Visitors to the Yokogawa exhibition booth on the second day of Gastech 2026 in Bangkok, Thailand, which attracted nearly 60,000 attendees, would have noticed the prominently displayed announcement marking the launch of the company’s first-ever Industrial Cyber Resilience Center (ICRC). The center was unveiled alongside Yokogawa’s extensive showcase of industrial automation and software solutions for the energy sector.
Located at the Yokogawa regional headquarters in Singapore to serve Southeast Asia, Australia, New Zealand, and Taiwan, the ICRC aims to help organizations identify cybersecurity capability gaps, boost cyber resilience, and recover safely from cyber incidents, all through a comprehensive portfolio of cybersecurity training, solutions, and services.
The launch of the ICRC takes place against a background of a rapidly evolving and complex cybersecurity threat landscape, which makes it all the more important that industrial organizations, many of which continue to rely on IT-centric response playbooks that are not inherently designed to address the safety, availability, and operational continuity requirements of OT systems, make strengthening cyber resilience a clear priority.

The launch announcement of the Industrial Cyber Resilience Center at Gastech 2026
To find out more about this changing cyber threat environment and how the ICRC can help companies meet new cybersecurity challenges, ARC spoke with Charles Lim, Head of Digital Security Solution at Yokogawa Engineering Asia, where his responsibilities span the cyber resilience lifecycle, including risk and regulatory assessments, secure IT/OT architecture design, monitoring and incident readiness, recovery planning, and workforce capability development.
ARC: How has the OT cyber threat landscape changed in recent years, and what impact is AI having on industrial cybersecurity?
AI is rapidly transforming the cybersecurity landscape for both attackers and defenders. Threat actors are increasingly using AI and automation to identify vulnerabilities, execute more sophisticated attacks, and operate at unprecedented speed and scale. At the same time, AI is enabling organizations to detect, respond to, and recover from threats more effectively.
A common challenge across all industries is the convergence of IT and OT environments. While digitalization initiatives have improved operational efficiency and visibility, they have also expanded the attack surface. As connectivity increases, cybersecurity can no longer be viewed as solely an IT issue. It requires active engagement from operations teams, engineers, business leaders, and cybersecurity professionals alike.
This is especially important in industries such as refining, where priorities extend beyond cybersecurity to include safety, product quality, operational availability, and rapid recovery of critical industrial processes.
As industrial organizations continue to digitalize, cyber resilience is becoming just as important as cyber defense. The ability to recover safely and efficiently from an incident is increasingly becoming a key differentiator.
ARC: What are some of the biggest misconceptions industrial companies have about cyber threats and how to mitigate them?
One of the most common misconceptions is the belief that a cyberattack is unlikely to happen to their organization. The reality is that the question is no longer whether an organization will experience a cyber incident, but when it will occur and how prepared it will be to respond and recover. Organizations need to be ready for cyber threats at all times to safeguard critical data and maintain operational continuity.
Another misconception is that cybersecurity is solely the responsibility of the IT department. In reality, cyber resilience is everyone's responsibility. Employees across the organization all play a role in protecting critical operations and building a resilient security culture.
We also see organizations assume that stronger cybersecurity simply means investing in more tools or more advanced technologies. However, effective cybersecurity is not just about technology. It requires an integrated approach that aligns people, processes, workflows, and systems while addressing actual risks and operational gaps.
There is also a perception that cybersecurity is prohibitively expensive. The truth is that organizations can improve resilience progressively based on their level of cyber maturity, risk profile, and business objectives.
This is one of the reasons we launched the new Industrial Cyber Resilience Center. The ICRC aims to help organizations build end-to-end cyber resilience by (1) assessing and identifying vulnerabilities; (2) helping organizations strengthen their defense capability and workforce development; and (3) providing realistic cyber drills to equip them with the ability to recover quickly and safely from cyberattacks.

The three-step ICRC framework
ARC: Do you find that the level of cyber awareness and cyber readiness varies across industries?
Cyber awareness and readiness do vary across industries, but perhaps more importantly, they vary according to an organization's leadership priorities, risk profile, regulatory environment, and level of cybersecurity maturity.
Industries such as oil & gas, chemicals, power generation, utilities, and other critical infrastructure sectors generally demonstrate higher levels of awareness of OT cybersecurity. This is because the consequences of a cyber incident can extend far beyond financial losses to include safety, environmental, and operational impacts. As a result, many organizations in these sectors have invested significantly in cybersecurity programs, governance frameworks, and resilience initiatives.
Organization-wide cyber exercises are becoming increasingly important. These exercises help teams develop and practice the skills needed to detect, respond to, and recover from incidents while maintaining safe and reliable operations. Through the ICRC, Yokogawa supports organizations with resilience assessments, capability development programs, realistic training environments, and cyber drills that strengthen operational preparedness.
ARC: Given the greater emphasis and spending on IT security compared with OT security, what skills and resources are generally lacking in industrial cybersecurity teams?
One of the biggest gaps is the shortage of professionals who can bridge both IT and OT domains. Many cybersecurity practitioners have strong IT security backgrounds, but industrial environments require a deep understanding of control systems, operational processes, safety requirements, and plant operations. Effective industrial cybersecurity depends on specialists who understand how cyber risks can affect physical processes and operational performance.
A second challenge is cyber resilience and incident response preparedness. While many organizations have invested heavily in preventive security technologies, fewer have developed and regularly tested their ability to respond to and recover from cybersecurity incidents in OT environments. Incident response in industrial operations requires different decision-making processes because safety, production continuity, and asset integrity must all be considered alongside cybersecurity concerns.
A third gap is capability development and hands-on training. Industrial cybersecurity cannot be mastered through policies or classroom instruction alone. Teams need realistic exercises, cyber drills, and simulation environments, which are all provided at the Industrial Cyber Resilience Center. These allow them to experience and respond to incidents in a controlled setting before they encounter a real-world event.

Teams need realistic exercises, cyber drills, and simulated environments to adequately prepare for real-world cyber incidents, says Charles Lim
ARC: Finally, what parting advice would you give to industrial companies anxious to improve their levels of cybersecurity resilience?
A key aspect of my role includes connecting business leaders, cybersecurity specialists, and plant operations teams, while also ensuring the solutions we bring to market reflect the realities of industrial environments, including legacy systems, long asset lifecycles, and stringent operational requirements.
But for me, the real measure of industrial cybersecurity is not how many tools an organization deploys. Rather, it is ensuring that you have the right combination of people, processes, and technology working together to protect critical operations and maintain resilience in an increasingly complex threat environment. It is also whether people can make the right decisions, critical processes remain safe, and operations can recover with confidence when disruption occurs.
Through our new Industrial Cyber Resilience Center in Singapore, Yokogawa can help customers strengthen their overall cybersecurity posture and operational resilience, so they can digitalize with confidence without compromising safety, reliability, or continuity.