2026 INFCIRC/908 Regional Workshop – Finland

Addressing Evolving Operational Technology
Impacts for Insider Threat Mitigation and Supply Chain Security
June 16-18, 2026
Helsinki, Finland
Title:
INFCIRC/908 Regional Workshop on Addressing Evolving Operational Technology Impacts
for Insider Threat Mitigation and Supply Chain Security
Goal:
OT systems combine hardware and software to control and automate physical processes in industry, and as a result, nuclear and radiological facilities increasingly rely on sophisticated OT for precise control and monitoring of industrial processes. This three-day workshop will explore how disruptions to these systems can have serious consequences, because the complexity and evolution of OT systems broadens the attack surface, introducing new vulnerabilities that can be exploited by both insider and external threats
Outcome:
A compendium of good practices for ITM when considering, introducing, and using OT at nuclear and radiological facilities from an ITM perspective
Dates:
June 16-18, 2026
Location:
Helsinki, Finland
Key Topics:
- Supply chain risk management
- Supply chain standards development
- Risk-based approaches to vulnerability management of OT for enhanced security and reliability Advanced performance testing and evaluation of OT systems to enhance insider resilience
Agenda
TUESDAY, JUNE 16th
| TIME | TOPIC | SPEAKER |
|---|---|---|
| 0815 – 0900 | Arrival to STUK, badging | |
| 0900 – 0915 | Welcome | Tomi Routamo / Director STUK Paula Karhu / Tommi Uotila STUK |
| 0915 – 0930 | INFCIRC/908 – International insider threat mitigation working group: 10th Anniversary of INFCIRC-908: Sharing Experience on Emerging Threats of Cybersecurity and Artificial Intelligence | Erin McLaughlin / DOE-NNSA / US |
| 0930 – 1015 | Psychological perspective: How does an insider act? | John Landers / INL / US Hannamiina Tanninen / Supo / Finland |
| 1015 – 1045 | Coffee Break/Group photo | |
| 1045 – 1125 | Overview on how to mitigate insider risks in general | Paula Karhu / STUK / Finland Lisa De Laet / FANC / Belgium |
| 1125 – 1205 | Panel: OT, Supply Chain Security, and AI Impact on Insider Threat Mitigation | Moderated by Rodney Busquim / IAEA |
| 1205 – 1245 | Insider threat in OT environments – How to identify and manage risks in practice? How Insider Risk Develops in OT Environments | Shannon Eggers / INL / US John Landers / INL / US |
| 1245 – 1345 | Lunch | |
| 1345 – 1445 | Interactive exercise part 1 | |
| 1445 – 1515 | Coffee Break | |
| 1515 – 1600 | The Cyber Fundamentals Framework: Use in an OT Environment | Johan Klykens / CCB / Belgium |
| 1600 – 1645 | Prerequisites for criminal investigation | Aku Limnell / NBI / Finland |
| 16:45 – 17:00 | Day closing | |
WEDNESDAY, JUNE 17th
| TIME | TOPIC | SPEAKER |
|---|---|---|
| 0900 – 0915 | Day Opening | |
| 0915 – 1000 | When trust turns to risk: Insider cyber incidents | Claudia Quester / GRS |
| 1000 – 1030 | OT Supply Chain Visibility at the Field Level | Shannon Eggers / INL / US |
| 1030 – 1045 | Computer Security Capabilities for Nuclear Security: IAEA’s OT and AI Activities | Rodney Busquim / IAEA |
| 1045 – 1115 | Coffee Break | |
| 1115 – 1200 | Supply chain management in OT environments | Johan Klykens / CCB / Belgium |
| 12:00 – 1245 | Component-level security: Can we trust the software in industrial components? | Saara Pesonen / Traficom / Finland |
| 1245 – 1345 | Lunch | |
| 1345 – 1430 | Training & awareness in OT environments – How to train staff and subcontractors? “10 lessons Learnt from the I&C Modernisation Regarding Cyber Security” | Marko Laimi & Pekka Nuutinen / TVO and Marko Mäki & Pekka Huhtinen / Fortum / Finland |
| 1430 – 1515 | Interactive exercise part 2, 3 & 4 | |
| 1515 – 1545 | Coffee Break | |
| 1545 – 1645 | Exercise Debrief | |
| 1645 – 1700 | Day Closing |
THURSDAY, JUNE 18th
| TIME | TOPIC | SPEAKER |
|---|---|---|
| 0900 – 0915 | Day opening | |
| 0915 – 1000 | Future Trends | Mikko Hyppönen / Sensofusion / Finland |
| 1000 – 1030 | Coffee Break | |
| 1030 – 1115 | So you want to build an OT SOC – Tales from the trenches, OT SOC from operator point of view | Karo Vallittu / Elisa Oyj / Finland |
| 1115 – 1200 | How to practically implement an OT SOC in a nuclear power plant – Why traditional SOCs fail in OT environments and what makes an OT SOC different | Eric Eifert / AIT Austrian Institute of Technology GmbH |
| 1200 – 1245 | Lunch | |
| 1245 – 1330 | Weaponizing the AI-Insider Threat Nexus: How Threat Actors Leverage AI | Audrey Crowe / Canadian Nuclear Laboratories / Canada |
| 1330 – 1415 | Discussion on good practices and way forward | Frank Wong / LLNL / US |
| 1415 – 1430 | Workshop closing | DOE / NNSA / US |


