API Cybersecurity Conference 2026

Date:
November 10-11, 2026
Location:
Woodlands Waterway Marriott, The Woodlands, Texas
Conference API Cybersecurity with official logo in retro computer.

The 21st Annual API Cybersecurity Conference for the Oil and Natural Gas Industry brings together security and operations leaders from across the energy sector to address the risks reshaping oil and gas infrastructure. Bishop Fox is glad to be part of this year's conversation.

Christie Terrill, Chief Information Security Officer at Bishop Fox, and David Vargas, Senior Security Consultant on the Red Team, will join a panel of oil and gas and offensive security experts to discuss how operators are adapting to an increasingly complex threat landscape, drawing on real-world case studies.

For more details, visit: API Cybersecurity Conference 2026

Pipeline to Pwned: Offensive Security in High-Stakes ICS Environments

Speakers: Christie Terrill, Chief Information Security Officer, Bishop Fox and David Vargas, Senior Security Consultant, Bishop Fox

Abstract: As AI-enabled operational technologies, cloud connectivity, and IT/OT convergence reshape energy infrastructure, security teams are being forced to defend environments that are evolving faster than traditional risk models, governance frameworks, and operational assumptions were designed to handle. This panel brings together experts from the oil and gas industry, as well as offensive security, to discuss how operators are adapting to an increasingly complex threat landscape through approaches such as attack surface management (ASM), adversary simulation, and carefully scoped testing in high-risk operational environments.

Through real-world successes and lessons learned, panelists will discuss:

  • Emerging Threats: how adversarial tactics, including AI-assisted reconnaissance and exploitation, are evolving faster than regulatory frameworks and traditional ICS security models.
  • Attack Surface Complexity: challenges associated with contextualizing and prioritizing exposures across subsidiaries, legacy ICS infrastructure, cloud environments, and emerging AI-enabled operational technologies.
  • Case Studies in Action: using ASM to identify and neutralize a critical vulnerability within hours while navigating regulatory obligations; validating real-world attack paths from vulnerability scan data to uncover exploitable access to critical infrastructure, Active Directory, and segmented internal systems.
  • Safe Offensive Testing: considerations and practical experiences for validating security in high-risk ICS environments without jeopardizing operational safety or reliability.

Attendees will walk away with perspectives on:

  • How organizations are translating attack surface visibility into operational resilience and faster response times.
  • Approaches for integrating offensive security practices into broader operational risk and security programs.
  • Balancing regulatory compliance, operational safety, and proactive defense in increasingly interconnected ICS environments.

Bfx25 Christie Terrill Update Bio

About the speaker, Christie Terrill

Chief Information Security Officer

Christie Terrill is the Chief Information Security Officer (CISO) of Bishop Fox, with more than 20 years of experience in security and technology services. She oversees the company’s security strategy and program, and has played an integral part in developing the company’s operational strategy while simultaneously ensuring the greatest value for clients. A 15-year Bishop Fox veteran, Christie most recently drove the rigorous, multi-year process of completing certifications for Bishop Fox’s ISO/IEC 27001 Type 2 and SOC 2 Type 2 Security Trust Services Criteria. Having joined Bishop Fox as a consultant, she quickly ascended to partner and established the company's enterprise security consulting practice, as well as serving in the sales organization.


David Vargas

About the speaker, David Vargas

Senior Security Consultant I

David Vargas is a Senior Security Consultant I on Bishop Fox's Red Team, with extensive experience in social engineering and physical penetration testing. David is an active security researcher with multiple CVEs in publicly accessible web applications.

Ready to get started? We can help.

Contact Us