An Undeclared War: UnDisruptable27, Critical Infrastructure Systems, and Cyber Threats at Critical Effect DC ‘26

August 4, 2026

Presented by ICS Village in partnership with IST’s UnDisruptable27 project and Akin, Critical Effect DC ‘26 brought together leaders across operational technology, industrial control systems, national security, and public policy, with a sharp focus on safeguarding human life and essential services.

“We are on the front lines of an undeclared war,” Acting CISA Director Nick Andersen told the audience at Critical Effect DC. For two days in Washington D.C this June, the conversation surrounding critical infrastructure cybersecurity moved beyond abstract threat vectors to actionable, real-world defense. 

Presented by ICS Village in partnership with the Institute for Security and Technology’s (IST) UnDisruptable27 project and Akin on June 17 and 18, Critical Effect DC brought together leaders across Operational Technology (OT), industrial control systems, national security, and public policy with a sharp focus on safeguarding human life and essential services.

Amid escalating geopolitical tensions and an increase in AI-driven cyber attacks, the conference took an urgent, solution-focused approach designed to bridge the gap between policy mandates and front-line operational defense. From quantum risk in OT to cyber disruption planning to unpacking the Electrotech Stack, Critical Effect featured 65+ experts in 37 sessions across 3 tracks.  

Missed your chance to join us this year? Check out a few of this year’s sessions, and stream all presentations on IST’s YouTube

Residential Proxies and Critical National Infrastructure 

Track 3: Tactical Mastery
Wednesday, June 17, 2026

Adversaries continue to target critical national infrastructure (CNI) via cyber means and have improved their technical and OPSEC mechanisms in doing so. Key to this evolution is leveraging proxies from compromised network devices, often in residential or small-office settings, to facilitate communication from the adversary to the victim space. In this presentation, Joe Slowik (Director, Threat Research and Cyber Engineering, Dataminr) analyzed the technical nature of these networks, their implications for monitoring and defense, and policy and ethical considerations for response and mitigation. 

When the Internet Breaks: How to Keep Critical Infrastructure Alive at 5% Bandwidth

Track 2: Strategic Effect
Wednesday, June 17, 2026

How can IT systems operate when networks degrade or fail? Presented by Caleb Queern (Managing Director, KPMG US), this talk presented practical techniques to build resilient systems that function under extreme bandwidth constraints and disrupted conditions.

The Electrotech Stack at Risk: China, AI, and America’s Energy Supply Chains

Track 2: Strategic Effect
Thursday, June 18, 2026

The United States is entering a generational energy buildout, but as billions go towards modernizing our electrical infrastructure, our systems remain dependent on China for the underlying “electrotech stack.” A new paper by the Carnegie Mellon Institute for Strategy and Technology examines how this reliance creates severe supply chain vulnerabilities and threatens the security advantages a modernized grid is supposed to deliver. This session led by Phoebe Benich (Non-Resident Fellow, Carnegie Mellon Institute for Strategy and Technology) and Emma Stewart (Director, Center for Securing Digital Energy Technology) drew on that research to explore how the U.S. can secure its energy future and achieve maximum strategic return.

Buying Blind: How Federal Acquisition Is Leaving Cyber-Informed Engineering on the Table

Track 2: Strategic Effect
Thursday, June 18, 2026

The principles of Cyber-Informed Engineering (CIE) are clear: engineer out cyber risk at the design stage, bound the consequences of compromise, and eliminate the assumption that detection and response alone can protect critical systems. What is far less clear is how any of this gets bought. Drawing on an analysis of current cybersecurity standards, procurement language, and evaluation criteria, Virginia Wright (Program Manager, Idaho National Laboratory) identifies where CIE requirements fall through the cracks — and what it would take to close them. In this session, she presented a mock procurement exercise as a concrete use case, demonstrating how vendors and buyers are talking past each other on engineered security and how targeted modifications to requirements language and evaluation factors could change outcomes without requiring a wholesale regulatory overhaul.

When YOU are your worst nightmare: Thinking Like an Adversary in an OT Environment

Track 2: Strategic Effect
Wednesday, June 17, 2026

Andrew Krapf (Director of Cybersecurity, Loudoun Water) challenged his audience to apply their knowledge of OT systems to considering what could happen when adequate Prevention, Detection, Isolation, and Recovery abilities are not available. Although fictitious, the conversation highlighted the need to engage in a consequence-driven, risk-based thought exercise and how they would respond. The goal was to show that a knowledgeable adversary is not just an abstract concept.

Related Content

MENU

GET IN TOUCH

Email: [email protected]
Send us a message: Contact

JOIN THE CATALINK MAILING LIST