Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Venue: Club A (Floor 1) clear filter
arrow_back View All Dates
Thursday, October 8
 

10:50 CEST

Sponsored Session: Advancing Trust in Open Source: CIP IEC-62443-4-x Achievement and CRA Compliance Readiness - Dinesh Kumar, CIP Security WG Chair / Toshiba Software & Pasquale Nieddu, CIP Security WG / Siemens Mobility
Thursday October 8, 2026 10:50 - 11:30 CEST
With increasing regulatory pressure and evolving cybersecurity requirements, product teams must navigate complex standards while maintaining speed to market.

This session provides a practical, implementation-focused deep dive into achieving IEC 62443-4-x compliance for components, alongside insights into aligning with the EU Cyber Resilience Act (CRA).

We will showcase how the CIP Security Workgroup has developed precise engineering artefacts—including IEC layer test suites and supporting documentation—that significantly reduce the effort required for compliance.

In addition, we will examine recent investigations into CRA requirements and demonstrate how IEC 62443-4-x compliance can help bridge critical gaps toward CRA readiness.

Attendees will leave with actionable guidance, reusable assets, and a clear roadmap to streamline compliance efforts while future-proofing their products against regulatory demands.

Speakers
PN

Pasquale Nieddu

Job DevOps Engineer, CIP Security WG / Siemens Mobility
Pasquale Nieddu is a DevOps Engineer within the CoreShield Secure Operating Systems team at Siemens Mobility s.r.o. in Prague. Passionate about railways, open source, and Linux, he has been an active contributor to the Civil Infrastructure Platform (CIP) project since February 2025... Read More →
DK

Dinesh Kumar

CIP Security WG Chair / Toshiba Software
Dinesh Kumar is an experienced embedded software engineer specializing in Embedded Linux, secure boot, Debian package development, board support packages (BSPs), and Android application and framework development. His research interests include Embedded Linux, Linux kernel security... Read More →
Thursday October 8, 2026 10:50 - 11:30 CEST
Club A (Floor 1)

13:50 CEST

Sponsored Session: Building Secure and Compliant Critical Infrastructure with Open Source - Benjamin Weber, Hitachi Energy & Bernhard Denner, Hitachi Rail
Thursday October 8, 2026 13:50 - 14:30 CEST
Critical infrastructure operators face growing pressure to modernize their systems while maintaining the highest levels of security, reliability, and regulatory compliance in an era shaped by regulations such as the EU Cyber Resilience Act (CRA) and NIS2. In this session, Hitachi shares two real-world modernization journeys with open source from the energy and railway sectors.

The first half focuses on Hitachi Energy’s adoption of Embedded Linux and Yocto for next-generation grid automation products. Hitachi Energy actively contributes to the modernization of energy systems, making electricity more accessible worldwide. In product development, adopting Embedded Linux and Yocto enhances flexibility and maintainability, with strong legal compliance, license management, and open-source collaboration. Hitachi Energy is rolling out Linux-based energy grid automation products and this talk covers their transition to embedded Linux via Yocto, addressing industry protocol support, impacts of the EU Cyber Resilience Act, OSS license challenges, and navigating these within a slow-evolving sector.

The second half presents Hitachi Rail’s modernization of mission-critical railway management systems using Keycloak, an an open source identity and access management platform. As railway systems become increasingly interconnected, cybersecurity and identity management have become fundamental architectural concerns. We show how secure-by-design principles were applied to modernizing legacy environments, with Keycloak. We also demonstrate how Keycloak helps address several IEC 62443-4-2 requirements and provides a strong foundation for meeting emerging regulatory expectations such as CRA.


Speakers
avatar for Bernhard Denner

Bernhard Denner

Chief Architect, Hitachi Rail
Bernhard is the Chief Architect of a cloud-native application platform that forms the foundation of many Hitachi Rail products. With a strong background in IT system administration and software engineering, he began automating infrastructure long before “DevOps” became widely... Read More →
avatar for Benjamin Weber

Benjamin Weber

Business R&D Manager, Hitachi Energy
Benjamin holds a PhD in electrical engineering from ETH Zurich and is with Hitachi Energy in the role of "Team Lead and Project Manager Linux". He held various positions in diverse industries as firmware developer for Linux and other systems as well as design engineer for a fabless... Read More →
Thursday October 8, 2026 13:50 - 14:30 CEST
Club A (Floor 1)

14:40 CEST

Sponsored Session: LLM-Assisted Vulnerability Research in Yocto - Anders Heimer, Ericsson Software Technology
Thursday October 8, 2026 14:40 - 15:20 CEST
The Yocto Project provides several building blocks for supply-chain security, including pinned sources, checksums, source mirroring, SBOM support, and reproducible builds. These mechanisms are invaluable, but only as strong as the code behind them.

In this talk, I will describe a project in which I used LLMs to assist security research on selected Yocto Project components. I will explain how candidate findings were identified, manually triaged, reproduced, and filtered before being reported upstream.

The talk will cover how I separated real issues from false positives, assessed whether suspicious code patterns were exploitable, prepared reports that maintainers could act on, and upstreamed patches where appropriate.

Speakers
avatar for Anders Heimer

Anders Heimer

Senior Specialist Linux Build, Packaging and Integration, Ericsson Software Technology
Anders Heimer is a Senior Specialist at Ericsson Software Technology, where he provides Yocto expertise across Ericsson. His work focuses on embedded Linux, build systems, and software supply-chain and product security. He is a BitBake and OpenEmbedded contributor.
Thursday October 8, 2026 14:40 - 15:20 CEST
Club A (Floor 1)

16:40 CEST

OpenGrid: An Open-Source Electric Grid Modeling Ecosystem - Alice Yake, David Paolella, James Hewett & Ryan Attig, Breakthrough Energy
Thursday October 8, 2026 16:40 - 17:20 CEST
Modeling underlies the grid we all rely on. Every decision to build a new power plant or transmission line starts with a model run, yet planning models are often opaque, expensive, and difficult to replicate. That lack of transparency, along with uneven access to high-fidelity tools and data, breeds distrust and delay in the planning processes essential to decarbonizing the grid and expanding energy access worldwide. Open-source planning tools are growing in number and capability, but real barriers to adoption remain. OpenGrid aims to build a shared infrastructure foundation for open-source modeling, so open tools and data can become a credible industry standard. This session introduces the OpenGrid initiative, announced as a project under Linux Foundation fiscal sponsorship, covering both the thinking behind it, the plans to build it out and how you can get involved.
Speakers
avatar for David Paolella

David Paolella

Director, Research and Analytics, GRIDS, Breakthrough Energy

JH

James Hewett

Breakthrough Energy

RA

Ryan Attig

Breakthrough Energy
avatar for Alice Yake

Alice Yake

VP GRIDS, Breakthrough Energy
Alice Yake, Vice President of GRIDS at Breakthrough Energy, leads efforts to develop an open-source modeling ecosystem for delivering reliable, low-emission electricity globally, addressing the complexities of system design, regulations, and zero-carbon goals. With over 25 years of... Read More →
Thursday October 8, 2026 16:40 - 17:20 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any
 


Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -