Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Claroty: Establishing OT Cybersecurity Baselines for Factories

Claroty
07/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


environment? So in my world, my company is highly decentralized, so it adds a little bit more, an extra wrench into that challenge. A lot of it is that initial training and awareness to let people understand why we're doing it, and then having a good mechanism to tell them how we're going to evaluate whether we're doing a good job or a bad job. So I hear that as kind of a common theme, just this cultural challenge that comes up. Is that something you think is a fair statement? A very fair statement, and with the diverse plants that we have, each different type of plant has a different culture as to how they approach things. So culture is huge. It also plays into that codependency between IT and OT, because they both need to work together. So you need that culture where they actually collaborate. Is cyber a little less of a foreign concept to the hardhats, so to speak, the engineers? Yeah, it's not as prevalent. We do have sites that are well along their way on that journey, and they fully understand it. They have their process to do their patching on their regular cadence. But then we have the others that it's not in their forefront. So in terms of our discussion about protecting the network at some measure of scale, how important is a strategy like segmentation to successfully complete this journey? So it doesn't really matter which framework you look at. Segmentation I think is number one. Everybody says you must have segmentation. In some of our facilities, segmentation is difficult, right? Because it's old equipment, et cetera, and it makes it a little bit harder. But segmentation is our primary piece that was our number one on our OT program, and we're still actively pursuing. I mean, I hear it's a pretty complex challenge for a lot of companies. What did you run into in terms of some of those challenges? How did you overcome them? It's an IT technical challenge for the most part, because typically the IT team owns the network until you get inside that cabinet. So from that perspective, a lot of plants didn't have the network guy, right? So they have good active directory, everything else. But from a network perspective, we found that some plants had to basically outsource to... We had third party providers that we vetted that could come in and actually help them, because yeah, it's just not something that they do on a daytime basis. So what would your role be, is just a matter of identifying the right assets to kind of... Our role was a little more high level, because Magna is like corporate group division. So obviously the plants are division level. So ours was more giving a high level idea of what segmentation should be. So where IT is, where that line is between IT and OT and that DMZ. But we kind of let the plants decide whether certain devices belong to DMZ, manufacturing, et cetera. So I wanted to dig into your talk here at Nexus a little bit about just how, again, this journey toward kind of automating firewall reviews, understanding, just using that as a kind of a baseline, the baseline standards that go into that. If you can kind of just maybe a two minute kind of overview of what you shared, that would be amazing. Okay. So again, we got to this position because we put firewalls in, but it's decentralized. So how do I know if they did a good job or a bad job? So what we did is we went through our basic configuration settings and we said, hey, these 15 items are important. So we should see these 15 items or not see them. We shouldn't see a public IP address, for example. But then we looked at the rules and there were different conduits, right, between IT, manufacturing, DMZ. So we had all those conduits and we knew that some were riskier than others. And so what we did is we said, we have a risky conduit and then we looked at rules and we broke them down basically on source, destination, destination port. What you had enabled in the rule would rate the rule from poor to best. So you take that poor to best, match it with the risk, blend it together and you get a score. So we scored each of the conduits, add it all up and here's your score out of 100. From my perspective, it was more, I needed an easy mechanism that I can kind of see, are we using the tool? That's all I was really looking for. As time goes on, I can see us upping the baseline to say, we expect you to have this score versus that score. Can you share some of those things that go into that baseline kind of establishing? It's interesting because what we did with the risk is we gave more points to a higher risk conduit, right? So that's where the points are associated. Coming into it, we expect that there's going to be more good rules than best rules. So the expectation is we're going to have this baseline here, but allowing the plants to understand that here's how we expect to see things, gives them that feedback to know that, okay, so I need to go do X. I need to add these rules or be more specific in my rules, which reduces the risk while bringing up their score. So it's trying to help them understand what they need to do versus just kind of saying you need better rules. I mean, every OT environment is obviously different, but I mean, do you see this being applicable elsewhere, any kind of factory setting, any kind of OT setting, this approach? Yes. I believe the approach can be used at any place where you're doing OT. As long as you have a firewall, I think being able to look at it and kind of say, how well are you using this tool? A different plant might have a different risk ratings for their conduits, but that's the flexibility of the tool. And in terms of the outputs, what are you specifically doing with that information as a matter of just better tuning of the firewall or were there eye openers maybe you didn't expect? Well, actually, this is all part of our OT KPI. So this feeds into our KPI of how well a plant is doing our OT program. So that was the initial use of it. But last year, Jim Tassel from Kellanova was on and he showed a way to show the KPIs. So when you got your number, you could see where you went wrong. So I actually used his knowledge and can break down. So here's your configuration score. Here's where you did right. Here's where you did wrong. Same with the conduits, where you can improve. So we use that to kind of help move us forward. And in terms of just firewall configurations and rules, are there some must haves in there that you could share? From a configuration perspective, there are some. So we expect that we're going to see that it's clustered. We expect that there's going to be, we use Fortinet tooling. So we expect that there's a Fortinet EA enabled on there. So it's in support, etc. So there's certain things that we expect in that area. From the rule base, we expect certain criteria of, we want to see DMZ, we want to see MFG, we want to see IT. So that way we can look it down. We do not want to see an any zone, where you don't specify where you're coming from or where you're going to. So there's certain things that we expect and we rate them accordingly. And just kind of this journey toward automation, I mean, is there a point where you kind of know you're ready to turn it on? That's a very good question. So this idea came early this year, and it's taken us a while to go through, can I actually parse that firewall and look at it? What can I do? How would I rate it? And we went through all these pieces. It took a while to get there. Because we're decentralized, there's an onboarding process, so the site has to grant us access so we can actually read the config. So getting that data has been the initial challenge. Looking at the data and how we display it has also been something like, ooh, I guess we need to show it this way versus that way. I started with negative numbers. You start at 100 and you lose. But it was confusing when you're trying to display it because it just didn't make sense compared to all the other KPIs. So we had to change our ways.

TL;DR

  • Managing OT cybersecurity across decentralized manufacturing facilities requires addressing cultural challenges and varying maturity levels, with success depending on collaboration between IT and OT teams and clear performance evaluation mechanisms.
  • Network segmentation is the foundational priority for OT security programs, though implementation in legacy environments often requires third-party expertise and flexible approaches that balance corporate standards with plant-level operational realities.
  • Magna developed an automated firewall scoring system that rates configurations and rules against baselines, weighting riskier network conduits more heavily and providing plants with actionable feedback on how to improve their security posture.
  • The scoring system evaluates 15 critical configuration settings and rule specificity, feeding into OT KPIs that enable corporate oversight while empowering local teams to understand exactly where security improvements are needed.
  • Implementation challenges include onboarding decentralized sites to grant access, refining data visualization approaches, and establishing realistic baselines that expect more 'good' rules than 'best' rules while driving continuous improvement.

Cultural Challenges in Decentralized OT Environments

Jim Miller, Director of OT Cybersecurity at Magna, discusses the unique security challenges of managing cybersecurity across highly decentralized manufacturing facilities. Each plant operates with its own culture and varying levels of cybersecurity maturity, from sites with established patching cadences to those where security isn't a priority. The fundamental challenge lies in training and awareness—helping operational teams understand why security matters and providing clear mechanisms to evaluate their performance. Miller emphasizes the critical need for collaboration between IT and OT teams, noting that cultural alignment is essential for successful security implementation. The diversity of plant types adds complexity, as different manufacturing environments approach security with different mindsets and technical capabilities.

Network Segmentation as Foundation

Network segmentation emerges as the cornerstone of Magna's OT security program, consistently identified as the top priority across all major cybersecurity frameworks. However, implementation proves challenging in facilities with legacy equipment where segmentation is technically difficult. Miller's team takes a high-level approach, defining the boundaries between IT, OT, and DMZ zones while allowing individual plants flexibility in device placement. The technical execution typically falls to IT teams, but many plants lack dedicated network expertise, requiring third-party providers to assist with implementation. This segmentation strategy creates the foundation for the more advanced firewall management and risk scoring system that follows.

Automated Firewall Scoring and Risk Assessment

To address the challenge of evaluating firewall effectiveness across decentralized facilities, Miller's team developed an automated scoring system that rates firewall configurations and rules against established baselines. The system evaluates 15 critical configuration settings and analyzes firewall rules across different network conduits (IT-to-manufacturing, DMZ connections, etc.), with riskier conduits weighted more heavily. Each rule is rated from poor to best based on specificity of source, destination, and port definitions, then combined with conduit risk to generate an overall score out of 100. This approach provides clear, actionable feedback to plant teams, showing exactly where improvements are needed rather than vague directives to improve security. The scoring feeds into Magna's OT KPI dashboard, enabling corporate oversight while empowering local teams to understand and improve their security posture. The system expects certain must-haves including clustered firewalls, Fortinet support contracts, and properly defined zones—explicitly prohibiting 'any' zone configurations that lack specificity.

Chapters

0:00 - Complexity and Cultural Challenges
1:44 - Network Segmentation Strategy
3:22 - Corporate vs Plant-Level Roles
4:04 - Automated Firewall Review System
5:52 - Baseline Configuration Requirements
7:30 - KPI Integration and Outputs
8:27 - Must-Have Firewall Configurations
9:29 - Journey Toward Automation

Key Quotes

2:04 "It doesn't really matter which framework you look at. Segmentation I think is number one. Everybody says you must have segmentation."
4:30 "We got to this position because we put firewalls in, but it's decentralized. So how do I know if they did a good job or a bad job? ..."
5:03 "We have a risky conduit and then we looked at rules and we broke them down basically on source, destination, destination port. What you had enabled in the rule would rate the rule from poor to best."
6:36 "Allowing the plants to understand that here's how we expect to see things, gives them that feedback to know that, okay, so I need to go do X. I need to add these rules or be more specific in my rules, which reduces the risk while bringing up their score."
7:47 "This is all part of our OT KPI. So this feeds into our KPI of how well a plant is doing our OT program."

FAQ

What are the must-have firewall configurations for OT environments?

Essential configurations include clustered firewalls for redundancy, active vendor support contracts (such as Fortinet EA), and properly defined network zones (DMZ, manufacturing, IT). Rules must specify source and destination zones—'any' zone configurations that lack specificity are explicitly prohibited as they create unacceptable security risks.

How do you handle network segmentation when plants lack dedicated network expertise?

Many plants outsource to vetted third-party providers who can implement segmentation, as network engineering isn't typically a day-to-day capability at the plant level. The corporate team provides high-level guidance on where boundaries should exist between IT, OT, and DMZ, while allowing plants flexibility in determining which specific devices belong in each zone.


Categories:
  • » Cybersecurity » Network Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • OT
  • IoT Security
  • Network Security
  • Best Practices
  • Technical Deep Dive
  • Security Operations
  • OT Cybersecurity
  • Network Segmentation
  • Firewall Management
  • Risk Scoring
  • Decentralized Security Operations
  • IT-OT Convergence
  • Manufacturing Security
  • Security Baselines
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Claroty: Establishing OT Cybersecurity Baselines for Factories

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    22

                    Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                    07/22/202601:00 PM ET
                    • Aug
                      19

                      Becoming Agent Ready: Insights from Cyera's Expertise

                      08/19/202612:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 07/21/2026
                        04:00 AM
                        07/21/2026
                        Strategies for Managing AI Governance: Safeguarding App-to-LLM API Traffic
                        https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-safeguarding-app-to-llm-api-traffic/
                      • 07/22/2026
                        06:30 AM
                        07/22/2026
                        Insights and Strategies for Effective Data Privacy and Protection
                        https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-for-effective-data-privacy-and-protection/
                      • 07/22/2026
                        01:00 PM
                        07/22/2026
                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                        https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                      • 07/28/2026
                        01:00 PM
                        07/28/2026
                        Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                        https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                      • 07/29/2026
                        04:00 AM
                        07/29/2026
                        Real-Time Strategies for Safeguarding Against Prompt Injections
                        https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                      • 07/29/2026
                        01:00 PM
                        07/29/2026
                        Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                        https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                      • 08/19/2026
                        12:00 PM
                        08/19/2026
                        Becoming Agent Ready: Insights from Cyera's Expertise
                        https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version