Meeting & Event Information

2026 03 Mar 06 Energy Sector Critical Infrastructure Safety, Cybersecurity, and Compliance

 

March 06, 2026
11:00 AM - 3:00 PM
Add to Calendar

 

Microsoft
750 Town and Country Blvd #1000
Houston, TX 77024
Directions

 Date:  March 6tth. 2026  
 Start Time: 11:30 CDT
 End Time:  1:30 CDT
 
Cost:  
  ISSA South Texas Members  $20
  Non ISSA South Texas Members:  $30
 
CPE Hours:  2  
Prerequisite:
  • Knowledge of basic OT/IT security and concepts
  • Fundamental knowledge of networking principles
 


Presentation Information:
Speaker: Dr. Tom Duffey
Title: Cybersecurity and Compliance Principal and Instructor (and former South Texas ISSA Education Director)
Company:

Knight Critical Infrastructure 

Bio:

Dr. Tom is an engineer, consultant, thought leader, project manager, instructor, and OT/IT cybersecurity and regulatory compliance professional with over 30 years of experience in the defense, energy, and healthcare sectors. His diverse experience also includes supporting multiple U.S. military branches. Dr. Tom spent over a decade as a defense contractor and was an ISSO and DIACAP/DoD RMF Program Manager for a three-star global military command before shifting his focus to industry. He holds multiple DoD 8570/8140 credentials and is a certified CMMC professional, lead assessor, and instructor.

Dr. Tom specializes in NIST, ISA/IEC, and ISO security frameworks, along with CMMC, NERC CIP, TSA SD02, HIPAA, and the DoD RMF regulatory mandates. He currently teaches ISA, TEEX, and CMMC classes. Throughout his career, Dr. Tom firmly believes in “growing” himself, others, and the organization while giving back to the security community. Therefore, he has participated in various NERC efforts and served in other supporting board and leadership roles for ISA Houston, South Texas ISSA, and the InfraGard Energy CSC. Teaching and learning remain two of Dr. Tom’s biggest passions.

Along with his doctoral dissertation on NERC CIP regulatory compliance, Dr. Tom has contributed to numerous security thought leadership efforts, including a World Economic Forum whitepaper on electric industry cyber resilience, and domain content for the EC-Council C|CISO certification Body of Knowledge.

Speaker:

Craig Wood

 


Title:

CEO

Company:

PSY Logistics Technology Partners (ISACA Programs Director (frmr South Texas ISSA Mentorship Director)

Bio:

Craig brings over 25 years of IT consulting and leadership experience as CEO of PSY Logistics Technology Partners. He specializes in information governance as a fractional CISO and CMMC assessor, helping businesses across the Houston metroplex build robust, scalable technology foundations through strategic alignment of cybersecurity and risk management. Throughout his career as a consultant,

Craig has delivered impressive results, including achieving 99% client retention while tripling as a Regional Manager at ERGOS Technology Partners, single-handedly building core ERP infrastructure for Tricon Energy as Global Director of Infrastructure and Security, and implementing digital automation solutions that increased operational efficiency by 40%. His global experience includes establishing secure collaboration, shared services, and support across more than 30 countries and building comprehensive IT service divisions from the ground up.

Craig is passionate about servant leadership and believes in empowering others to overcome limitations. He holds extensive experience in project management, risk management, business IT strategy, business continuity planning, virtualization architecture, cybersecurity, and digital transformation initiatives.

Beyond his professional achievements, Craig is an avid cyclist who completed the 450-mile RAGBRAI ride across Iowa, and he’s working toward certification in Therapeutic Gaming to volunteer with children facing chronic and terminal illnesses. He and his wife, Natasha, enjoy volunteering and staying active when Houston weather permits.

Abstract:

Operational technology (OT) systems provide support for national critical infrastructure spanning multiple industries. The U.S. Cybersecurity and Infrastructure Agency (CISA) supports 16 critical infrastructure sectors, including Energy. We live in a growing world of connectivity and a constantly evolving threat landscape. The days of “air-gapped” OT systems running proprietary protocols have gone by the wayside, and increasingly devices that originally were isolated from the outside world have built-in network capabilities. While increasing convenience and flexibility, such dynamic changes have resulted in the ability for global access via the Internet, along with a growing number of cyberattacks like those impacting the Ukraine in 2015/2016.

The juxtaposition of traditional information technology (IT) with OT environments, has resulted in realized physical consequences from cyberattacks. A knowledge gap exists because classic engineering focuses primarily on physics instead of digital risk. At the same time, IT curricula do not usually address plant environments or industrial control systems (ICS) like supervisory control and data acquisition (SCADA) and distributed control systems (DCSs) or common OT components like programmable logic controllers (PLCs) or a growing number of Industrial Internet of Things (IIoT) devices. Network switches and other equipment require ruggedized versions for use in OT environments. CMMC, a Department of War program to protect sensitive government information, including Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) for both IT and OT environments entered the first stage of enforcement, now requires energy defense contractors to undergo rigorous assessments to secure contracts.

Traditional IT security frameworks and regulations are insufficient for managing such challenges, and bridging the IT-OT gap requires a paradigm shift, incorporating proactive cyber-informed engineering (CIE) principles, along with OT-focused safety and cybersecurity risk mitigation measures. This session will discuss how organizations can leverage such principles and use countermeasures from the International Society of Automation/International Electrotechnical Commission (ISA/IEC) 61511 and 62443 and the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-82 security frameworks, along with North American Electric Reliability Corporation (NERC) critical infrastructure protection (CIP) standards and the Transportation Security Authority (TSA) pipeline security directives to protect their energy OT environments. Additionally, the session will touch on Defense Acquisition Regulation Supplement (DFARS) and NIST SP 800-171 requirements for energy sector entities with government contracts.

Register Now

If the registration button (above) doesn't work, use this link to go to the EventBrite page - https://www.eventbrite.com/e/issa-south-texas-chapter-meeting-january-25-2024-tickets-728310776137?aff=ebdsoporgprofile