ICS Security's 25-Year Reunion Is Headed to Nashville
The Industrial Control Systems Cybersecurity Conference marks a quarter-century in October 2026, touching down at the W Nashville for three days of OT threat intelligence.

Key points
- The 2026 ICS Cybersecurity Conference runs October 6-8, 2026, at the W Nashville.
- The anniversary edition arrives as ransomware groups and nation-state actors pursue industrial targets through distinct but converging paths.
- OT environments face a standing tension between uptime and security that enterprise patching schedules cannot resolve.
- AI anomaly detection on process data has real promise; vendor booth claims are a separate matter.
- Our coverage of OT security goes back to 28 May 2026, when we reported that fewer than 10 percent of OT networks have meaningful monitoring in place.
Twenty-five years is a long time in any security discipline. In ICS and OT (operational technology) security, it's practically geological, spanning Stuxnet, a ransomware epidemic that learned to cross the IT/OT boundary, and a slow reckoning with legacy PLCs (programmable logic controllers) that were never designed to live on a network.
What has actually changed in 25 years?
The threat picture has shifted in two directions at once. Early ICS security conversations centered on nation-state actors with surgical intent. Today the field contends with ransomware groups that stumbled into OT impact, Colonial Pipeline being the canonical example, alongside adversaries who are deliberate about targeting industrial processes. Those are different threat models calling for different defenses.
The push to connect OT environments to enterprise networks and cloud monitoring platforms has sharpened an old tension: operators who keep power grids and water treatment lines running cannot simply patch on Tuesday because downtime means something other than a help-desk ticket.
Should AI pitches at the booth be trusted?
AI is appearing in this conversation in ways that are occasionally useful and occasionally theatrical. Anomaly detection on process data has genuine promise. Automated patch prioritization for environments where many CVEs (common vulnerabilities and exposures) will never be remediable is worth examining closely. Whether vendor pitches match technical reality is, as always, a separate question. Our earlier reporting found that layering machine-learning tools on top of industrial control systems may create more risk than it resolves until monitoring coverage improves.
The most useful thing a 25-year-old conference can do is keep those two conversations, the genuinely promising and the theatrical, in separate rooms.
Nashville, October 6-8, 2026.



