Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Claroty: OT Security Trends: Data Centers, Retail & AI Governance

Claroty
06/19/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


would love to talk about what you are seeing around the show floor and what's new in the market of cyber physical systems. Yeah, cyber physical systems has had a really good year. We've been doing hospitals and we've been doing factories, we've been doing all these really hard projects. Now we have new people coming and are attracted to the CPS problem because they're realizing how important building management systems are, how important physical spaces are, and those two that are specifically, and we've had a lot of activity on this week, is data centers and then retail. So data centers have a really, really unique OT challenge, right? Heat and, or sorry, cooling and energy are super important for them, and if they don't have access to those controls because of a threat actor, well then that's a huge problem for all this AI stuff we're trying to do. So security and data centers is really coming into understanding what the physical presence in those data center looks like, and then what do we need to do on top of that. Yeah. And then the other really fun ones retail, because we've got people moving in and out of places, we have logistics centers, we have sometimes manufacturing, and having a multi-faceted supply chain issue is causing them a lot of attention on how are we handling these systems. From point-of-sale to factory floor and connecting that with one thing of security, rather than like cut jumps and different tool sets and different theaters, they're really wanting a more harmonious look. Yeah, a full picture of their environment. What do you see bringing in a data center security team that they're most interested in, or most worried about, that has made them realize they need a dedicated CPS security solution? Number one, kinetic theaters, right? There's open theaters of war right now, and those people are starting to put their finger in anything they see as attractive. Data centers have HVAC problems, they're the same exact HVAC problems we've been dealing with for 20 years. Target. Target, yeah, same exact thing. The fish tank thermometer at the Vegas casinos, right? Those things are still present. We haven't solved those, and now data centers are realizing they have a billboard that is an HVAC control system that has been targeted in other theaters that we just haven't seen that present. If you couple that with their clients' expectations of reliability of uptime of $99.99, they're really focused on what do we do around this system, how do we surround it as best as we possibly can, and that's been the fun realization of just how similar their challenges are to legacy manufacturing. Yeah, in even hospitals, and I imagine some of the same global and economic pressures are impacting retail as well, and all of that makes supply chains really interesting, so is that kind of a similar motivation we see? I think what's changed in retail is the knowledge that the way we've addressed customers in a shop floor isn't the same, right? There's a lot more IOT devices coming into those theaters and trying to see what people are looking at, how they're moving inside of a store, how can we capture their social media presence of a client before the client walks in the door? So they're bringing a lot more digital transformation to the retail sector, and that's coming with a lot of weird IOT devices that just look funky and are built typically without securities knowledge and are showing up in the retail sites, and they need that one single pane of glass of security from when the person walks in the door in retail to where the product has been shipped from, to where the product's been created, and we need that single chain of cyber custody to make sure that nothing in the way gets disrupted, because if you miss that one window for that client, they don't come back. Yeah, and that's your opportunity. Well, those are fascinating. Thank you so much. What else are you looking forward to about this week? Obviously AI is the whole buzz. One vendor even did like an anti-AI zone, which I thought was really funny. I think really coming to terms with how to build governance around all these AI engines that we're building. We see that in the operational theater with a lot of OT operators are using Claude and using Gemini to do PLC programming, and that's El Dangeroso. That's a problem. So finding the governance path around AI, especially in critical infrastructure, I think is really important. It's too flippant to just build some agentic agent and plug it into a power plant, right? That's not wise. So what are we doing from the governance perspective around these AI tools to make sure we don't develop our own worst enemy? Amazing. Well, thanks so much for your time. Enjoy the rest of the week.

TL;DR

  • Data centers are prioritizing CPS security due to HVAC vulnerabilities that could disrupt cooling systems critical for AI infrastructure, facing the same building management system threats that affected Target and other high-profile breaches.
  • Retail organizations are seeking unified security visibility across their entire supply chain—from manufacturing to point-of-sale—as digital transformation introduces IoT devices for customer analytics that create new attack surfaces.
  • AI governance in operational technology environments is emerging as a critical concern, with OT operators using AI tools like Claude and Gemini for PLC programming without adequate safety frameworks, creating potential risks in critical infrastructure.

Summary

In this RSA Conference 2026 interview, Claroty Field CTO Sean Tufts discusses emerging trends in cyber-physical systems (CPS) security, highlighting two sectors experiencing significant growth in OT security adoption: data centers and retail. Data centers face unique operational technology challenges around cooling and energy management, where threat actors targeting HVAC systems could disrupt critical AI infrastructure. The retail sector is grappling with digital transformation that introduces numerous IoT devices for customer analytics and in-store experience enhancement, creating security gaps across supply chains from manufacturing to point-of-sale. Tufts emphasizes that these sectors are discovering their OT vulnerabilities mirror the same HVAC and building management system weaknesses that have plagued other industries for decades, from the Target breach to the Vegas casino fish tank thermometer incident. The conversation concludes with concerns about AI governance in operational environments, particularly the risky practice of OT operators using tools like Claude and Gemini for PLC programming without proper oversight frameworks.

Chapters

0:00 - Introduction from RSA 2026
0:16 - CPS Market Growth Overview
0:38 - Data Center OT Challenges
1:04 - Retail Security Complexities
1:35 - Data Center Threat Landscape
2:47 - Retail Digital Transformation
3:49 - AI Governance Concerns

Key Quotes

1:45 "Number one, kinetic theaters, right? There's open theaters of war right now, and those people are starting to put their finger in anything they see as attractive."
1:54 "Data centers have HVAC problems, they're the same exact HVAC problems we've been dealing with for 20 years. Target."
4:07 "We see that in the operational theater with a lot of OT operators are using Claude and using Gemini to do PLC programming, and that's El Dangeroso."

FAQ

Why are data centers suddenly prioritizing OT security?

Data centers are realizing their HVAC and cooling systems face the same vulnerabilities that have been exploited in other sectors for 20 years, from the Target breach to casino incidents. With AI infrastructure requiring 99.99% uptime and active threat actors targeting critical infrastructure, they need dedicated CPS security to protect cooling and energy management systems that are essential for operations.

What makes retail environments challenging for CPS security?

Retail organizations are implementing numerous IoT devices for customer analytics and in-store experience without built-in security, while also needing visibility across multi-faceted supply chains that include manufacturing, logistics centers, and point-of-sale systems. They require a unified security approach rather than disconnected tools across different operational theaters.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • OT
  • IoT Security
  • Critical Infrastructure
  • AI & Machine Learning
  • Executive Briefing
  • Threat Intelligence
  • Cyber-Physical Systems Security
  • Data Center OT Security
  • Retail IoT Security
  • HVAC Vulnerabilities
  • Supply Chain Security
  • Building Management Systems
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Claroty: OT Security Trends: Data Centers, Retail & AI Governance

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Taking Control of You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-taking-control-of-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                Agentic Trust in Practice: Enhancing the Human Experience
                https://www.truthinit.com/index.php/channel/2026/agentic-trust-in-practice-enhancing-the-human-experience/
              • 07/14/2026
                11:00 AM
                07/14/2026
                Discover the Latest Innovations in Netwrix 1Secure During This Technical Session
                https://www.truthinit.com/index.php/channel/2014/discover-the-latest-innovations-in-netwrix-1secure-during-this-technical-session/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version