Semperis is taking its feature-length documentary on cyberwar to 30 cities following a Black Hat USA premiere, using the screening programme to place crisis response and critical-infrastructure resilience in front of security and operational leaders. European stops include Frankfurt, Munich, Zurich, London, Hamburg, Paris, and Dublin before the tour concludes later in the year.
Midnight in the War Room was produced by Semperis Studios from more than 50 interviews and over 100 hours of conversations with chief information security officers, former hackers, journalists, and national-security figures. Contributors include former US National Cyber Director Chris Inglis, former CISA director Jen Easterly, former CIA director David Petraeus, WannaCry researcher Marcus Hutchins, and former SolarWinds CISO Tim Brown.
The film premiered at Black Hat on 5 August and the international roadshow is sponsored by Cohesity. Semperis is presenting the tour as the second phase of the documentary’s rollout, with screenings planned across Europe, North America, Asia-Pacific, and Latin America between September and November.
The fact that the documentary has been produced by a cybersecurity supplier should remain obvious. The tour is also a marketing exercise, and Semperis specialises in identity-system resilience. Its industrial relevance lies in the underlying problem being discussed rather than in treating a corporate film as independent analysis.
Cyber incidents affecting manufacturers and critical infrastructure increasingly create consequences outside the IT department. A compromised identity environment, unavailable domain service, encrypted engineering workstation, or forced network isolation can interrupt production even when the programmable logic controllers and physical machinery at the centre of the process remain untouched.
Modern factories depend on layers of software sitting around physical equipment. Production planning, laboratory systems, maintenance platforms, remote engineering tools, warehouse management, quality records, enterprise resource planning, and cloud services can all become operational dependencies. Losing enough of those systems can leave machinery technically capable of running but the organisation unable to operate it safely or productively.
Identity services are especially significant because they often sit upstream of many other applications. If credentials cannot be trusted or authentication infrastructure becomes unavailable, companies may have to disable access to large parts of their environment while investigators determine the scale of compromise.
That creates a recovery problem different from restoring one failed server. Organisations have to determine which systems can be trusted, which backups are clean, how privileged accounts will be recovered, what services must return first, and how operations will continue while the recovery sequence is still incomplete.
For industrial businesses, those choices immediately become commercial and engineering decisions. Restoring email may improve communication, but it will not restart a production line if operators still cannot reach manufacturing execution systems or maintenance records. Bringing production scheduling back online may achieve little if laboratory data needed to release finished batches remains unavailable.
Thomas LeDuc, Semperis chief marketing officer and executive producer and co-director of the film, said: “We made this film because the people who defend the world’s critical systems have never had their story told on their own terms.”
The documentary includes water and power systems, food supply chains, healthcare networks, and financial infrastructure among the critical services exposed to major cyber incidents. Those sectors differ technically, but they share one difficult characteristic: outages can create consequences for customers and wider society long before the affected organisation has completed its investigation.
Manufacturers have an additional complication because recovery of digital systems does not automatically mean the physical process can resume. Equipment may have stopped in an abnormal state, partly processed material may need to be discarded or requalified, and quality or traceability records may have become unavailable during the outage.
Operators also need confidence that control, monitoring, and safety systems are behaving as expected before restarting machinery. A ransomware incident can therefore generate mechanical inspections, cleaning, recalibration, batch investigation, and production planning work even where no attacker directly manipulated the industrial process.
That is why resilience extends beyond conventional prevention. Firewalls, endpoint security, identity controls, network monitoring, and employee training reduce risk but cannot guarantee that every intrusion will be stopped. Industrial organisations also need a credible answer to what happens after controls fail.
Network segmentation, tested backups, offline recovery information, privileged-access management, alternate communications, crisis exercises, and clear decision authority all contribute to that capability. Most are considerably less dramatic than the attack itself, yet their absence usually becomes visible at exactly the point when an organisation has the least time to correct it.
The global screening schedule reflects another aspect of the problem. Critical-infrastructure operators work under different national regulations, but many depend on the same enterprise software, cloud platforms, industrial equipment suppliers, identity architectures, and remote-access technologies. A successful attack technique can therefore migrate between sectors and countries far faster than physical industrial threats traditionally have.
The European leg begins in Frankfurt on 10 September, followed by Munich on 15 September and screenings in Zurich and London on 17 September. Hamburg follows on 22 September, with Paris scheduled for 20 October and Dublin on 5 November. Other stops include Boston, Washington, Sydney, Singapore, New York, Toronto, Mexico City, São Paulo, and Vancouver.
Those events will put Semperis in front of exactly the audience to which it sells security technology, so the commercial context requires no disguise. The wider issue remains valid regardless of sponsor: as factories and infrastructure connect more equipment to enterprise identities, remote services, cloud applications, and shared data platforms, the difference between a cyber outage and an operational outage continues to narrow.
Cyber resilience is therefore becoming an asset-management issue as much as an information-security one. Industrial machinery may remain in service for 20 or 30 years, while the software, credentials, servers, operating systems, and network architecture surrounding it change repeatedly during the same period. Every upgrade creates another potential dependency between physical equipment designed for longevity and digital infrastructure designed around much shorter refresh cycles.
The resulting problem is not solved by making plants less connected. Remote diagnostics, predictive maintenance, digital work instructions, cloud analytics, and integrated production data can create real operating benefits. The engineering requirement is to gain those benefits without allowing one compromised identity system or failed digital service to make an otherwise healthy factory impossible to run.
Semperis has chosen a feature-length film and a 30-city tour to make the case. Industrial operators have a less cinematic task: deciding which systems the business genuinely cannot operate without, testing how those systems would be recovered, and discovering weaknesses before an attacker performs the test for them.



