Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Claroty: Petrobras Strengthens Critical Infrastructure Security

Claroty
07/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


It's a pleasure to be here, thank you for the invitation, for participating in this tremendous conference of learning and exchange of experience with the actor. My name is Rodney, I work at Petrobras, the largest company in Brazil. I work in the oil and gas sector, with platforms, refineries, thermal power plants and gas treatment units. Perfect. And within the process of evaluation of tools and everything by Petrobras, what motivated Petrobras to look for a cybersecurity solution like Clarity? First of all, our need to gain more visibility within the OTI network. Our visibility was very little, very small. Only some antivirus solutions were installed and there was no other approach. So we needed a solution that gave more visibility, could assess the vulnerability of assets, as well as being in monitoring, covering the possible cyber attacks or anomalous events that could be happening in the OTI environment. Perfect. And since the implementation of the Clarity solution, how did the solution help to mitigate or prevent incidents within the business? Can you share an example, please? Yes, as we did not have an antivirus installed in the entire automation park, with the Clarity solution we had visibility of where there could be some malware installed, some unwanted communication, and we were able to mitigate, solve problems through the solution. We also had the opportunity to identify, despite having a network segregation, improper connections between the corporate environment and the OTI environment, which was quickly identified and treated with the implemented solution. Perfect. One more point, looking at Clarity, within the business, supporting the business, did it prevent any operational availability that could really help in the return to the business? Since we started a cyber security program in Petrobras, where several actions were taken, and one of the main objectives was to integrate the SI area with the IT and OTI areas. This integration allowed us to create a better alignment with the business, and raise the level of integration and cyber security. This facilitated the implementation of the Clarity solution, and this also showed the great gain of visibility and possibilities of cyber risks, and that the people in the business area, in the OTI area, were able to verify and observe how their own environment was. This proximity that we created in our cyber security program also gave us the opportunity of a return, of a request. With this solution that was implemented, could we have help to identify a problem that we are having, a recurring industrial plant trip, where we are not discovering what is the reason for the trip, and eventually the trip occurs. There was a fire and gas alert, where on the platform everyone had to move to a meeting point, when the fire brigade arrived at the point, nothing was happening, it was a false alarm. This was being repeated several times, but people were always used to going to the meeting point, avoiding any possible risk of a fire at the site. So we were called to verify. Could we identify the problem? At first, in the solution, there was no alert, no alarm, nothing abnormal, both cybernetic and operational integrity. However, we knew what equipment generated the alarm. So we collected all the communication and sent it to the business, so they know how the normal communication should work in that environment. With this, after the analysis of the business team, they saw that the communication, which was supposed to be only reading, was also writing. So there was a mistake in the communication driver, in which it was identified that the writing times were the ones that caused the trip in the plant. So this was a big gain, this alignment with the business, and looking for information about what could be the cause of the trips in that plant. With this, we created an internal alert at Clarote, so that every time there was a written occurrence of that communication driver, it would alert the business, with the imminence of a trip problem in the plant, until we, together with the manufacturer, were able to correct the operation of the driver to heal that problem. I see that we talk so much about this area of ours. Return on investment, or ROE. How difficult it is to measure a return on investment on cybersecurity solutions. But in this case, you were able to have a measurable return, let's say, for the business, which, of course, also supported you in your solution. Correctly. With this identification, there was a return for the business, for the investment we made in the solution, for a cybernetic monitoring, but we helped the business with an occurrence of abnormality of communication of some plant driver, avoiding all this chaos of moments of a trip on an offshore platform. Microsoft Mechanics www.microsoft.com www.microsoft.com

TL;DR

  • Petrobras implemented Claroty to gain visibility across OT networks in offshore platforms, refineries, and gas treatment facilities where previous coverage was limited to basic antivirus solutions
  • The solution identified malware infections, unauthorized IT-OT network connections, and communication anomalies that traditional security tools missed
  • Claroty helped diagnose recurring false fire alarms on an offshore platform by revealing a faulty communication driver that was writing data instead of only reading
  • The cybersecurity investment delivered measurable ROI by preventing production disruptions and eliminating costly platform evacuations caused by the driver malfunction

Visibility Challenges in Oil & Gas OT Environments

Petrobras, Brazil's largest oil and gas company, faced significant visibility gaps across its operational technology networks spanning offshore platforms, refineries, thermal power plants, and gas treatment facilities. Prior to implementing Claroty, the organization relied primarily on antivirus solutions with minimal network monitoring capabilities. This limited visibility prevented the cybersecurity team from effectively assessing asset vulnerabilities, detecting anomalous events, or monitoring for potential cyber attacks across critical industrial infrastructure. The need for comprehensive OT network visibility and threat detection drove Petrobras to evaluate dedicated industrial cybersecurity solutions.

Operational Impact and Business Value Realization

The Claroty deployment delivered measurable business value beyond traditional cybersecurity metrics. The solution identified malware infections and unauthorized connections between corporate IT and OT networks that bypassed network segregation controls. Most notably, Claroty helped resolve a recurring false alarm issue on an offshore platform where fire and gas detection systems triggered evacuations to muster points despite no actual emergency. By analyzing communication patterns captured by Claroty, the business team discovered a faulty communication driver that was writing data when it should only read, causing plant trips. This discovery enabled the team to create custom alerts and work with the manufacturer to correct the driver operation, preventing costly production disruptions and demonstrating tangible return on investment for the cybersecurity solution.

Chapters

0:00 - Introduction and Background
0:34 - Visibility Challenges at Petrobras
1:41 - Incident Prevention and Mitigation
2:44 - Business Alignment and Integration
4:13 - Troubleshooting Platform Alarms
6:40 - Measuring Return on Investment

Key Quotes

0:52 "First of all, our need to gain more visibility within the OTI network. Our visibility was very little, very small. Only some antivirus solutions were installed and there was no other approach."
1:14 "So we needed a solution that gave more visibility, could assess the vulnerability of assets, as well as being in monitoring, covering the possible cyber attacks or anomalous events that could be happening in the OTI environment."
4:13 "With this solution that was implemented, could we have help to identify a problem that we are having, a recurring industrial plant trip, where we are not discovering what is the reason for the trip, and eventually the trip occurs."
5:45 "With this, after the analysis of the business team, they saw that the communication, which was supposed to be only reading, was also writing. So there was a mistake in the communication driver, in which it was identified that the writing times were the ones that caused the trip in the plant."
7:05 "With this identification, there was a return for the business, for the investment we made in the solution, for a cybernetic monitoring, but we helped the business with an occurrence of abnormality of communication of some plant driver, avoiding all this chaos of moments of a trip on an offshore platform."

FAQ

What specific operational problem did Claroty help Petrobras solve beyond cybersecurity?

Claroty helped diagnose recurring false fire and gas alarms on an offshore platform that forced evacuations to muster points. By analyzing communication patterns, the team discovered a faulty driver that was writing data when it should only read, causing plant trips. This enabled them to create alerts and work with the manufacturer to fix the issue.

How did Petrobras measure return on investment for the Claroty deployment?

Beyond traditional cybersecurity metrics, Petrobras measured ROI through operational impact—specifically preventing production disruptions and eliminating costly platform evacuations caused by the communication driver malfunction. The solution paid for itself by solving a business-critical reliability issue.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • OT
  • IoT Security
  • Customer Story
  • Critical Infrastructure
  • Security Operations
  • Best Practices
  • OT network visibility
  • oil and gas cybersecurity
  • industrial control systems
  • asset vulnerability assessment
  • IT-OT convergence
  • operational technology monitoring
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Claroty: Petrobras Strengthens Critical Infrastructure Security

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    03

                    Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                    08/03/202611:00 AM ET
                    • Aug
                      06

                      Safeguarding Sensitive Data in the Era of AI Adoption

                      08/06/202604:00 AM ET
                      • Aug
                        06

                        Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                        08/06/202602:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/03/2026
                          11:00 AM
                          08/03/2026
                          Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Safeguarding Sensitive Data in the Era of AI Adoption
                          https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-ai-adoption/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version