{"id":118435,"date":"2025-05-14T08:45:34","date_gmt":"2025-05-14T07:45:34","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=118435"},"modified":"2025-06-03T10:22:42","modified_gmt":"2025-06-03T09:22:42","slug":"why-ot-security-is-becoming-a-key-priority-for-positive-technologies","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2025\/05\/14\/why-ot-security-is-becoming-a-key-priority-for-positive-technologies\/","title":{"rendered":"Why OT security is becoming a key priority for Positive Technologies"},"content":{"rendered":"\n<p><em>In this Q&amp;A, Ilya Leonov, Regional Director for Positive Technologies in the MENA region, discussed the surge in OT-targeted attacks and the increasing weaponisation of AI, warning that outdated defences leave a growing surface open to highly strategic adversaries.<\/em><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2025\/06\/Ilya-Leonov-Regional-Director-for-MENA-Positive-Technologies-New-683x1024.jpg\" alt=\"\" class=\"wp-image-119093\" style=\"width:277px;height:auto\" \/><figcaption class=\"wp-element-caption\"><em>Ilya Leonov, Regional Director for MENA, Positive Technologies<\/em><\/figcaption><\/figure><\/div>\n\n\n<p>At GISEC Global 2025, one thing was clear\u2014traditional defences no longer protect systems against growing attacks on operational technology (OT) and application environments.<\/p>\n\n\n\n<p>There needs to be a growing focus on embedding security earlier in the software development lifecycle.<\/p>\n\n\n\n<p>It is crucial to adopt DevSecOps practices to mitigate long-term risks and address a growing skills gap that even the most advanced tools cannot compensate for.<\/p>\n\n\n\n<p>This message is particularly resonant in the Middle East. According to a recent<strong><em> Gartner report<\/em><\/strong>, nearly 14% of organisations in the UAE\u2014particularly in the energy, government, finance, and infrastructure sectors\u2014are ramping up investment in proactive cyber defence strategies.<\/p>\n\n\n\n<p><strong>UAE cybersecurity spending is set to rise by 14% in 2025\u2014what\u2019s driving this growth?<\/strong><\/p>\n\n\n\n<p>The primary driver is the rapid digital transformation taking place not only in the UAE but across the Middle East. We\u2019re witnessing an unprecedented integration of IT into virtually every aspect of daily life\u2014whether cloud-based services, IoT applications, remote access platforms, or smart infrastructure.<\/p>\n\n\n\n<p><strong>The threat landscape increases with every new technology layer\u2014new vulnerabilities, attack surfaces, and intrusion methods. <\/strong>While not unique to the region, the GCC has seen a sharp rise in adopting digital platforms, creating a need for stronger cybersecurity protocols.<\/p>\n\n\n\n<p>In response, governments in the region\u2014especially the UAE\u2014are stepping in with progressive regulations and national cybersecurity frameworks. These are compliance checkboxes and well-structured, future-focused strategies to ensure resilience in an increasingly complex threat environment.<\/p>\n\n\n\n<p>It is reactive and proactive\u2014addressing today\u2019s vulnerabilities while building long-term national cyber defences.<\/p>\n\n\n\n<p><strong>With OT attacks on the rise, what\u2019s needed to secure critical infrastructure better?<\/strong><\/p>\n\n\n\n<p>For years, Cybersecurity has focused almost exclusively on IT\u2014corporate networks, endpoints, and software systems. OT, by comparison, was often treated as a black box: sensitive, legacy-bound, and not to be tampered with.<\/p>\n\n\n\n<p>However, the nature of threat actors has evolved. We now see that OT environments\u2014those responsible for energy grids, water utilities, manufacturing plants, and transportation systems\u2014have become primary targets. These systems control real-world processes and affect real lives. Any compromise can have catastrophic consequences\u2014not just business disruption but national or international fallout.<\/p>\n\n\n\n<p>Also, OT environments are notoriously difficult to update. Many are still running on decades-old systems, like Windows XP because downtime could halt production. Yet, these legacy systems were never designed with cybersecurity in mind. They are vulnerable by default.<\/p>\n\n\n\n<p>There also is a shortage of knowledge and capability regarding securing OT. It\u2019s a completely different discipline from IT security. You need tools designed for industrial protocols and people who understand engineering and cyber. That\u2019s a rare combination.<\/p>\n\n\n\n<p>This is why Positive Technologies has been working in the OT space for over ten years now. Especially with increasing geopolitical tensions, we&#8217;ve seen that threat actors\u2014particularly advanced persistent threat (APT) groups\u2014aren\u2019t always financially motivated.<\/p>\n\n\n\n<p>Their aim is disruption on a national level. Unfortunately, OT is a prime target for that kind of attack. Thus, the focus on OT security isn\u2019t just important\u2014it\u2019s now essential.<\/p>\n\n\n\n<p>However, the tide is turning. We\u2019re seeing more organisations invest in dedicated OT SOCs (Security Operations Centres), more awareness campaigns, and more vendors\u2014like us\u2014offering integrated solutions tailored to this space.<\/p>\n\n\n\n<p><strong>How can organisations stay ahead of AI-powered threats?<\/strong><\/p>\n\n\n\n<p>AI and machine learning have become indispensable in modern cybersecurity\u2014not because they\u2019re buzzwords, but because they solve a real problem: data overload. The volume of logs, alerts, threat intelligence feeds, and anomaly signals that security teams must analyse is staggering. No team of analysts, no matter how skilled, can manually process everything in real-time.<\/p>\n\n\n\n<p>We are using AI to support our experts\u2014not replace them. Our AI capabilities help sift through the noise, identify genuine threats, prioritise responses, and offer recommended actions. It\u2019s about accelerating the response loop and giving security professionals time to focus on what matters.<\/p>\n\n\n\n<p>That said, we must be cautious about overpromising what AI can do. It\u2019s a powerful tool, but it must be embedded wisely. It won\u2019t stop an attack on its own, but it can ensure that the right people see the right warning signs at the right time\u2014and that can make all the difference.<\/p>\n\n\n\n<p><strong>How should businesses secure applications against fast-evolving, intelligent attacks?<\/strong><\/p>\n\n\n\n<p>Application security is a perfect example of where a proactive mindset is needed. Many businesses still treat security as a final checklist item\u2014something you do just before an app is released. This is too late.<\/p>\n\n\n\n<p>We advocate a DevSecOps approach\u2014security built into every development lifecycle stage. That means scanning for vulnerabilities as the code is written, training developers on secure coding practices, and automating testing throughout the pipeline.<\/p>\n\n\n\n<p><strong>Fixing vulnerabilities in the early stages is more secure and vastly more cost-effective. <\/strong>If a security flaw is caught just before launch\u2014or worse, post-launch\u2014it becomes a major headache. But if the developer sees it in real-time and addresses it immediately, it never becomes a problem.<\/p>\n\n\n\n<p>Our message to businesses is clear: treat security as part of the development process, not an afterthought.<\/p>\n\n\n\n<p><strong>Can you share a real-world example where PT Network Attack Discovery helped stop a cyber threat?<\/strong><\/p>\n\n\n\n<p>One common scenario concerns hidden threat actors\u2014individuals or groups that breach a network and lie dormant for extended periods. There\u2019s a misconception that hackers are always fast and aggressive. In reality, many prefer to stay undetected for months or even years.<\/p>\n\n\n\n<p>In one case, a client noticed a massive spike in their cloud bill. Upon investigation, we discovered that their infrastructure had been compromised. Attackers had spun up a separate, cloned environment to mine cryptocurrency. The client wasn\u2019t even aware because operations weren\u2019t disrupted\u2014until the bill arrived.<\/p>\n\n\n\n<p>This is where our Network Attack Discovery Tool helps. It\u2019s designed to detect these stealthy intrusions\u2014behavioural anomalies, unusual east-west traffic, privilege escalations\u2014before damage is done. We\u2019ve seen it detect threat actors who have been present in systems for over five years, silently harvesting data or selling access on the dark web.<\/p>\n\n\n\n<p>We\u2019ve also found that, on average, attackers take just five days to gain full administrative access once inside. The response window is small. Early detection is everything.<\/p>\n\n\n\n<p><strong>How is threat hunting evolving in the Middle East, and what challenges hinder early threat detection?<\/strong><\/p>\n\n\n\n<p>The biggest hurdle is human capital. You can invest in the most advanced tools and platforms, but they&#8217;re ineffective without skilled analysts to interpret the data and make the right decisions.<\/p>\n\n\n\n<p>There\u2019s a global skills gap in cybersecurity, and the Middle East is no exception. We need more trained professionals who understand how to use tools and think like attackers, correlate complex threat patterns, and respond under pressure.<\/p>\n\n\n\n<p>What\u2019s encouraging is that many organisations here are starting to understand this and are investing in training and capacity-building. We need partnerships with universities, continuous upskilling programmes, and mentoring the next generation of cybersecurity experts.<\/p>\n\n\n\n<p><strong>How does MENA\u2019s cybersecurity maturity compare globally, and where can it improve?<\/strong><\/p>\n\n\n\n<p>The region is on a very promising trajectory. The UAE, in particular, has shown remarkable foresight in implementing national cybersecurity strategies, setting up regulatory bodies, and promoting best practices.<\/p>\n\n\n\n<p>There\u2019s room for growth in operational execution\u2014things like incident response readiness, red teaming capabilities, and cross-sector collaboration\u2014but the fundamentals are being implemented.<\/p>\n\n\n\n<p>We also see an opportunity to enhance regional collaboration\u2014sharing threat intelligence across borders, harmonising standards, and learning from one another\u2019s experiences.<\/p>\n\n\n\n<p><strong>What were main goals and expectations for GISEC 2025?<\/strong><\/p>\n\n\n\n<p>At GISEC this year, we showcased some advanced live demos\u2014one of which demonstrates how a laptop can be accessed without knowing the password using a fault injection technique. We\u2019re also running hands-on workshops on DMA attacks and other cutting-edge threats.<\/p>\n\n\n\n<p>We see GISEC as a place where professionals can speak to professionals. It\u2019s not just about products\u2014it\u2019s about building the community, sharing what works, and collectively raising the bar for cybersecurity across the region.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this Q&amp;A, Ilya Leonov, Regional Director for Positive Technologies in the MENA region, discussed the surge in OT-targeted attacks and the increasing weaponisation of AI, warning that outdated defences leave a growing surface open to highly strategic adversaries. At GISEC Global 2025, one thing was clear\u2014traditional defences no longer protect systems against growing attacks [&hellip;]<\/p>\n","protected":false},"author":4338,"featured_media":119094,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14804,16005,809],"tags":[1530,19540,19592,16412],"class_list":["post-118435","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-deep-dive-newsletter","category-more-news","tag-cybersecurity","tag-gisec-2025","tag-ot-targetted-attacks","tag-positive-technologies"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/118435","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/4338"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=118435"}],"version-history":[{"count":28,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/118435\/revisions"}],"predecessor-version":[{"id":119095,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/118435\/revisions\/119095"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/119094"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=118435"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=118435"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=118435"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}