
In manufacturing environments, every minute of downtime can impact production, revenue, and customer commitments.
Yet when a cyber incident occurs, many organizations struggle to quickly understand what actually happened - especially when data is distributed across endpoints, plants, and remote locations.
This session will walk through a realistic incident scenario, highlighting where typical approaches break down and how teams can respond more effectively under pressure.
What you'll learn
- How manufacturing organizations can reduce investigation time during active incidents
- Where visibility is typically lost across endpoints, cloud, and distributed environments
- How to quickly determine scope, impact, and affected systems
- Real-world scenarios including:
- ransomware
- insider risk
- suspicious activity
- How to improve collaboration between security, IT, and investigation teams
During the session, we will work through a practical investigation workflow, including:

Remote acquisition and triage of endpoint data

Rapid evidence collection during an active incident

Connecting artifacts across systems to understand impact

Building a defensible investigation - from collection to reporting
This is a small, interactive session designed for discussion and exchange—so we can share approaches and challenges across organizations.
As places are limited, we recommend securing your spot early.
Countdown to the Lunch & Learn
- Days53
- Hours20
- Minutes25
