Why OT security is becoming a key priority for Positive Technologies

Why OT security is becoming a key priority for Positive Technologies

In this Q&A, Ilya Leonov, Regional Director for Positive Technologies in the MENA region, discussed the surge in OT-targeted attacks and the increasing weaponisation of AI, warning that outdated defences leave a growing surface open to highly strategic adversaries.

Ilya Leonov, Regional Director for MENA, Positive Technologies

At GISEC Global 2025, one thing was clear—traditional defences no longer protect systems against growing attacks on operational technology (OT) and application environments.

There needs to be a growing focus on embedding security earlier in the software development lifecycle.

It is crucial to adopt DevSecOps practices to mitigate long-term risks and address a growing skills gap that even the most advanced tools cannot compensate for.

This message is particularly resonant in the Middle East. According to a recent Gartner report, nearly 14% of organisations in the UAE—particularly in the energy, government, finance, and infrastructure sectors—are ramping up investment in proactive cyber defence strategies.

UAE cybersecurity spending is set to rise by 14% in 2025—what’s driving this growth?

The primary driver is the rapid digital transformation taking place not only in the UAE but across the Middle East. We’re witnessing an unprecedented integration of IT into virtually every aspect of daily life—whether cloud-based services, IoT applications, remote access platforms, or smart infrastructure.

The threat landscape increases with every new technology layer—new vulnerabilities, attack surfaces, and intrusion methods. While not unique to the region, the GCC has seen a sharp rise in adopting digital platforms, creating a need for stronger cybersecurity protocols.

In response, governments in the region—especially the UAE—are stepping in with progressive regulations and national cybersecurity frameworks. These are compliance checkboxes and well-structured, future-focused strategies to ensure resilience in an increasingly complex threat environment.

It is reactive and proactive—addressing today’s vulnerabilities while building long-term national cyber defences.

With OT attacks on the rise, what’s needed to secure critical infrastructure better?

For years, Cybersecurity has focused almost exclusively on IT—corporate networks, endpoints, and software systems. OT, by comparison, was often treated as a black box: sensitive, legacy-bound, and not to be tampered with.

However, the nature of threat actors has evolved. We now see that OT environments—those responsible for energy grids, water utilities, manufacturing plants, and transportation systems—have become primary targets. These systems control real-world processes and affect real lives. Any compromise can have catastrophic consequences—not just business disruption but national or international fallout.

Also, OT environments are notoriously difficult to update. Many are still running on decades-old systems, like Windows XP because downtime could halt production. Yet, these legacy systems were never designed with cybersecurity in mind. They are vulnerable by default.

There also is a shortage of knowledge and capability regarding securing OT. It’s a completely different discipline from IT security. You need tools designed for industrial protocols and people who understand engineering and cyber. That’s a rare combination.

This is why Positive Technologies has been working in the OT space for over ten years now. Especially with increasing geopolitical tensions, we’ve seen that threat actors—particularly advanced persistent threat (APT) groups—aren’t always financially motivated.

Their aim is disruption on a national level. Unfortunately, OT is a prime target for that kind of attack. Thus, the focus on OT security isn’t just important—it’s now essential.

However, the tide is turning. We’re seeing more organisations invest in dedicated OT SOCs (Security Operations Centres), more awareness campaigns, and more vendors—like us—offering integrated solutions tailored to this space.

How can organisations stay ahead of AI-powered threats?

AI and machine learning have become indispensable in modern cybersecurity—not because they’re buzzwords, but because they solve a real problem: data overload. The volume of logs, alerts, threat intelligence feeds, and anomaly signals that security teams must analyse is staggering. No team of analysts, no matter how skilled, can manually process everything in real-time.

We are using AI to support our experts—not replace them. Our AI capabilities help sift through the noise, identify genuine threats, prioritise responses, and offer recommended actions. It’s about accelerating the response loop and giving security professionals time to focus on what matters.

That said, we must be cautious about overpromising what AI can do. It’s a powerful tool, but it must be embedded wisely. It won’t stop an attack on its own, but it can ensure that the right people see the right warning signs at the right time—and that can make all the difference.

How should businesses secure applications against fast-evolving, intelligent attacks?

Application security is a perfect example of where a proactive mindset is needed. Many businesses still treat security as a final checklist item—something you do just before an app is released. This is too late.

We advocate a DevSecOps approach—security built into every development lifecycle stage. That means scanning for vulnerabilities as the code is written, training developers on secure coding practices, and automating testing throughout the pipeline.

Fixing vulnerabilities in the early stages is more secure and vastly more cost-effective. If a security flaw is caught just before launch—or worse, post-launch—it becomes a major headache. But if the developer sees it in real-time and addresses it immediately, it never becomes a problem.

Our message to businesses is clear: treat security as part of the development process, not an afterthought.

Can you share a real-world example where PT Network Attack Discovery helped stop a cyber threat?

One common scenario concerns hidden threat actors—individuals or groups that breach a network and lie dormant for extended periods. There’s a misconception that hackers are always fast and aggressive. In reality, many prefer to stay undetected for months or even years.

In one case, a client noticed a massive spike in their cloud bill. Upon investigation, we discovered that their infrastructure had been compromised. Attackers had spun up a separate, cloned environment to mine cryptocurrency. The client wasn’t even aware because operations weren’t disrupted—until the bill arrived.

This is where our Network Attack Discovery Tool helps. It’s designed to detect these stealthy intrusions—behavioural anomalies, unusual east-west traffic, privilege escalations—before damage is done. We’ve seen it detect threat actors who have been present in systems for over five years, silently harvesting data or selling access on the dark web.

We’ve also found that, on average, attackers take just five days to gain full administrative access once inside. The response window is small. Early detection is everything.

How is threat hunting evolving in the Middle East, and what challenges hinder early threat detection?

The biggest hurdle is human capital. You can invest in the most advanced tools and platforms, but they’re ineffective without skilled analysts to interpret the data and make the right decisions.

There’s a global skills gap in cybersecurity, and the Middle East is no exception. We need more trained professionals who understand how to use tools and think like attackers, correlate complex threat patterns, and respond under pressure.

What’s encouraging is that many organisations here are starting to understand this and are investing in training and capacity-building. We need partnerships with universities, continuous upskilling programmes, and mentoring the next generation of cybersecurity experts.

How does MENA’s cybersecurity maturity compare globally, and where can it improve?

The region is on a very promising trajectory. The UAE, in particular, has shown remarkable foresight in implementing national cybersecurity strategies, setting up regulatory bodies, and promoting best practices.

There’s room for growth in operational execution—things like incident response readiness, red teaming capabilities, and cross-sector collaboration—but the fundamentals are being implemented.

We also see an opportunity to enhance regional collaboration—sharing threat intelligence across borders, harmonising standards, and learning from one another’s experiences.

What were main goals and expectations for GISEC 2025?

At GISEC this year, we showcased some advanced live demos—one of which demonstrates how a laptop can be accessed without knowing the password using a fault injection technique. We’re also running hands-on workshops on DMA attacks and other cutting-edge threats.

We see GISEC as a place where professionals can speak to professionals. It’s not just about products—it’s about building the community, sharing what works, and collectively raising the bar for cybersecurity across the region.

Browse our latest issue

Intelligent CIO Middle East

View Magazine Archive