API Cybersecurity Conference 2026
- Date:
- November 10-11, 2026
- Location:
- Woodlands Waterway Marriott, The Woodlands, Texas
The 21st Annual API Cybersecurity Conference for the Oil and Natural Gas Industry brings together security and operations leaders from across the energy sector to address the risks reshaping oil and gas infrastructure. Bishop Fox is glad to be part of this year's conversation.
Christie Terrill, Chief Information Security Officer at Bishop Fox, and David Vargas, Senior Security Consultant on the Red Team, will join a panel of oil and gas and offensive security experts to discuss how operators are adapting to an increasingly complex threat landscape, drawing on real-world case studies.
For more details, visit: API Cybersecurity Conference 2026
Pipeline to Pwned: Offensive Security in High-Stakes ICS Environments
Speakers: Christie Terrill, Chief Information Security Officer, Bishop Fox and David Vargas, Senior Security Consultant, Bishop Fox
Abstract: As AI-enabled operational technologies, cloud connectivity, and IT/OT convergence reshape energy infrastructure, security teams are being forced to defend environments that are evolving faster than traditional risk models, governance frameworks, and operational assumptions were designed to handle. This panel brings together experts from the oil and gas industry, as well as offensive security, to discuss how operators are adapting to an increasingly complex threat landscape through approaches such as attack surface management (ASM), adversary simulation, and carefully scoped testing in high-risk operational environments.
Through real-world successes and lessons learned, panelists will discuss:
- Emerging Threats: how adversarial tactics, including AI-assisted reconnaissance and exploitation, are evolving faster than regulatory frameworks and traditional ICS security models.
- Attack Surface Complexity: challenges associated with contextualizing and prioritizing exposures across subsidiaries, legacy ICS infrastructure, cloud environments, and emerging AI-enabled operational technologies.
- Case Studies in Action: using ASM to identify and neutralize a critical vulnerability within hours while navigating regulatory obligations; validating real-world attack paths from vulnerability scan data to uncover exploitable access to critical infrastructure, Active Directory, and segmented internal systems.
- Safe Offensive Testing: considerations and practical experiences for validating security in high-risk ICS environments without jeopardizing operational safety or reliability.
Attendees will walk away with perspectives on:
- How organizations are translating attack surface visibility into operational resilience and faster response times.
- Approaches for integrating offensive security practices into broader operational risk and security programs.
- Balancing regulatory compliance, operational safety, and proactive defense in increasingly interconnected ICS environments.