Galina Antova on Securing Industrial Networks

TL;DR
Operational technology security starts with passive asset discovery, OT-specific threat detection, and practical segmentation that does not disrupt long-lived industrial systems. Galina Antova says IT security teams are increasingly assuming responsibility for OT protection as connected infrastructure, legacy devices, limited patching, and proprietary protocols expose organizations to operational disruption and provide attackers with potential entry points into corporate networks.
Transcript
Good morning. We're here at RSA 2019, and I'm Chenxi Wang, the GP of Reign Capital. We're here doing Women in Cyber interviews, and this morning I'm sitting down with Galina Antova. Good morning. Is that the right pronunciation of your name? Yeah, that's the right way, yeah. So Galina, you're the co-founder of Claroty. Uh, tell us a little bit abou... Read More
Key Insights
- Operational technology networks run essential physical processes across oil and gas, electric utilities, manufacturing, and building infrastructure. Their importance extends to ordinary systems such as lights, elevators, and fire suppression, so failures or compromises can affect daily life as well as corporate operations.
- OT environments are often blind spots for security teams because they historically received less specialized protection than IT environments. That lack of visibility makes them attractive targets and can allow attackers to use operational networks as convenient entry points into an organization's connected IT systems.
- Claroty was created to close a security gap of more than 25 years between IT and OT. Its approach focuses on technology purpose-built for operational networks, including passive asset discovery, detection of threats specific to OT, and virtual segmentation suited to industrial constraints.
- Industrial devices are designed for life cycles of 35 or 40 years, which creates security challenges unlike those of conventional software systems. Some environments still operate Windows XP, and operational requirements can make routine patching or replacing equipment difficult, impractical, or impossible.
- NotPetya and similar campaigns became a major executive wake-up call because they accidentally spread into manufacturing networks and stopped production. These incidents demonstrated that even attacks not aimed at industrial systems can cause serious operational damage when basic visibility and segmentation are absent.
- IT security teams are increasingly taking responsibility for protecting OT networks, particularly within Fortune 500 companies discussed in the interview. Consolidating accountability can create clearer ownership, streamline security operations, and establish budgets for protecting networks that engineering teams previously maintained without dedicated security responsibility.
- Purpose-built OT security is necessary because industrial networks use proprietary protocols and operate differently from standard IT systems. Vendors that merely repurpose broadly marketed machine learning or AI products may fail to address the specific communications, assets, threats, and operational limitations found in industrial environments.
- Virtual segmentation is presented as a practical alternative to physical segmentation in operational environments. Physical projects can require new field devices and take three to five years, while virtual approaches can help organizations separate and protect systems without relying on an extensive physical infrastructure overhaul.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is operational technology security?
Operational technology security protects the networks and devices that control physical operations and infrastructure. These environments include oil and gas facilities, electric utilities, manufacturing systems, lights, elevators, and fire suppression equipment. According to Galina Antova, security teams often lack visibility into these networks, even though their compromise can disrupt operations or provide an entry point into connected IT networks.
Q: Why are industrial control systems difficult to secure?
Industrial control systems are difficult to secure because their devices may remain in service for 35 or 40 years and can depend on legacy technology such as Windows XP. Patching may be impossible or operationally impractical, while some deployed devices lack remote update capabilities. Industrial networks also use proprietary protocols, so protection developed for conventional IT environments may not work effectively in OT settings.
Q: How did NotPetya change executive views of OT security?
NotPetya and similar campaigns showed executives that attacks do not need to target industrial networks directly to cause major operational damage. Their accidental spillover into manufacturing environments stopped production at multiple companies. The resulting disruption exposed missing fundamentals, including visibility and basic segmentation, and quickly moved OT security discussions to executive and board levels, where organizations began assigning budgets to address the risks.
Q: Who should be responsible for OT network security?
IT security teams are increasingly assuming responsibility for OT network protection, while OT engineering teams continue to focus on engineering and operations. Galina Antova says engineering groups were previously assumed to handle security even though it was not their job, leaving some networks without dedicated protection. Consolidated security ownership can clarify accountability, streamline decisions, and support a unified approach across converged IT and OT networks.
Q: How are IT and OT security becoming connected?
IT and OT security are becoming connected because their networks now exchange data to deliver business benefits, and attackers do not respect organizational divisions between separate security operations teams. The interview describes the network as truly converged. As a result, IT security organizations, particularly in Fortune 500 companies, are taking broader responsibility for protecting operational environments through consolidated leadership, budgets, visibility, and security processes.
Q: Why do industrial networks need purpose-built security tools?
Industrial networks need purpose-built security tools because they have proprietary protocols, specialized equipment, long asset life cycles, and severe limitations on patching or replacement. Galina Antova warns that products repurposed from general IT security, including offerings marketed with machine learning or AI, may not work in ICS environments. Effective capabilities include passive asset discovery and threat detection specifically designed around operational technology behavior.
Q: What is virtual segmentation for OT networks?
Virtual segmentation is a way to separate and protect operational network assets without relying entirely on a lengthy physical redesign. The interview presents it as an alternative to physical segmentation projects that may require installing new field devices and take three to five years. After establishing passive asset discovery and OT-specific threat detection, security providers can extend their capabilities toward this more practical segmentation approach.
Q: How did Galina Antova identify the industrial cybersecurity opportunity?
Galina Antova identified the opportunity while starting and running industrial cybersecurity services at Siemens, a major industrial control system vendor described in the interview as a company exceeding $100 billion. The role exposed her to the distinctive security challenges facing operational networks. She saw that major IT security companies were not developing technology for the domain, then joined her co-founders to create specialized solutions.
Summary & Key Takeaways
-
Operational technology networks support oil and gas operations, electric utilities, manufacturing, building lights, elevators, fire suppression systems, and other infrastructure. Claroty was founded to help close a security gap of more than 25 years between IT and OT by developing protection designed for the distinctive requirements of industrial environments.
-
Industrial systems present unusual security constraints because devices may remain deployed for 35 or 40 years, some environments still run Windows XP, and patching may be impractical. Many older field devices also lack remote update capabilities, creating the possibility that compromised equipment will remain vulnerable after an intrusion.
-
NotPetya and similar campaigns increased executive awareness because their accidental spread into manufacturing environments disrupted production. This exposure revealed missing fundamentals such as network visibility and segmentation. As boards and executives recognized the operational consequences, organizations began allocating budgets and placing OT security under consolidated IT security leadership.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator