BSides London 2025

BSides London 2025

When Incidents Get Physical: A View of Incident Response in Critical Infrastructure
2025-12-13 , Rookie Track 2

Many sectors of critical infrastructure need to control and automate their physical infrastructure with operational technology (OT). That means that any OT cyber attack requires an incident response that bleeds into the physical world. This brings with it unique challenges, such as real-time pressures, cross-border coordination, and safety concerns. This talk covers my recent experience in the world of critical infrastructure to tell the story of how responding to cyber-physical incidents changes the game.

Attendees will learn:
- The importance of cross team communication. Why cyber-physical incidents require collaboration across technical, operational, and even geopolitical boundaries
- How cascading effects can quickly escalate from system downtime to safety risks and societal disruption


Incident response usually feels like chasing down logs and server alerts, but in critical infrastructure, the problems don’t just stay digital.

In this 15-minute talk, I’ll cover:

What stood out in early experience: how incidents in energy infrastructure require coordination across teams and borders.

Why OT changes the mindset: how real-time systems and safety make IR feel faster and riskier than IT.

Insights from both the energy sector and competitions like Cyber Leaders Challenge that highlighted the importance of teamwork, communication, and thinking beyond the technical.

Attendees will leave with a deeper understanding of how cyber incidents in OT differ from IT, and why communication, collaboration, and situational awareness are just as critical as technical expertise.


Please confirm that I am a first time speaker and have not spoken in public and will not be before the Bsides London event date (14th December 2024).: Yes

Hi, I’m Akash. I’m a student who just finished an internship in the energy sector, where I got my first real exposure to OT security. I’ve also competed in events like Cyber 9/12 and the Cyber Leaders Challenge, which pushed me to think about how technical work connects with bigger strategic decisions. This is my first BSides talk, and I’m using it as a chance to share what I’ve learned about incident response in the physical world of OT.