Transcript
It's a pleasure to be here, thank you for the invitation, for participating in this tremendous conference of learning and exchange of experience with the actor. My name is Rodney, I work at Petrobras, the largest company in Brazil. I work in the oil and gas sector, with platforms, refineries, thermal power plants and gas treatment units. Perfect. And within the process of evaluation of tools and everything by Petrobras, what motivated Petrobras to look for a cybersecurity solution like Clarity? First of all, our need to gain more visibility within the OTI network. Our visibility was very little, very small. Only some antivirus solutions were installed and there was no other approach. So we needed a solution that gave more visibility, could assess the vulnerability of assets, as well as being in monitoring, covering the possible cyber attacks or anomalous events that could be happening in the OTI environment. Perfect. And since the implementation of the Clarity solution, how did the solution help to mitigate or prevent incidents within the business? Can you share an example, please? Yes, as we did not have an antivirus installed in the entire automation park, with the Clarity solution we had visibility of where there could be some malware installed, some unwanted communication, and we were able to mitigate, solve problems through the solution. We also had the opportunity to identify, despite having a network segregation, improper connections between the corporate environment and the OTI environment, which was quickly identified and treated with the implemented solution. Perfect. One more point, looking at Clarity, within the business, supporting the business, did it prevent any operational availability that could really help in the return to the business? Since we started a cyber security program in Petrobras, where several actions were taken, and one of the main objectives was to integrate the SI area with the IT and OTI areas. This integration allowed us to create a better alignment with the business, and raise the level of integration and cyber security. This facilitated the implementation of the Clarity solution, and this also showed the great gain of visibility and possibilities of cyber risks, and that the people in the business area, in the OTI area, were able to verify and observe how their own environment was. This proximity that we created in our cyber security program also gave us the opportunity of a return, of a request. With this solution that was implemented, could we have help to identify a problem that we are having, a recurring industrial plant trip, where we are not discovering what is the reason for the trip, and eventually the trip occurs. There was a fire and gas alert, where on the platform everyone had to move to a meeting point, when the fire brigade arrived at the point, nothing was happening, it was a false alarm. This was being repeated several times, but people were always used to going to the meeting point, avoiding any possible risk of a fire at the site. So we were called to verify. Could we identify the problem? At first, in the solution, there was no alert, no alarm, nothing abnormal, both cybernetic and operational integrity. However, we knew what equipment generated the alarm. So we collected all the communication and sent it to the business, so they know how the normal communication should work in that environment. With this, after the analysis of the business team, they saw that the communication, which was supposed to be only reading, was also writing. So there was a mistake in the communication driver, in which it was identified that the writing times were the ones that caused the trip in the plant. So this was a big gain, this alignment with the business, and looking for information about what could be the cause of the trips in that plant. With this, we created an internal alert at Clarote, so that every time there was a written occurrence of that communication driver, it would alert the business, with the imminence of a trip problem in the plant, until we, together with the manufacturer, were able to correct the operation of the driver to heal that problem. I see that we talk so much about this area of ours. Return on investment, or ROE. How difficult it is to measure a return on investment on cybersecurity solutions. But in this case, you were able to have a measurable return, let's say, for the business, which, of course, also supported you in your solution. Correctly. With this identification, there was a return for the business, for the investment we made in the solution, for a cybernetic monitoring, but we helped the business with an occurrence of abnormality of communication of some plant driver, avoiding all this chaos of moments of a trip on an offshore platform. Microsoft Mechanics www.microsoft.com www.microsoft.com