The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Fortinet Cybersecurity Podcast
Fortinet Cybersecurity Podcast artwork

Brass Tacks S2E05 - Securing the Systems That Move Industry

Fortinet Cybersecurity Podcast · 2026-03-13 · 23 min

0:00--:--

Key moments - from our scoring

Substance score

48 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality8 / 20
Guest Caliber12 / 20
Specificity & Evidence7 / 20
Conversational Craft11 / 20

Hossein Al Shadoki, a partner at KPMG Middle East and global lead for OT and IoT, discusses the critical challenge of securing operational technology environments as they increasingly converge with IT systems. Historically, OT environments - which control industrial processes in utilities, oil and gas, manufacturing, and transportation - relied on physical security and operational isolation. Today's Industry 4.0 push demands data flow between IT and OT networks, creating cyber vulnerabilities in systems that were never designed with digital attacks in mind. Al Shadoki emphasizes that successful convergence requires more than technology: it demands cultural change, cross-functional team integration, and fundamental asset visibility. He walks through a real success story where his team extended IT security capabilities like advanced anomaly detection into OT environments, implemented asset discovery and vulnerability scanning tools, and redesigned governance across both domains. The core message is simple but foundational - organizations must first understand what assets they have, how they're connected, and what vulnerabilities exist before implementing automated GRC tools or complex security controls that might inadvertently disrupt critical production systems.

Key takeaways

  • →CISOs must build cross-functional relationships with OT teams and develop cultural understanding before attempting technical integration, including strategies like rotating team members between IT and OT roles.
  • →Asset discovery and visibility are prerequisite foundations - organizations cannot effectively secure or automate governance of OT environments they don't fully understand at a manual level.
  • →Security controls implemented without understanding OT architecture and operational requirements can degrade production performance and inadvertently harm the business.
  • →IT security capabilities like advanced anomaly detection can be tailored and extended to OT environments, but require careful study of existing IT and OT governance, people, processes, and resiliency requirements.
  • →Network segmentation, zonings, and proper architectural documentation using frameworks like the Purdue model must be established before attempting convergence between historically separated IT and OT domains.

In this episode

  1. 1Introduction to Operational Technology and Cybersecurity Challenges
  2. 2Key OT Terminology: ICS, SCADA, PLC, DCS, and Cyber-Physical Systems
  3. 3IT and OT Convergence: History, Drivers, and the Purdue Model
  4. 4Cultural and Organizational Barriers to IT-OT Security Integration
  5. 5Asset Discovery and Visibility as the Foundation for OT Security
  6. 6Success Story: Building Integrated IT-OT Security Operations
  7. 7Best Practices and Foundational Steps for Secure Convergence

Mentioned

FortinetKPMGJoe RobertsonHossein Al Shadoki

Guests

Hossein Al Shadoki

Topics in this episode

Industry 4.0SCADA systemsIT/OT convergenceOperational Technology (OT)Purdue modelProgrammable logic controllers (PLCs)Industrial Control Systems (ICS)Distributed Control Systems (DCS)Cyber-Physical Systems (CPS)Industrial Internet of Things (IIoT)

Questions this episode answers

What are the main differences between IT and OT security architectures?

IT uses relatively flat architectures where software pulls data from multiple sources via APIs, while OT uses hierarchical Purdue model architecture with different levels of controllers managing specific processes; merging these requires dynamic mesh architectures rather than simple network connections.

Why do CISOs from IT backgrounds struggle with OT security?

Most CISOs come from IT backgrounds with limited visibility into OT environments, lack understanding of how operational technology works, and may implement security controls that degrade production performance without realizing the impact on core business operations.

What is cyber-physical systems (CPS) convergence?

CPS convergence is the integration of computing, networking, and physical processes where technology manages mechanical systems that can have real physical impacts, increasingly relevant as Industry 4.0 demands data flow between IT and OT networks.

What's the first step organizations should take to secure OT environments?

Organizations must start by understanding their OT environment through manual asset discovery and visibility before implementing any automated tools, as implementing controls without knowing what exists can harm production systems.

How did the KPMG client successfully integrate IT and OT security?

The team studied both environments' people, processes, technologies, and governance; extended IT capabilities like anomaly detection to OT; implemented asset discovery and vulnerability scanning tools; and redesigned integration programs between departments with CISO oversight.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

The episode covers important OT/IT convergence concepts but relies heavily on restatement of a single core idea - understand your environment, build culture, then implement controls - repeated across multiple client anecdotes. While some useful framing exists (Purdue model, asset discovery basics), there's substantial filler around terminology definitions and general principles that B2B operators in security already know.

Start simple Joe. Start simple. Get to know your environment before you secure it.
Most of this it comes from a uh, people mindset and cultural change. Before I start thinking about architecture

Originality

8 / 20

The framing of IT/OT convergence and culture-first approaches is well-trodden in security consulting circles. The guest repackages standard CISO playbooks (people-process-technology, asset discovery, anomaly detection) without fresh angles or contrarian takes. The Purdue model reference is textbook, not novel thinking.

Capabilities that would have existed in the IT world that could be tailored to an OT world.
People are your first line of defense. They're not the weak point, they're the first line of defense.

Guest Caliber

12 / 20

Hossein Al Shadoki is a KPMG partner and global lead for OT/IoT, giving him relevant seniority and broad exposure. However, the transcript reveals mostly consulting rhetoric and anecdotal examples rather than deep operational expertise. He speaks as an outside advisor citing 'clients' rather than as a practitioner who built or operated OT systems at scale.

a partner at KPMG Middle east and global lead for OT and IoT
As a consultant you must have seen some real success stories too. Can you give us an example, maybe without naming names

Specificity & Evidence

7 / 20

The episode is sparse on concrete data, named companies, timelines, and metrics. References to client engagements are vague ('a couple of years ago,' 'one of my clients,' 'a large global client'). No specific attack vectors, incident data, or measurable outcomes are provided. Terminology definitions are specific but add little operational value.

Recently one of my clients came in and the ultimate goal
A uh, couple of years ago we were engaged with a client where they really want to take over the visibility

Conversational Craft

11 / 20

Host Joe Robertson asks reasonable setup questions and shows familiarity with the domain, but rarely challenges or pushes back on vague claims. Follow-ups are mostly affirming ('So what you're saying is...') rather than probing. The guest's lengthy, repetitive answers go largely unchecked, and no substantive disagreement or skeptical questioning surfaces.

So part of the solution is sociological, not just technological.
You mean you can put in place security tools that actually slow down production, which doesn't sound like really the objective I uh, would think.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A59%
  • Speaker B41%

Most-used words

environment23world15security14visibility11technology11cyber10technologies10processes10convergence10control9different9physical9start9systems8cybersecurity7point7

Episode notes

Factories, power plants, and transport networks now sit on connected systems. Hossain Alshedoki, Partner at KPMG Middle East, and Global Lead for OT and IoT, explains how cyber risk turns physical, why IT and OT teams struggle to align, and what leaders must fix first to protect systems that move, heat, and power industry. Watch or listen to the episode, and read the blog to learn how to secure operational technology.

Full transcript

23 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Nowadays is faced at any CISOs who comes ultimately from a background of it. They're taking care of the overall cyber across the organization, the resiliency of those technologies without so much visibility into what's happening in an OT environment. And that makes it a challenge.

Speaker B: Hello and welcome to Brass Tac's Talking Cybersecurity, the 40 net podcast that gets straight to the point on cyber risk. I'm your host, Joe Robertson. This season we're taking a broad look at cybersecurity not just as a business issue, but as a societal one. Although we are all familiar with being online in our personal and professional lives, there is an area where being online is pretty new and pretty well undefined. I'm talking about automation and control and operational technology, or ot. In contrast with it, information technology sectors like utilities, oil and gas, manufacturing, transportation and logistics, defense and many, many more rely heavily on control systems which, although managed by computers, are very different from the IT we're all used to. So to talk about how this huge sector of the global economy is more and more exposed to the risk of cyber attacks, I'm pleased to welcome Hossein Al Shadoki, a partner at KPMG Middle east and global lead for OT and IoT. Hossain, welcome to BRSS Tacks.

Speaker A: Thank you, Joe, for having me today.

Speaker B: Hey, it's uh, a, uh, real pleasure for me as well. Just like the IT world, you're an expert in the OT world and it's full of terminology. We can't get away from terminology. Let's define a few of the most important terms and concepts and acronyms. Uh, in this world, of course, we've already defined OT operational technology, but there's also stuff like ics, dcs, plc, scada, cps, uh, uh, there's a whole raft of different acronyms. Tell us about the important ones. What do they mean, all of them? Well, pick the most important.

Speaker A: All of them. I'm not going to say one over the other because at the end when I think of ot, I think of all of these subcomponents that would allow productions to. To be happening in any environment. So as ICS industrial control systems, it's really important to manage, uh M. The components of SCADA. There's components of TCS, the components of PLCs, which again, a lot of other terminologies, PLC is the programmable logic controllers where all logics and processes have been saved in that manner. Or right. When I think about dcs, right. This is the distributed control systems that is used to distribute the Control elements across, sorry, through a centralized system. When I think of cps, and this is another terminology, but you can think of the systems when they are integrated and integrating the computing, the integrating the network and the physical processes all in one space in a simple way.

Speaker B: So CPSN is cyber physical systems. Is that what it is?

Speaker A: Okay, exactly. And this is where the intersection point is happening between technology networking and cyber in a physical world. This is when technology is managing uh, mechanical systems that could have a physical impact towards the end.

Speaker B: Okay, so turning on valves or moving uh, machinery or moving uh, an arm or something like that.

Speaker A: Exactly.

Speaker B: Most of it much more sophisticated than what I just described. So you're saying that OT is the digital control of physical processes. Now this contrasts of course with it, which is the digital control of virtual processes. There's a lot of talk nowadays about the convergence of um, IT and OT, the growth of CPs that would include things like IIoT, the Industrial Internet of Things and also uh, a lot of ioxts where the X stands for something like the Internet of Medical things. Obviously sharing the infrastructure can lead to cost savings, but convergence, it's gotta be about more than just cost savings of physical wires and boxes.

Speaker A: True, you don't look at this from an economical point of view, but when I think of convergence, while it's a trending topic nowadays, didn't exist yesterday, it's been there for a long, long time. And the starting point when we started using simply Windows in an OT environment, Windows XP existed in an OT environment. That's convergence.

Speaker B: That's way back.

Speaker A: That's way back. Convergence didn't start today. Yes, we see a growth, we see a demand and we see a push because adoptions of these new advanced technologies are being requested for various reasons. In an OT environment where the two roles needs to, I'm not saying have a one network for both, but they need to start talking to each other. They need to streamline processes. They need to have people working together in order to achieve that efficiency of using and utilizing technologies and better help leadership for taking decisions when visibility exists. That's why we see so much push nowadays towards it OT convergence. For that reason, uh, I can talk more but I want to stop here and I want to hear your thoughts, Joe here.

Speaker B: Well yeah, I think the thing that comes to my mind right away is that we're trying to bring things together. But the architectures in IT are extremely different from the model that is used in operations. Uh, when you organize industrial processes and equipment, most of the that organization is done Using what's known as the Purdue model, which has different types of processes and controllers that are set up in hierarchical levels of what controls what and how many devices, et cetera. That is not at all like the relatively flat IT organization where software might be pulling information from right and left from M all over the place using APIs. It sounds like a really big job to merge this hierarchical environment with this flat IT environment. What's involved with getting these two worlds together?

Speaker A: I don't want to say it's simple, but I want to take you Back to yesterday versus today. In the past, CISOs or information security managers and leaders, their main responsibility was towards the corporate level, making sure computers, systems, ERP systems are secure and safe and they can be utilized in a corporate world where engineering departments and operational technology team members, their main responsibility was simply the productions and the business running on day to day. And the security elements have been covered by those team members which their main focus was completely operation and availability and performance.

Speaker B: And for a lot of those security really meant physical security, making sure that no one can enter the building or no one can get on the grounds and protecting the property like that. Not worried so much about connecting, uh, having attackers connect because they weren't connected to anything.

Speaker A: Correct, Correct. And that existed in the past for many years and nothing wrong with that. And both they did an amazing job. And the industrial, manufacturing and energy sectors and oil and gas were those two people I, uh, would call or different team members taking care of their main responsibility. For the main challenge that is nowadays is faced that any CISOs who comes ultimately from a background of it, they're taking care of the overall cyber across the organization, the resiliency of those technologies without so much visibility into what's happening in an OT environment. And that makes it a challenge. Most of this it comes from a uh, people mindset and cultural change. Before I start thinking about architecture, I'll come back to your question on architecture. I'm not disputing that and that's in the past. So different architectures has been set statically for different two environments. Now we've got convergence and we've got a push in the world that we're living in the industry 4.0 and to start having data moving from one area to another. And guess what, this is what's going to lead us in the future to move towards Industry 5.0 and that's going to be the new oil. But in order to do that architectures needs to be looked at. I'm not saying completely change it but we need to have every single organization, and this is what we're advising our clients today, to look at the existence of their security architecture and to design a mesh dynamic architectures that could be agile, to adopt and absorb those advanced technologies in both worlds and to start not connecting the two network, but to streamline the processes from one area to another in a secure manner. That's why architectures are very important in the past. Still today Purdue model will exist and you'll continue using it, but having the visibility on what you've got is very key.

Speaker B: So bringing together these two worlds in some way, uh, bringing the data together at least, is a question of understanding what you've got and how you're going to connect them. But one of the things that we know in the cybersecurity world is being able to connect things means also creating weak points as far as entry points for an attacker. In the IT world, uh, we all know about cyber attacks that can block up computers, freeze, uh, your applications, um, have a huge impact on the business, obviously. But operational technology, it is physical, okay? It's about stuff that's actually dangerous. We're talking about the production of harmful chemicals, uh, production of high, uh, voltage, electricity or high, uh, temperature steel or whatever, heavy machinery, all of these things. If a bad actor somehow takes control of some of those things, it creates a physical danger for people and for property. So my thinking on this is this has been in process for the last 60 years, 70 years, we've been automating these processes in some cases even more, um, but haven't worried about cyber security. Whereas in the IT world for the last 40 years, we've been attacked and attacked and attacked, and we've been coming up with more ways of protecting ourselves. The cyber world has moved very quickly, and in ot, suddenly they're being attacked, not just as we were saying, physically, uh, who do you let into the building, but by bad, uh, actors, uh, coming in through IT and the Internet in general. So all of that is to bring up a question. It, uh, knows how to deal with cybersecurity. Although it's always a challenge. OT is just learning. So what do we have to do to protect our operational technology environments?

Speaker A: Thanks, Joe. Uh, you mentioned who are we letting to our buildings and sometimes who are we letting to our country or cities? Because we've same bad actors who took over operational and grids of electricity and they've just shut them down in different countries. And what we really need, and this is our advice as, uh, consultants to CISOs and to our clients start understanding your environment more and more get connected, whether you're OT engineers, get to know them at a personal level. Start with that point. Right. Bring the two roles together. Ah, this uh, is one of the advices that I've given to one of my clients. Send some of your team members to become uh, workers of OT for a year and take some of the ot, uh, people and engineers to have them as part of your IT team in order to learn and in order to integrate the two cultures together.

Speaker B: So part of the solution is sociological, not just technological.

Speaker A: Correct. And right after that you need to understand and have the visibility into what assets you've got within your environment. And I'll tell you one nice example. Recently one of my clients came in and the ultimate goal, it's either been his thought or been pushed on top that he wanted to have an automated IT OT GRC tool that can give him a visibility and what risks, what controls that he's uh, in compliance with and whatnot. And guess what? He's missing the fundamental. He doesn't know his OT environment visibility to him, zero at a manual level. And not even tools that existed within his OT environment that would help him out to do the scanning of assets. No existence of tools to do vulnerability scannings. So what exactly are you managing or automating and pushing? Uh, uh, as your governance and risk and compliance within that function you would have a tool that wouldn't give you valuable data.

Speaker B: Simply I've had similar customers where we put a probe on their network, their operational technology network and they were astonished at what was connected. They had no idea that all those things were connected. And what you're saying is that if you don't know what you've got, uh, uh, an automation tool of saying what your risks are isn't going to do you any good.

Speaker A: Exactly. Start simple Joe. Start simple. Get to know your environment before you secure it. Also this is very crucial because if you don't and you put security controls that would impact the performance of your technologies, which is your core, core business, you might just attacked your environment without even knowing.

Speaker B: You mean you can put in place security tools that actually slow down production, which doesn't sound like really the objective I uh, would think.

Speaker A: Exactly.

Speaker B: Okay, well as a consultant you must have seen some real success stories too. Can you give us an example, maybe without naming names, but good examples of how this kind of convergence has been done with in a secure and protected manner?

Speaker A: One of the good success, and I'm m proud of, uh, that I was part of that team. A uh, couple of years ago we were engaged with a client where they really want to take over the visibility and the security operations of their OT environment. And the same approach that I was just mentioning, when we thought about that, we started thinking about what capabilities of security they've got existing within IT environment. What if those IT security capabilities that could be extended to an OT environment, either it's people or process or technologies. I'll give you an example. Advanced anomaly detection, 15, 20 years. It exists as an IT world and our world as an OT. Uh, engineers. We're very happy nowadays because there are technologies that exist that would identify or detect anomalies. That's new to us. Right. And this is what I mean. Capabilities that would have existed in the IT world that could be tailored to an OT world. And this was our journey. Basically we've studied their IT and OT environments, we've analyzed the culture, we've analyzed the capabilities of people in both worlds. We've designed the second programs between the two departments to make sure that they are integrated. The CISO started taking over with clear visibility. Technologies have been implemented to discover what assets are there. Vulnerability tools have been implemented to discover vulnerabilities. Now CISO is have. The CISO is having the visibility and the enablements, the empowerment to enable his leadership and organizations and their digital transformation journey. I don't want to talk about AI and the adoptions of AI because this is going to come next. Right? And when you introduce AI or I would say machine learning in an OT environment and you want to control this at an ecosystem level, again they would need a visibility. And that was our journey. Simply. We studied people, we studied process, we studied technology, we studied governance, how things are governed across the organizations. We studied the resiliency and the business continuity for both roles. We streamlined processes and standards where, where applicable. Not everything is similar. And then we got on the journey. It's been a beautiful successful journey. Uh, it's not done overnight, it's still ongoing, but the success and the results is observed as we go.

Speaker B: Okay, so in the few minutes that we've got left, maybe you can provide us with some concluding thoughts on what we should be thinking about as we plan. Plan this convergence of OT and it. Uh, what are the basics, the foundational levels and then what is above that?

Speaker A: Be open minded to change. Agility is key. Flexibility and exchanging thoughts. Understanding the two environment requires a lot of agilities. Uh, uh, I go back and I stress on culture, culture, culture because it's the umbrella that covers the entire transactions and transition of this convergence. You want to have an environment that is not only controlled and secured, you want to have an environment that is resilient, but at the same time agile. Because the advancements of technologies every day is moving fast. And as, uh, security leaders and security controllers, at the end you want to go with that dynamic and to be agile and to help out, adopting and absorbing, uh, these things. That would be my one advice to everybody I know.

Speaker B: I've always, uh, said that when it comes to cybersecurity, your, your people are your first line of defense. They're not the weak point, they're the first line of defense. Then there's technology that comes to back them up, but you've got to have the people on board and having a good working relationship between those two environments, uh, which are very different, the IT and the OT environment. The more you understand and know each other, the more you respect each other and the qualifications that uh, each of you has and what you bring to the party.

Speaker A: Exactly, exactly. I'll end up, and I'll close up with one simple example. A couple of years ago I was engaged with a large global client, uh, which did have a lot of plans around the world. Some of these plans has been existing, as you mentioned earlier, 60, 70 years. And when we got in, yes, the two worlds have been segregated, IT versus OT. But when we got in to study the OT environment, it was a flat network. It was a bit chaos. There was no system that gathers, uh, what assets they've got. All of this knowledge has been a tacit knowledge on people or operators, no architecture diagrams. Guess what? CISO doesn't know what he's dealing with. You want to merge or integrate or converge the two roles. You want to allow data to be moving from one place to another without even having the simplicity of segmenting your networks, the right zonings and conduits, where things should be located at, uh, what security controls that should be implemented. Let's go back to basics. Define those basics to move forward.

Speaker B: Basic is knowing what you've got and where it is and how it connects to everything else. Uh, before you even think about putting in place firewalls and things like that. Know what you got is what you're saying.

Speaker A: Simply know what you got so you can deal with it. And I'm not making that simple, Joe as well, don't get me wrong, it's not a simple job to do.

Speaker B: No, I can't imagine that it would be. Well, that actually is a good place for us to finish this conversation. I'd really like to thank you for your time, Hussein.

Speaker A: Thank you, Joe, for having me here today.

Speaker B: That's it for today's episode of Brass Tacks Talking Cybersecurity, the 40 net podcast that gets straight to the point on Cyber Risk. My guest has been Hossein Ashdoki, a partner at KPMG Middle east and global lead for OT and IoT there. I hope you found this discussion interesting. I know I did. I hope you also found it insightful and useful. You can watch more Brass tacks conversations on YouTube and FortinetTV, or listen on your favorite podcast platform under the Fortinet Cybersecurity Podcast show channel.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Ep. 025: The Innovation Gap in American Manufacturing | w/ Special Guest Arturo PinoOpen Source CXO: The Tech Leader's Podcast · on Industry 4.088 / 100
  • Managing Risk with Digital Twins - What Do We Do Next? [the industrial security podcast]The Industrial Security Podcast · on Purdue model85 / 100
  • How to Design AI for Scale From Day One with Tom Greenlees, Intelligent Core [090]The Business of AI · on SCADA systems80 / 100
  • Beyond Dashboards: Building a Connected WorkforceAuto Supply Chain Champions · on SCADA systems80 / 100
  • The Real Threat to Tribal Knowledge Isn't Just Retirement w/ Jamie MarzilliThe Manufacturing Executive · on Industry 4.079 / 100
  • Dr. Yvonne Lutsch Investmet Director Lam Capital E34ImpacTV · on Industry 4.078 / 100

More from Fortinet Cybersecurity Podcast

All episodes →
  • Brass Tacks S2E06 - Fighting Cybercrime at Global Scale64 / 100
  • Brass Tacks S2E04 - Why Cybersecurity Is a Societal Issue
  • Brass Tacks S2E03 - From Compliance Fear to Cyber Trust
  • Brass Tacks S2E02 - EU Cyber Regulations & Digital Sovereignty
  • Brass Tacks S2E01 - Cyber Conflict and the Risk to Critical Infrastructure
Explore the best B2B Engineering & DevTools podcasts →
All Fortinet Cybersecurity Podcast episodes →