BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Two NICs\, Zero Trust: Pulling Apart a PAC Buried in
  Critical\n   Infrastructure\n   Tags: ICS Village | Creator Talk/Panel\n 
   When: Sunday\, Aug 9\, 12:30 - 12:59 PDT\n   Where: LVCCW Level 1 Hall 3
  801 (Creator Stage 1) - [1]Map\n\n   Description:\n\n   Imagine you get c
 alled up by a large CNI operator - "We have these\n   devices\, they're al
 l over our outstations and they sit between our\n   most critical OT trust
  zones"\, would you want to take a look? We did\n   what any curious greml
 ins would do: we bought the hardware\, built a\n   bench\, and started pul
 ling at every thread. This talk tells the\n   investigation as it actually
  happened\, starting with architecture and\n   documentation\, moving thro
 ugh firmware analysis and protocol\n   dissection\, and ending with full p
 wnage at the firmware and\n   application layers. Along the way we found a
  security model that felt\n   frozen in the 2010s: weak trust boundaries\,
  unauthenticated\n   reconfiguration paths\, and cryptographic protections
  as strong as wet\n   cardboard. The point of the talk is not "bench testi
 ng is cool."\; It's\n   how to take a standard CNI concern into a hardware
 -led investigation\n   that uncovers flaws a network-only pen test will mi
 ss. Attendees will\n   leave with a practical workflow for assessing OT de
 vices at scale\, a\n   mental model for deciding when to go from docs to f
 irmware to hands-on\n   testing\, and a clear picture of how apparently bo
 ring PACs can become\n   high-value footholds inside critical infrastructu
 re. Nation-state\n   level firmware backdoors and research artefacts will 
 be released\n   alongside this talk.\n\n   Speakers:Adam Bromiley\,Sam Tho
 m\n\n   SpeakerBio:  Adam Bromiley\, Pen Test Partners\n\n   Adam is a sec
 urity consultant at Pen Test Partners who specialises in\n   industrial co
 ntrol systems and embedded hardware security. He's worked\n   on everythin
 g safety-critical: from high-speed rail to aircraft\, power\n   stations\,
  and gas distribution. His embedded work has seen him break\n   driverless
  cars\, slot machines\, and drones and has led to the\n   responsible\n\n 
   disclosure of numerous vulnerabilities in industrial controllers. Adam\n
    enjoys hands-on and boots-on-the-ground testing\, reverse engineering\,
 \n   and providing practical security advice for complex real-world\n   sy
 stems.\n\n   SpeakerBio:  Sam Thom\n\n   Sam is a security consultant at P
 en Test Partners who focuses on the\n   weird stuff - hardware\, IoT and O
 perational Technology. He's poked and\n   prodded Industrial and embedded 
 systems across various industries like\n   automotive\, IoT\, IIoT\, chemi
 cal\, water\, power\, gas\, manufacturing and\n   his favourite of all - t
 he alcohol industry. Sam enjoys tearing down\n   operational systems on th
 e bench almost as much as owning them in the\n   field.\n\n   '\n\n   1. #
 LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T195900Z
DTSTART:20260809T193000Z
LOCATION:ICS Village - LVCCW Level 1 Hall 3 801 (Creator Stage 1)
SUMMARY:Two NICs\, Zero Trust: Pulling Apart a PAC Buried in Critical Infra
 structure
END:VEVENT
END:VCALENDAR
