Home
European Smart Grid Cyber Security Forum
14 March - 15 March 2011
European Smart Grid Cyber Security Forum


The European Smart Grid Cyber Security Forum March 12th and 13th London is now booking. This is the flagship Cyber event in Europe for Smart Grids and heavily supported by Government, Utilities, Academia and the most authoritative solution providers.

If you wish to be involved please visit the site at http://www.smartgridcybersecurity.co.uk or call Jamison Nesbitt at +44 (0)20 7827 6164 or jnesbitt@SAE Media Group-online.co.uk to avoid disappointment.

 
 
 
 
 
"Thanks for your hospitality, generous assistance, and steadfast promotion of Lockheed throughout the event.
I made some very helpful contacts, and I hope it serves as a springboard for opportunities for us in Europe.
You had a full house of 166, and they were the right kinds of people to influence as we enter a new market space" -
Lockheed Martin, commenting on the recent European Smart Grid Cyber Security Forum

Just wanted to express a thank you for the very well organised conference and an assurance that we will be back once we have implemented some of the good advise from some of the peers around Europe. It resulted in some good networking opportunities and especially one that we identified had similar challenges and ethos to solve these that we will pursue further. " Major UK Utility

 

 

Thank you to all of our speakers, sponsors, workshop leaders and attendees for a huge success
 
 

 

 

As Governments and utilities around the world continue to work on the deployment of the Smart Grid initiative, cyber security issues around such an infrastructure are now top priority in relation to national security and investment.

In April 2009, reports surfaced that China and Russia had infiltrated the U.S. electrical grid and left behind software programs that could be used to disrupt the system, according to current and former national security officials

See influential players from the European and UK Landscape come together to discuss the important role of security in Smart Grid Deployment, and the risks associated with digital, modernized electricity networks. Don’t miss this rare opportunity to integrate, share insight and help define the landscape of a future industry estimated to be worth in excess of $3.7 Billion by 2015 (Pike Research).





Lead sponsors   



 


Gold Sponsors   

 


   





 Silver  Sponsors




 



Silver Sponsors





 

 NIST
Chief Security Advisor




• ENISA
Senior Expert, Network Security Policy



• Swissgrid
Head of Information and Communication Services Technology



•  Transmission System Operator Security Cooperation
Chairman of the Transmission Security Cooperation and Senior Advisor of Operations, swissgrid AG



• Alliander
Senior Consultant Smart Grids



• E.ON Sverige AB
Chief Information Security Officer, Nordic region




 E.ON Energie AG
Information Security Officer, Central and Eastern Europe



• Elia Belgium
Chief Information Officer

 

Alliander
Privacy and Security Officer

 

Conference agenda

clock

8:30

Registration & Coffee

clock

9:00

Chairman's Opening Remarks

Mark Ossel

Mark Ossel, ESNA Board Member and VP Echelon, ESNA

ESNA partners with the European Smart Grid Cyber Security Forum

ESNA is an not-for-profit association formed by a group of companies who recognised the need for establishing an organisation to promote the application of advanced energy management systems, including AMR/AMM, based on the NES platform and to build and expand the interoperability standard for utility networks NTA 8150.
Mark B.M. Ossel
Vice President Energy & Utility, Echelon
Board member, Treasury, ESNA
Netherlands

Mark B.M. Ossel (1955), Vice President Echelon, is focussed on developing the Energy and Utility market for Echelon in West Europe, Middle East and Africa, by extending the network of partners and growing the customerbase. He is involved in AMR since 2001, when the Enel AMR project started.
Mark is also member of the board of ESNA (Energy Services Network Association), the international Echelon NES usergroup, and involved in international standardization efforts.
Mark has a background of more then 20 years in various management functions in the Information & Communication Technology market, before he became involved in energy management, smart metering and Smart Grids..
Before joining Echelon in June 2001 as Vice President EMEA for the LonWorks Infrastructure business, Mark served, among other management roles,  as the Director Marketing Operations Europe, Middle East & Africa for Unisys Corporation, one of the largest US computers and IT services companies.
Mark has a bachelor degree in marketing and economics, and attended additional courses in The Netherlands, UK and USA; he has a special interest in applying new technology.
A specific area of interest is the field of energy management through home automation. Based on the background in LonWorks and Energy management systems a perfect match.
Mark has a Dutch nationality, lives in the Netherlands and is  a.o. a member of Rotary International , non-executive member of various boards.and active in the Unesco World Heritage program.

clock

9:10

Defining a cyber security strategy

William Barker , Chief Security Advisor, NIST

System envirinment (Legacy and target)

Policy environment 

Standards and interoperability

Risks defined

  • Terrorism
  • Hackers
  • Natural Disasters
  • Equipment failures
  • User Errors

    Stakeholders defined

    • Government (Regulation and support)
    • Utilities (public and private sectors)
    • Telecoms  and Internet Service Providers
    • Dependent entities 

      Government

      • Goals, rules, and security standards
      • Risk assessment 
      • Prevention
      • Response
      • Recovery
    clock

    9:40

    Enisa's resilience and CIIP program

    Evangelos Ouzounis , Senior Expert, Network Security Policy, ENISA - European Network and Information Security Agency

  • Introduce EU Commission’s and ENISA policy context in the areas of CIIP 
  • Explain the importance of security and resilience of communications networks and services for Europe
  • Present ENISA’s good practices on exercises, incident reporting and information sharing
  • Introduce ENISA’s approach to interdependencies of different sectors including SCADA and Smart Grids
  • Present ENISA’s activities in the area of interconnected communication networks
  • clock

    10:10

    Smart Grid security and privacy framework

    Johan  Rambi

    Johan Rambi , Privacy & Security Officer , Alliander

  • Security & Privacy legal framework
  • European policy and regulatory directives
  • Security & Privacy standards
  • Lessons learned
  • Next steps
  • clock

    10:40

    Morning Coffee

    clock

    11:10

    The reliability and security of the Grid

    Rajesh Nair , Head, Strategy and Architecture, Swissgrid

  • A Multi-tier strategy
  • Standard Framework
  • Holistic approach to addressing reliability and security
  • Risk Mitigation strategies
  • clock

    11:40

    Identity and Access Management Lifecycle for Smart Grids

    Ian Collard

    Ian Collard, Security Practice Manager , Siemens

  • The role that IAM should play
  • The identity Ecosystem for SMART Grids
  • Maturity modelling
  • Identity architecture and modelling
  • Identity lifecycle management
  • Access and Authorisation models
  • Entitlement models
  • How to avoid failure in deployment
  • How to avoid over-engineering and under-utilisation
  • Some speculation regarding HANS
  • Some speculation regarding 3rd party energy management
  • clock

    12:10

    How real time cyber security changes the game for utilities worldwide

    Sean Patton

    Sean Patton, Director of Energy and Cyber Services, Lockheed Martin - Management & Data Systems

  • Current state of cyber protection
  • Lack of threat and information sharing
  • Advanced Persistent Threat
  • Solving the problem for large energy companies
  • Solving the problem for the other 95%
  • Next generation tools and capabilities
  • clock

    12:40

    Networking Lunch sponsored by Lockheed Martin

    Securing the Smart Grid: Lockheed Martin Cyber Security

    Today's energy providers face complex security risks and challenges. Relying on traditional firewalls, intrusion detection systems, and encryption alone are not effective against the rapidly evolving threats. Cyber security is a critical cross-cutting enabler for all Smart Grid technology that begins with the utility’s operations and requirements, and continues with security solutions that are integrated, proactive and resilient. With a history of solving hard, complex problems, Lockheed Martin brings best practices, new technologies, fresh approaches, and innovating minds to the Energy community for providing cyber security and interoperability services.
     

    clock

    14:00

    Building a Secure Smart Grid- Principles and Methodology

    Saadat  Malik

    Saadat Malik, Senior Manager, Smart Grid Solutions and Architecture, Cisco Systems

  • Ensuring the grid infrastructure is resilient, is essential to achieving the objectives of a “smart grid”.?Interoperability is critical, yet creates more diverse threats and complexity.
  • This requires an architectural approach based on key security principles and implemented using a requirements-based methodology.  
  • The same approach needs to be extended to the communications architecture, enabling it to be developed with a security framework in mind.
  • This will ensure that security is embedded within, and applied effectively to all aspects of the utility environment.?
  • Building security into the communications infrastructure can bring the various components of the grid together to form a synergistic, more intelligent grid that addresses regulatory and compliance needs.
  • Process beginning from the security challenges to requirements development, and provide a use case to illustrate how this fits within a broader security lifecycle approach.
  • clock

    14:30

    Panel Session Collaborating on International Standards and Framework

    Today's panel session "Collaborating on International Standards and Framework" will be moderated by Bob Lockhart, Senior Analyst with Pike Research.

    Bob Lockhart is a senior analyst contributing to Pike Research’s smart energy practice, with a focus on cyber security markets. Lockhart is a recognized information security industry leader who spent 31 years at EDS, 17 of which were in information security management.

    Lockhart has extensive leadership experience in the global technology and outsourcing industry, having supported more than 200 multinational clients. His career encompasses support or manufacturing, aerospace, government, financial services, outsourcing, and healthcare industries in both the United States and Europe. Lockhart has served multiple roles including Chief Security Officer, Software Manager, Security Portfolio Executive, Solution Architect, and Data Center Manager. He holds a B.Sc. in mathematics from Loyola Marymount University.
     
     
    Key members of the Forum's standards and framework presentations today, will come together to discuss how we can collaborate further and develop global understanding and process.
  • What can Europe learn from the U.S?
  • What can the US learn from Europe?
  • How do we tie two and two together?
  • Who are the key stakeholders we must engage?
  • What barriers exist and how can we overcome them?
  • William Barker , Chief Security Advisor, NIST

    Kenneth  Van Meter

    Kenneth Van Meter, General Manager, Energy & Cyber Services, Lockheed Martin

    Evangelos Ouzounis , Senior Expert, Network Security Policy, ENISA - European Network and Information Security Agency

    Today's panel session "Collaborating on International Standards and Framework" will be moderated by Bob Lockhart, Senior Analyst with Pike Research.

    Bob Lockhart is a senior analyst contributing to Pike Research’s smart energy practice, with a focus on cyber security markets. Lockhart is a recognized information security industry leader who spent 31 years at EDS, 17 of which were in information security management.

    Lockhart has extensive leadership experience in the global technology and outsourcing industry, having supported more than 200 multinational clients. His career encompasses support or manufacturing, aerospace, government, financial services, outsourcing, and healthcare industries in both the United States and Europe. Lockhart has served multiple roles including Chief Security Officer, Software Manager, Security Portfolio Executive, Solution Architect, and Data Center Manager. He holds a B.Sc. in mathematics from Loyola Marymount University.
     
     
    Key members of the Forum's standards and framework presentations today, will come together to discuss how we can collaborate further and develop global understanding and process.
  • What can Europe learn from the U.S?
  • What can the US learn from Europe?
  • How do we tie two and two together?
  • Who are the key stakeholders we must engage?
  • What barriers exist and how can we overcome them?
  • Robert Cragie, Chair of the ZigBee Security Working Group, ZigBee Alliance

    Ian Collard

    Ian Collard, Security Practice Manager , Siemens

    Saadat  Malik

    Saadat Malik, Senior Manager, Smart Grid Solutions and Architecture, Cisco Systems

    Bob Lockhart

    Bob Lockhart, Senior Analyst , Pike Research

    Johan  Rambi

    Johan Rambi , Privacy & Security Officer , Alliander

    clock

    15:30

    Afternoon Tea

    clock

    16:00

    Getting it right first time: Lessons for smart grid users from GB smart metering so far

    Steve Daniels

    Steve Daniels , Head of cyber security and information assurance, Detica

  • The real cyber security threat
  • Taking a comprehensive approach to meter and grid security
  • Defining guiding principles and consequent strategy
  • Establishing accountability, authority and arrangement for effective delivery
  • Establishing an holistic controls framework
  • clock

    16:30

    Implementing security & privacy framework into Smart Meter/Grid Infrastructure

    Johan  Rambi

    Johan Rambi , Privacy & Security Officer , Alliander

  • Privacy & Security issues about Smart Meter/Grid
  • Certification Privacy Audit Proof
  • Project implementation Security & Privacy at Alliander
  • ISPMS cycle
  • Lessons learned

     

  • clock

    17:00

    Information Risks around the Smart Meter

    Stephan Gerhager

    Stephan Gerhager, Security Manager for Central and Eastern Europe, E.ON Energie AG

  • Future Smart Meters play a central role
  • Connecting customers (Internet), the “Smart Home” and the “Smart Grid”
  • Smart meters  a  target for different kinds of attackers
  • Information security risks in connecting these three worlds
  • First ideas for countermeasures
  • clock

    17:30

    Chairman’s Closing Remarks and Siemens Networking reception

    clock

    8:30

    Registration & Coffee

    clock

    9:00

    Chairman's Opening Remarks

    Mark Ossel

    Mark Ossel, ESNA Board Member and VP Echelon, ESNA

    clock

    9:10

    Developments in Smart Grids Around the World

    John Newbury, Director of Power Communication System Research, The Open University

  • The Emergence of the Smart Grid in the World
  • International Standards in the Smart Grid
  • Communication Architectures for the Smart Grid
  • Future Developments
  • clock

    9:40

    The role of the DNO in Smart Grid Security

    Frans Campfens

    Frans Campfens, Senior Consultant SmartGrids (ICT) and AMR, Alliander

  • Smart grids scenarios
  • The Local System Operator concept
  • Grid Connection Register concept (GCR)
  • The DNO as Certification Authority
  • Security by design
  • clock

    10:10

    The responsibilities of the TSO in Cyber Security

    Rudolf Baumann

    Rudolf Baumann , Chairman of the Transmission Security Cooperation, Senior Advisor Operations , Swissgrid AG

    TSO's have improved the System Security by developing a "Common Tool for Data exchange and Security assessments“ as a collaboration platform by:

  •  Exchanging experiences regarding remedial actions
  • Exchanging experience based on the results of system monitoring
  • Developing new multilateral procedures and measures
  • Making proposals for new functionalities like implementation of a Real-Time Awareness & Alarm system (RAAS) for Central Europe
  • clock

    10:40

    Morning Coffee

    clock

    11:00

    SCADA in security: A business and societal risk

    Gitte Bergknut

    Gitte Bergknut, MU Nordic Information Security Manager, EON Sverige AB

  • Insight into E.ON's proactive work in the VIKING Project, a EU 7 programme sponsored SCADA Security Research Project
  • Why is SCADA Security important? One of the key findings so far is that physical damages to the electrical grid can be achieved
  • One aim of the VIKING Project is to develope methods and tools for risk assessments from the physics to the societal consequence of a cyber attack on a SCADA systems
  • Another aim is to find, develop and recommend mitigations - Our news and ideas
  • Create an SCADA Security awareness and mitigation strategy
  • clock

    11:30

    How do we ensure the security of our Smart Grids?

  • Discuss the potential security threats in the roll-out of Smart Grids and AMI in the UK
  • Putting the threats into perceptive
  • Present SAIC global experiences
  • The Common Security Model’ and SOA
  • What will the future Smart Grid look like?
  • Gilbert Sorebo

    Gilbert Sorebo, Chief Cybersecurity Technologist,, SAIC

    clock

    12:00

    Securing the Home Area Network

    Robert Cragie, Chair of the ZigBee Security Working Group, ZigBee Alliance

  •  Cyber security in the HAN
  •  Mutual authentication in the HAN
  •  Public key cryptography
  • Certificate PKI
  •  Dual certificate model
  • Shared network model

                           o    Network Access
                           o    Registration

  • Federated and end-to-end security
  • Access control
  • Operational security
  • Accommodating multiple service provider interfaces
  • clock

    12:30

    Networking Lunch

    clock

    13:30

    Panel Discussion: Risk mitigation, awareness and strategy

    Today's panel session will discuss Risk Mitigation and Awareness and Strategy. The session will be moderated by Bob Lockhart, Senior Analyst with Pike Research

     

     
     

  • Gitte Bergknut,MU Nordic Information Security Manager, E.ON Sverige AB
  • Rajesh Nair, Head of Strategy and Architecture, Swiss Grid 
  • Rudolf Baumann,Chairman of the Transmission Security Cooperation and Senior Advisor of Operations, Swiss Grid AG
  • Marc M.J. Hullegie,Managing Director, Vest Information Security

     

     

    Bob Lockhart is a senior analyst contributing to Pike Research’s smart energy practice, with a focus on cyber security markets. Lockhart is a recognized information security industry leader who spent 31 years at EDS, 17 of which were in information security management.
    Lockhart has extensive leadership experience in the global technology and outsourcing industry, having supported more than 200 multinational clients. His career encompasses support or manufacturing, aerospace, government, financial services, outsourcing, and healthcare industries in both the United States and Europe. Lockhart has served multiple roles including Chief Security Officer, Software Manager, Security Portfolio Executive, Solution Architect, and Data Center Manager. He holds a B.Sc. in mathematics from Loyola Marymount University.
  • Gitte Bergknut

    Gitte Bergknut, MU Nordic Information Security Manager, EON Sverige AB

    Rajesh Nair , Head, Strategy and Architecture, Swissgrid

    Rudolf Baumann

    Rudolf Baumann , Chairman of the Transmission Security Cooperation, Senior Advisor Operations , Swissgrid AG

    Marc M.J. Hullegie, Managing Director, Senior Consultant Information Governance , VEST INFORMATION BV

    Bob Lockhart

    Bob Lockhart, Senior Analyst , Pike Research

    clock

    14:30

    Evolution and strategy - An ELIA Case Study

    Pierre  Loverious

    Pierre Loverious , Chief Information officer , Elia System Operator SA

  • The evolution of ELIA’s IT network architecture (i.e. TDM -> IP)
  • Grid functionalities that prevent us to move towards a 100% IP network (i.e. protections)
  • ELIA’s network security
  • clock

    15:00

    Afternoon Tea

    clock

    15:30

    Perception and value of security testing the Smart Grid infrastructure

    Marc M.J. Hullegie, Managing Director, Senior Consultant Information Governance , VEST INFORMATION BV

  • Penetration testing, what is on a hackers mind
  • The (non) value of Security testing on Component level
  •  Security testing, is it an objective or an attribute of quality
  •  A tick in the box or a process
  • clock

    16:00

    Short and long term strategies for securing the Smart Grid

    Joshua  Pennell

    Joshua Pennell, Founder and President , IOActive

  • Security by design
  • Lack of Authentication
  • Encryption and authorization
  • Long term tactics, and Security Development LifeCycle
  • Cooperation of key stakeholders to fully realise the Smart Grid promise
  • clock

    16:30

    Cyber security lessons from Financial Services

    Owain Powell-Jones , Founder and Principal of Apurien, Apurien Ltd

    • Projecting security out end to end
            -Sharing secrets and securing access across open networks and multiple devices
    • United we stand
            -The essential role of co-operation and data sharing
    • Case Study: The Payment Card Industry Data Security Standard
             -The advantages and difficulties of a mandated standards driven approach to common security
    • A Black and White Hat industry
             -The cold war that is cybersecurity and its arms dealers

    clock

    17:00

    Closing Key Note Case Study: Grid Cyber Security in New York City

    Patricia  Robison

    Patricia Robison, Smart Grid Project Manager, Con Edison of New York, Inc.

     

  • Extending Cyber Security to support Smart Grid in New York City
  • Integrating Cyber Security Controls within the Smart Grid Framework
  • Implementing Risk Based Approach to Cyber Security Polices and Integration
  • Complying with NIST and IEC guidelines for Cyber Security
  • Establishing Multi-layer protection for Smart Grid Communications Components
  • Extending Cyber Security from the Utility to the customer and the DR aggregators

     

  • clock

    17:30

    Chairman’s Closing Remarks and Close of Day Two

    Workshops

    Introduction to Smart Meter Penetration Testing
    Workshop

    Introduction to Smart Meter Penetration Testing

    Marriott Hotel Regents Park
    16 March 2011
    London, United Kingdom

    Building a secure communications architecture for smart grid
    Workshop

    Building a secure communications architecture for smart grid

    Marriott Regents Park
    16 March 2011
    London, United Kingdom

    Marriott Hotel Regents Park

    128 King Henry’s Road
    London NW3 3ST
    United Kingdom

    Marriott Hotel Regents Park

    This 4 star north London hotel in zone 2 is the perfect destination for the astute business traveler as well as the leisure guest that knows how convenient north London hotels are, as a base from which to explore the city .Bond Street is just 3 stops from Swiss Cottage underground station on the Jubilee Line, so you can be shopping, exploring the sights and taking in one of London’s world-renowned West End shows in less than 15 minutes when you stay at this hotel near central London. At the same time, the hive of activity that is Camden Town, the chic shops, cafes and restaurants of Primrose Hill and ZSL’s London Zoo in Regents Park are all just a short walk from this hotel in north London.

    HOTEL BOOKING FORM

    Title

    SubTitle
    speaker image

    Content


    Title


    Description

    Download

    Title


    Description

    Download

    Title


    Description


    Download


    WHAT IS CPD?

    CPD stands for Continuing Professional Development’. It is essentially a philosophy, which maintains that in order to be effective, learning should be organised and structured. The most common definition is:

    ‘A commitment to structured skills and knowledge enhancement for Personal or Professional competence’

    CPD is a common requirement of individual membership with professional bodies and Institutes. Increasingly, employers also expect their staff to undertake regular CPD activities.

    Undertaken over a period of time, CPD ensures that educational qualifications do not become obsolete, and allows for best practice and professional standards to be upheld.

    CPD can be undertaken through a variety of learning activities including instructor led training courses, seminars and conferences, e:learning modules or structured reading.

    CPD AND PROFESSIONAL INSTITUTES

    There are approximately 470 institutes in the UK across all industry sectors, with a collective membership of circa 4 million professionals, and they all expect their members to undertake CPD.

    For some institutes undertaking CPD is mandatory e.g. accountancy and law, and linked to a licence to practice, for others it’s obligatory. By ensuring that their members undertake CPD, the professional bodies seek to ensure that professional standards, legislative awareness and ethical practices are maintained.

    CPD Schemes often run over the period of a year and the institutes generally provide online tools for their members to record and reflect on their CPD activities.

    TYPICAL CPD SCHEMES AND RECORDING OF CPD (CPD points and hours)

    Professional bodies and Institutes CPD schemes are either structured as ‘Input’ or ‘Output’ based.

    ‘Input’ based schemes list a precise number of CPD hours that individuals must achieve within a given time period. These schemes can also use different ‘currencies’ such as points, merits, units or credits, where an individual must accumulate the number required. These currencies are usually based on time i.e. 1 CPD point = 1 hour of learning.

    ‘Output’ based schemes are learner centred. They require individuals to set learning goals that align to professional competencies, or personal development objectives. These schemes also list different ways to achieve the learning goals e.g. training courses, seminars or e:learning, which enables an individual to complete their CPD through their preferred mode of learning.

    The majority of Input and Output based schemes actively encourage individuals to seek appropriate CPD activities independently.

    As a formal provider of CPD certified activities, SAE Media Group can provide an indication of the learning benefit gained and the typical completion. However, it is ultimately the responsibility of the delegate to evaluate their learning, and record it correctly in line with their professional body’s or employers requirements.

    GLOBAL CPD

    Increasingly, international and emerging markets are ‘professionalising’ their workforces and looking to the UK to benchmark educational standards. The undertaking of CPD is now increasingly expected of any individual employed within today’s global marketplace.

    CPD Certificates

    We can provide a certificate for all our accredited events. To request a CPD certificate for a conference , workshop, master classes you have attended please email events@saemediagroup.com

    Event Title

    Headline

    Text
    Read More

    I would like to speak at an event

    I would like to attend an event

    I would like to sponsor/exhibit at an event

    SIGN UP OR LOGIN

    Sign up
    Forgotten Password?

    Contact SAE Media Group

    UK Office
    Opening Hours: 9.00 - 17.30 (local time)
    SAE Media Group , Ground Floor, India House, 45 Curlew Street, London, SE1 2ND, United Kingdom
    Tel: +44 (0) 20 7827 6000 Fax: +44 (0) 20 7827 6001
    Website: http://www.smgconferences.com Email: events@saemediagroup.com
    Registered in England - SMi Group Ltd trading as SAE Media Group




    Forgotten Password

    Please enter the email address you registered with. We will email you a new password.

    Thank you for visiting our event

    If you would like to receive further information about our events, please fill out the information below.

    By ticking above you are consenting to receive information by email from SAE Media Group.
    Full details of our privacy policy can be found here https://www.smgconferences.com/privacy-legals/privacy-policy/.
    Should you wish to update your contact preferences at any time you can contact us at data@smgconferences.com.
    Should you wish to be removed from any future mailing lists please click on the following link http://www.smgconferences.com/opt-out

    Fill in your details to download the brochure

    By submitting this form you agree to our privacy policy and consent to receiving communications, you may opt out at any time.