operati
 onal patterns that are directly relevant\n   to physical security and supp
 ly chain intelligence. IRONMAP discovered\n   ATGs at locations that inclu
 de commercial truck stops\, bulk fuel\n   terminals\, and sites with produ
 ct profiles consistent with aviation or\n   military use. We will demonstr
 ate a live walk-through of what an\n   unauthenticated session reveals\, d
 iscuss the responsible disclosure\n   posture we have taken\, and present 
 mitigation guidance for asset\n   owners.\n\n   Attendees will leave with 
 a realistic\, data-grounded view of the\n   exposed OT landscape — not a
  cherry-picked set of scary screenshots\,\n   but statistically representa
 tive findings from a 5.5-million-asset\n   dataset — plus actionable con
 text on the ATG exposure class and how\n   to find and fix it.\n\n   Speak
 erBio:  Matt Caldwell\, Tophat Security\n\n   Matt Caldwell is the founder
  of Tophat Security\, cyber security firm\n   specializing in innovative O
 T/ICS software and tools\, red team\n   operations\, and critical infrastr
 ucture research. With over a decade\n   of experience in industrial contro
 l system security\, Matt has assessed\n   environments spanning oil and ga
 s\, electric utilities\, water\n   treatment\, manufacturing\, and federal
  government. He built IRONMAP as\n   a research platform to continuously m
 ap the internet-exposed OT attack\n   surface at scale\, applying it to bu
 ild threat intelligence\, support\n   disclosure efforts\, and develop dat
 a-driven visibility into the global\n   ICS exposure problem. Matt holds r
 elevant certifications in cyber\n   security and penetration testing and h
 as presented research at global\n   OT/ICS security conferences. He is bas
 ed in Athens\, Georgia\, and\n   speaks regularly with asset owners\, gove
 rnment stakeholders\, and\n   research organizations on OT exposure topics
 .\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T173000Z
DTSTART:20260809T170000Z
LOCATION:ICS Village - LVCCW Level 1 Hall 3 801 (Creator Stage 1)
SUMMARY:Five Million Industrial Control Systems Walk Into a Bar: What IRONM
 AP Found When It Scanned the Whole Internet
END:VEVENT
END:VCALENDAR
