AI Raises OT Data Demands and Threats Faster Than Factory Networks Can Keep Up: Felipe Sabino Costa of Moxa on Security
Manufacturing Happy HourIn this episode of Manufacturing Happy Hour, host Chris talks with Felipe Sabino Costa of Moxa about how artificial intelligence is changing operational technology (OT), the networks and systems that run factories, highways and other industrial processes. Costa's argument has two sides. AI pushes manufacturers to move far more data, far faster, over infrastructure that was never built for it. The same technology also gives attackers better tools. His position is that the traditional industrial approach of isolated networks and perimeter defenses is no longer enough. He believes manufacturers need layered security down to the edge of the process, recognized standards such as IEC 62443 and NIST, and partners who understand both networking and security.
Why OT Data Matters Now
Chris opened with a basic question: why should manufacturers care about OT data at all? Costa said the industry is in the middle of a large change in how it works. OT data used to be mainly about logging and historical analysis. Today, in his words, it is "more like about predictive power, instant control, precision." He sees demands for greater precision and energy efficiency pushing plants away from reactive operation and toward predictive operation.
The shift he emphasized most is the timing of decisions. Historically, feedback came at the end of a process. A run would finish, information would flow back, and people would decide what to change. Now, Costa said, the system should recognize what is happening while the process is running and change decisions midway. He called this "way different" from how things were done in the past.
Old Infrastructure Meets AI-Driven Data Needs
Chris pointed out that the last time the show covered OT, AI was not really part of the discussion. Costa agreed that AI drives much of the new demand for faster, mid-process decisions. Whatever AI means in a given case, he said, the core idea is using data to do things that weren't done or couldn't be done before.
He named two main challenges in moving that data. The first is age and bandwidth. Many OT systems are 15 to 20 years old and were designed with very limited bandwidth. By his estimate, AI has been part of OT for only about five or six years, so these systems were not designed with it in mind. That leaves the question of how to make data usable for AI on very old infrastructure.
The second challenge is architecture. OT networks used to be standalone. Each factory did its own job and had no need to share information. Now plants need to send data to a cloud or a corporate data center so that more global, efficiency-oriented decisions can be made. That requires new kinds of connections. As a result, old systems are sending more data across more complex networks, which Costa said creates "a huge headache" for the people who have to make it work, himself included. He noted that the industry's term for the old isolated model is "air-gapped" networks, meaning systems that operate entirely on their own.
Bandwidth: Streaming 4K Over a Copper Line
To explain why bandwidth has become such a problem, Costa offered an analogy: it is like trying to stream 4K high-definition video over an old copper telephone line. The infrastructure is very old, and people are now trying to push high-definition images and video through it.
His first real-world example came from intelligent transportation systems (ITS), the cameras and related systems on highways that make travel safer and help the people using the data decide things like when to dispatch support. Costa said these systems have been adding more cameras, and higher-resolution ones, to photograph vehicles or stream live video. That greatly increases the amount of data each line has to carry. He described this as a current situation that Moxa has been working on with several customers.
His second example tied more directly to AI: processor manufacturing. He described it as a very precise process that has to be fast, secure and exact. Manufacturers are putting high-definition cameras at the very end of the process for image recognition and to improve parts of the system, for example better color control or higher precision. This used to be done differently. Costa's point was that there was previously no need for this level of image definition, but as AI adoption grows, he is seeing "data-hungry" applications that demand much more data.
Chris summarized the two cases. In transportation, the goal is safety, the method is more cameras, and the result is more data. In processor manufacturing, the goal is more visibility into a high-precision process, and that also creates more data. In both cases, bandwidth becomes the constraint.
Hardware Still Has to Survive the Environment
Costa added that bandwidth is only the technical side. Industrial applications also have specific requirements, and reliability is the main one. He gave the example of Nevada, where it is extremely hot outside, and of other states where it can be very cold. The devices supporting safety systems like the ones he described must keep running in those harsh conditions. That calls for ruggedized designs and wide operating temperature ranges. For AI adoption to help the industry move from the old model to the new one, he said, these specific demands have to be met, and that requires dedicated technology and hardware.
The Threat Landscape: Companies That Think They're Air-Gapped but Aren't
Moving to security, Chris asked about the current threat landscape for OT networks. Costa called it a "one million type of question" and focused on two major issues.
The first connects back to the air gap. Many companies still believe their plants are isolated, but Costa said they are not anymore. To be truly air-gapped, a system must have no way at all to send data out. If there is even one connection sending data to a cloud or to another factory, it is no longer air-gapped. Whether a plant has one such connection or thousands, a path exists.
That leads to the second issue: a need for what Costa called a second layer of defense close to the edge, meaning protection for the industrial devices themselves. He contrasted IT and OT. In his view, IT "was born with security," and its solutions were designed with it in mind. In industry 15 to 20 years ago, safety mattered but data security "was not really a thing." Now, for all the reasons discussed in the episode, security is extremely important too.
He then gave a figure: roughly 80% of global industry, "including us" (it was unclear whether he meant the U.S.), does not have these specific defense layers at the very edge. In his description, these organizations do have some defenses at the IT layer and some segmentation between automation networks and corporate networks, but "nearly zero protections close to the process itself." That, he said, is where work is needed.
Chris restated the number as about 80 to 85% of the industry and urged listeners to ask whether they are in the minority taking action or in the majority that is not doing enough. On the air gap, he added that some connection to the cloud has become nearly universal over the past decade. It is not true for every company, but it is likely true somewhere in most processes.
How AI Changes Attacks
Asked how AI has created new threats, Costa said attackers are using AI in many areas, just as everyone else is. Broadly, they use it to make attacks more sophisticated and more precise. In the same way that legitimate users rely on ChatGPT and similar tools to process large amounts of information and get insights, attackers combine information about vulnerabilities and industries. According to Costa, this lets them craft sophisticated attacks against OT systems with little or no real knowledge of those systems.
He described phishing as one of the most common attack types: a fake email that leads someone to click a link and compromise a device. Attackers are not necessarily doing new things, he said, but they are doing the old ones "faster and better."
Chris offered a parallel. When he uses ChatGPT and it learns more about him and his podcast, its responses become more tailored. A phishing attack aimed at getting a specific person to open a specific file can be refined the same way, so it looks more convincing than before. Costa agreed and called it one of several ways attackers are using AI. In the past, he said, you could scan an email and find typos or inconsistencies. That is now much harder, so organizations need additional layers of defense, "or even another AI," to check and verify messages.
Malware That Adapts Mid-Attack
When Chris asked for a more detailed example of increasingly sophisticated attacks, Costa connected it to the theme from earlier in the episode. Legitimate AI moves decision-making earlier, into the middle of a process, and attackers are following the same logic.
His example was port scanning. In the past, an attacker's scan looking for particular open ports was essentially binary. If a port wasn't open, the attacker moved on to something else or to another target. With AI, Costa said, the code can adapt "during the flight." As it scans and receives information, it can change its behavior in the middle of the attack. That makes attacks more efficient and, as he put it, "more dangerous if you will."
From Prevention Alone to Defense, Detection and Response
Costa's conclusion was that the old defensive approach is no longer sufficient on its own. He said he has been discussing this with customers. Prevention, meaning perimeter controls and defense-in-depth layers, remains important and should still be done, especially since most of the industry is not doing even that. But for more mature organizations, prevention alone is "not enough anymore," and "there is no silver bullet."
What he recommends instead is a combination: defense in depth plus detection and response, tailored to each organization's size and goals. That is why he talks with each customer to understand who they are and what they are trying to do before recommending a solution. Two frameworks, IEC 62443 and NIST, help tie all of this together.
For a product manufacturer like Moxa, Costa said, security is not only about how a product is built and what goes into it, although that is part of what IEC 62443 defines. It is also about what happens afterward. Does the manufacturer have people who can help a customer facing an incident? Is there a proper place to report vulnerabilities, which he described as flaws? He referred to a specialized response team that receives vulnerability reports and handles them on defined timelines. He summed this up as a shift toward a more "strategic" and combined approach to industrial security.
NIST: Connecting the Pieces
Before defining NIST, Costa again stressed that no single product, analysis or standard solves every problem. Different industries do different things and combine good practices as best they can. He said security strategy is moving toward something more sophisticated that includes resilience and defense in depth, and that frameworks like NIST and IEC 62443 help fit these pieces together.
He described NIST, the National Institute of Standards and Technology, as an organization that does many things. Among them, it maintains a framework that helps organizations understand the different phases of security and where and how to deploy it. NIST also publishes handbooks and special publications with more detailed guidance, including documents specific to industry. Organizations can adapt the broad framework using these specific documents. Costa called NIST the best-known framework among security professionals and said it helps organizations combine different steps and make sure they are progressing.
He explained that IEC 62443 originated in the U.S. as ISA-99 and was later adopted in Europe and other markets. He said it is now effectively a global framework.
IEC 62443 as a Nutrition Label
Chris asked Costa to explain an analogy he had mentioned before the recording. Costa, who said he loves food, compared IEC 62443 to the food industry, which he thought would make more sense to people outside security than references to NIST.
The analogy has three parts. First, a food production line can be certified for how it makes food. Similarly, IEC 62443 can certify the process a manufacturer uses to build its products. Second, historically it has been hard to know how secure one product was compared to another. Just as food has a nutrition label listing ingredients and proportions, there is also product-level certification. With it, a buyer can see the full "nutritional information" of a product: whether it has security and which security features it includes. Third, certification requires a response team, which Costa compared to a customer hotline. If someone finds a problem, there is a contact point in the company, and someone is responsible for handling the request. "I hope everybody's hungry right now," he joked.
Chris restated it with his breakfast cereal. A nutrition label says a product is nutritious, and a certification says a product is secure. Costa agreed and said this helps both sides. Manufacturers know what they should be doing, and buyers can be confident they are getting the security features they need.
What Sets IEC 62443 Apart
When Chris asked directly what IEC 62443 is and why manufacturers should pay attention to it, Costa described it as a standard, or handbook, that makes different recommendations for different audiences. In his view, that is what makes it unique. It gives guidance to product manufacturers like Moxa. It helps system integrators who assemble solutions. It also helps end customers know how to ask for security and what to ask for. By defining expectations for each role, it "closes the loop" so everyone knows what they must do to deliver a secure system.
Costa said this is why he sees IEC 62443 being adopted globally, and he noted that some people in industry will know it as ISA-99. For him, the most valuable feature is that certification is done by third-party labs. It is "not like self-stated," so everyone involved can trust what they are receiving and delivering.
How Moxa Approaches Cyber Resilience
Asked how Moxa builds cyber resilience into its designs, Costa said the company follows two main frameworks. On the IT side, it follows the ISO 27000 series to protect data and customer information. For products, it follows IEC 62443, which defines what should be included in how products are built.
He listed several elements. One is the incident response team already discussed. Another is actively searching the company's own processes for vulnerabilities, with the goal of finding them "before the bad guys find it" and releasing fixes. He stressed that this is about process and that it is verified by an outside company, not just defined internally. He believes this is why standardized definitions of security are becoming popular. He also presented this as a way to reduce supply chain risk for customers.
On the solutions side, Costa named two areas. The first is better protection at the edge of the network through improved segmentation. The second, which he called the second major problem after segmentation, is a lack of visibility. Moxa offers tools to help customers see what is happening at the very end of the network and to detect whether they may be under attack. He described visibility and segmentation as a necessity, not a trend, along with working with vendors that do not introduce new vulnerabilities into your system.
Chris added that for manufacturing listeners who do not focus on security day to day, understanding what makes a product secure by design helps them know what questions to ask their security teams and vendors.
Outlook: A Transition Phase, and a Warning About Change
Looking ahead, Costa expects AI adoption, along with both its benefits and its threats, to keep increasing. He does not see a future without continued pressure to improve. Demand is growing, and so are the threats that come with it. Certifications are needed, but he believes the market will take time to mature to the point of self-regulation, where customers routinely require these standards and the whole ecosystem works together. "We are in this shifting phase," he said.
His practical advice was aimed at asset owners, the people responsible for a system. Any change to an industrial system can itself cause incidents if you don't know exactly what you're doing, which is why the industry is cautious about changes. You need to understand what you are doing to avoid creating new problems or vulnerabilities. His recommendation was to find a partner that understands both networking and security and can help build a plan, because good products alone are not enough without an understanding of these impacts. He named Moxa as a company he can recommend. His framing was that such a partnership lets organizations focus on their core business while adopting AI, which he called necessary, "in the right way," with proper security in place.
The episode ended lightly. Asked what meal he would choose if this conversation happened over food, Costa admitted he loves junk food but tries to be disciplined, so he picked a protein shake. He added that he reads every nutrition label, which, as Chris noted, explains where his analogy came from.
AI, the bad actors using them in different arenas. They are using it to make their attacks more sophisticated and more precise.
In this episode, we're exploring how artificial intelligence is reshaping security and OT network requirements. That's right. This episode is focused on operational technology. We'll learn how AI is impacting everything from the factory floor to transportation networks and how we get around. Moxa's Felipe Sabino Costa will cover the importance of OT data. We'll discuss OT security in the age of AI. We'll dive into certifications and he'll share his outlook on the future of OT networks today on Manufacturing Happy Hour.
Felipe, it's good to have you here on Manufacturing Happy Hour. Welcome to the show.
Thank you Chris and all of you that are listening to us. I appreciate the invitation. Thank you for having me.
Yeah, of course. And cyber security in general, OT security, it's a topic that we talk about on the show at least once a year, right? It's probably been at least a year since we've done this. So, we are overdue for a refresh here. And you're just the right person to have here on the show. We're going to dive into a few topics today, but let's do the first one. Let's go into a 101 question right out of the gate. Why is OT, operational technology, data so important right now? Or set another way, what are some of the reasons manufacturers should care about OT data?
Yeah, that is definitely a good question. I believe that's the moment that we are living. It's a big change in how the industry used to do things and the needs that we have now. So nowadays OT data isn't anymore about logging and just, let's say, historical data analysis, right? It's more about predictive power, instant control, precision. So all of that actually shifts the way that we used to do things for the new technology and more data and everything else. So definitely it's a demand for more precision, and health, energy and other things that we are seeing, they are also shifting to a more predictive thing instead of just a reactionary one.
I would add real-time decisions. So you're seeing that historically we used to use the feedback as the process ends and send some information back to return to a decision-making process, but now we need to make it way faster. So during the process the system should recognize what's happening and shift decisions in the middle of the process. So it's way different from the way we used to do it in the past.
Yeah. So I'm hearing predictive versus reactive, a need to make faster decisions. One thing that I think is worth adding to this as well, and this is a big portion of our conversation, is I mentioned we've talked about this on the show before, but the last time I talked about OT, it was really, you know, AI wasn't really part of the conversation.
Correct.
What challenges are manufacturers actually hitting when they try to transmit OT data, especially now that artificial intelligence is part of the picture?
Yeah, you nailed it Chris, because actually a lot of these pushes and this demand that we are talking about, at different times or parts of the process where we make the decision, it's driven by AI, right? So AI may have different meanings, but definitely the idea is to use data to do something else that we used to do or could not do in the past. So when we think of OT, that by the way stands for operational technology, so basically industrial applications that build things, right, we see that they are very old systems. Most of them have been running since like 15, 20 years ago, and they have, as you imagine, a very limited type of bandwidth, the way that they were designed, because AI is pretty much like five years, six years of age in OT, if you will. So definitely the systems were not designed for that. So this is the first challenge: how do I make the data enable AI with this very old infrastructure.
The second thing is more about how you used to do things. Again, it used to be standalone networks. So basically I had different factories. They had their own job. They didn't have the need to exchange information, but now they do. I need to send data basically to maybe a cloud or a corporate data center to make, let's say, more global decisions, to be more efficient, and that demands new types of connections. And I'm dealing with these old systems transmitting more data and now in a more complex network. So this basically creates a huge headache for all the people, including myself, that need to make that happen.
So if I'm hearing it correctly, legacy networks with limited bandwidth. That was the way, you know, things used to be done. And then also standalone networks, if you will, where they were isolated in the past. Now with all the need to transmit data, things are tied together in ways they weren't before.
Exactly. One word that the industry used to like is air-gapped networks or air-gapped systems. So basically it has the meaning of isolated systems operating by themselves, right? So you got it.
Well, I'd like to dive into the bandwidth topic a little bit more, because I guess the basic question is why is bandwidth a particular issue right now? When we chatted before this conversation, I believe you had a good example from the transportation industry, possibly others as well. Can you share an example from industry that illustrates this a little bit?
Absolutely. I'd say to bring the concept, put some color, right? It's like nowadays we have 4K or high definition videos and try to stream them on a very old connection, right? The copper or the old telephone networks that we used to have. So it's that hard. Basically, you have a very old infrastructure and now we are trying to stream very high definition images or video. So this is just to paint a picture, right? And why and how it's happening, technically speaking.
A few examples that are running exactly under that situation, as you can imagine: we have the ITS, that is intelligent transportation systems. So the cameras and other, let's say, solutions that we have on highways to make transportation safer and also allow, right, the people that work with this data to make wise decisions and send basically people to support, etc. So what I have been seeing is this type of system has been adding more cameras, high resolution cameras, to take pictures of the cars or even stream live video, right, to exactly deliver these types of solutions I explained. And this is definitely increasing the quantity of information that I need to transmit through the line. And this is a very current example that we have been working on with different customers to help them make this transition.
Another one that is really hot and we can connect with AI: we have a lot of new types of processors, right? And as you can imagine it's a very precise process and you need to create them at very high speed and in a very secure and precise way. So they are using a lot of high definition cameras at the very end of the process. So pretty much where I'm building the processors, cameras help in image recognition or to improve different parts of the system, right? So basically use the image to support better color control or even increase the precision in how we make things. So right there, in the past we used to do it in a different way, and now we use cameras to help in the process. So this is another example where we didn't have the need in the past to use this type of definition, but as the adoption of AI is getting more popular, definitely we are seeing these data-hungry types of applications where they demand more data, just to name a few of them.
So I'm going to summarize here as best I can just to do a quick recap, because those are two similar but different examples. I thought both are really great. When we're talking about transportation, you're talking about intelligent transportation systems. The core thing that you're trying to do is make transportation safer. And you do this by adding cameras. As a result of adding more cameras, you're transmitting more data. Hence why bandwidth could be an issue in that scenario.
Exactly. And then similarly with the processors that you were talking about, it's a high definition process for making those controls. So again, you're bringing more visibility to that process, creating more data at the end of the day, and then hence again creating a situation where increased bandwidth is needed.
Exactly. And it's also important to share with your audience, right, that this is the technical aspect, but usually we have very specific needs across many industry applications. So reliability: as you can imagine, for example in Nevada, the temperature outside, right, is extremely hot, among other states. In other states it may be really cold, and the device should be running to provide all the safety and all the things that we just described, in a very, let's say, harsh environment, right? So we should include this rugged design, wide temperature kind of combinations with the hardware. So when we are actually talking about making all these AI adoptions and helping the industry shift, right, from the old to the new paradigm, definitely we need to deal with all these specifics that the industry demands. So this is where you also need to have this specific technology and hardware to make that happen.
Yeah, appreciate the extra deep dive into where hardware and temperature kind of play together in all this as well. I'm going to move into another thread of conversation, and that's OT security in the age of artificial intelligence. I mentioned security at the start. Really, we were just talking more on the data side there at the start, but let's ask another question to set the baseline. What is the current threat landscape as it relates to OT networks?
Yeah, that's a one million type of question, right? I would say we have a lot of challenges, but I'll try to name the two major ones. The first one ties together with the first part of the conversation, where we said that the industry used to be air-gapped or isolated, and many of the companies still think that they are, but they are not anymore, right? To be really air-gapped I shouldn't have any way to send data, but if I already have some, even if it's one connection to send data to a cloud or to another factory, that is not air-gapped anymore, right? So it's what we have been seeing. So the fact that I have these connections, doesn't matter if it's one or thousands of connections, I have a way to send data. We start to see this demand for what we call a second layer of defense, or close to the edge, or another way is actually protecting the real industrial device. Because as you can imagine, IT, or information technology, was born with security. So all their solutions kind of already had this design in mind, but in the industry, like we discussed, 15 years, 20 years ago security per se, data security, was not really a thing. Safety was, but now, exactly because of the reasons we are talking about here, security is also extremely important, right?
So this is definitely one of the major challenges, or threat landscape, that we can name inside industry: the fact that I need additional layers of security, and the industry is working on that. Just to give a number, usually, give and take, 80% of the global industry, including the US, does not have these specific layers of defense at the very edge. They have some defense, let's say, on the IT layer and some defense on the segmentation between automation and, let's say, corporate networks, but they have nearly zero protections close to the process itself. So this is where we need to work to protect.
Yeah, those are big examples right there. You know, for the folks that listen, let's just go back to the one you just said, like around 80, 85% of the industry in the US doesn't have basic defense in these types of scenarios. So that means there's really only close to what, 20% of people that are really actually doing something. So I hope the manufacturing leaders listening are asking themselves, am I part of that 20%, or am I in the vast majority here that aren't really doing enough around defense?
The other thing you mentioned is companies that once thought they were air-gapped, right, probably aren't anymore. With all the connections that have taken place, it almost does seem inevitable that pretty much, I don't know, pretty much any company probably has some sort of connection to the cloud. Obviously, not all of them, right? But it's become ubiquitous, especially over the past decade, that, you know, that's the reality. There is somewhere in that process that is likely connected to the cloud. So, just good, you know, self-awareness for the manufacturing leaders there. My next question is how has artificial intelligence resulted in new threats to OT security?
Yeah, definitely. We may have a different lens to explore this, but AI, like we are using it in every place, basically we're seeing the threat actors or the bad actors using it in different arenas or different areas. I would say, to try to put it more broadly, they are using it to make their attacks more sophisticated and more precise. So as we use, right, ChatGPT and many others to process a huge amount of data and information and get insights from it, they are basically doing the same. So this is one way to put it, right? They are combining different information about vulnerabilities, types of industry, and with that they can craft a very sophisticated attack with basically no knowledge, or nearly no knowledge, about OT systems and create these attacks. Probably one of the most common types is phishing, where the attacker kind of fakes an email and makes the person, or helps the person, right, to click on specific links and compromise the device. So basically they are everywhere, but definitely now they are doing faster and better the attacks that they used to do.
Yeah, I like that you used the phishing example. One thing that at least comes to mind, and tell me if you feel I'm on the right track: you know, when I leverage tools like ChatGPT and it starts to get to know a little bit more about me, about my podcast, for example, right? It's able to tailor responses better. In the same way, a phishing attack, which is a very targeted type of, hey, I'm trying to get this particular person to open this file, for example, right? With artificial intelligence, you can refine what that looks like. So it comes off as even more real than it may have in the past. Do you think that's a correct parallel to draw?
Absolutely. Absolutely. This is exactly what's happening. One of the facets, right, of how the hackers are using it. We have many others, but definitely what you just said is really precise. Usually in the past we'd make a simple scan, looking or reading the mail, and we'd find some typos or some inconsistencies. And now it's really harder to find them. So we need additional layers or even another AI to check this, to verify it, right? So it's way harder to take on this type of phishing attack right now.
Well, let's put this in the context of a story. Can you share an example as to how attacks are becoming more sophisticated due to AI? We talked a little bit about that in the context of phishing. I'd love to hear a bit more.
Absolutely. I believe that connects pretty much to what we have been discussing, right, in the other part of the conversation. AI has been evolving, and in the past we used to wait to have a response, feed it back and make a decision afterwards, after the fact, and now AI is pushing, right, to exactly make the decision early in the process and actually be more efficient. So the hackers are actually using the same analogy. So let's start in the past. Let's assume that they used to do like a
scans looking for specific ports and it was like a binary decision. I had like zeros and ones and if the port wasn't open I had to skip for another thing or maybe another target. But now with AI, actually the AI can adapt the code during the flight, and now let's assume that it's scanning some ports, it would be receiving some information and it can adapt the code to change during the flight attack. So they can be way more efficient and more dangerous, if you will.
So with that, basically, as everything else, the way that we used to do things, we cannot do anymore, right, in the same way.
So one thing that I have been discussing with different customers actually: it used to be really present to work on the prevention, more in the way that we used to defend. That is too important, definitely, we should be doing that still, but it definitely is not enough anymore, right? Just work on the prevention, have some layers itself. So this is the shift we have been seeing, right? As AI is evolving, the threats are evolving. The traditional defense on the perimeter, or these layers that I also call defense in depth, it's extremely important. Like you said, still 80–85% of industry is not doing even that. So definitely it's a step that they should be doing, but for those folks that are more, let's say, mature, they will be looking for something else, right? There is no silver bullet.
So definitely this is why we have these conversations with different customers and different, let's say, organizations, understanding their sizes, etc., because actually we need to understand who is the company, what they're trying to do, and adapt the best solution to them, right? So basically it will be a combination of defense in depth, detection, response, and in order actually to have all of that, we should probably talk about 62443, that is one framework, or even NIST, that is here in the US. For those who are familiar with the security landscape, they probably already heard of NIST before.
So anyways, these are kind of two frameworks, right, that can help the industry. The manufacturer like myself — I work at Moxa, the company that I work for — we design products, and I would say it's not just a matter of how we build the product and put the right things right there, that definitely is part of what 62443 defines, but also what happens afterwards: if I have people that can help the customer if they are facing an incident, or if they find vulnerabilities, that are basically flaws, if they have the right department to talk to.
So basically, I believe you're going to explain later to the audience during our conversation, but PSIRT is definitely the response team, specialized people that will receive that vulnerability and have specific timelines to address it. So we are seeing this trend, right, where basically we need to have this change in how we perform security. It's a combinational thing. So we definitely need a more strategic, I would say, security for the industry nowadays.
As we get into some of the certifications and solutions here at the end of the interview, that's going to come up. We'll get to that in a second. But before we get there, we should talk about NIST. We've talked about NIST, the National Institute of Standards and Technology. We've talked about it on the show before in our security-focused episodes. Can you first describe NIST for our audience? We have folks listening that are probably very familiar with it and others that, you know, maybe just hear it from time to time.
No, you got it. Before I really jump there, I believe it's important also to align the strategy part, right, Chris? So we're going to share a few standards. You just named a few of them that we're going to talk about in a minute, but basically it's important to understand that there is no silver bullet, right? There is no one thing that is going to fix all the problems. So this is where we have different industries doing different things and trying to combine, the best they can, the good practices, and that is definitely the case for NIST and 62443.
So we are seeing this shift, right, from this resilience, or how we used to do security, and now we are seeing more a combination of things. Strategy should be way more sophisticated, so we should consider resilience; defense in depth is another thing that we're going to see in a different place, and ultimately these frameworks, 62443, they help us to put all these pieces together, right? So definitely it's not just one thing or one product or one analysis, it's actually a combination of things.
So this is where we come to basically NIST. NIST, like you said, is an organization that does different things, and they have one framework that basically helps you understand different phases and where or how you should be deploying security, and they have specific, let's say, handbooks or special publications where you can have specific information. So they also have, specifically for industry, a few documentations that you can refer to, so we can adapt basically the framework with any other documentation that they have, and with that you have the specific and the broad. So basically NIST is the most well-known framework for those who work with security in different aspects, because it helps us a lot and helps us to have this frame of how I can combine different steps and make sure I'm progressing and evolving in my structure, right? So this is the first one.
And you kind of mentioned also 62443, which actually is ISA 99, so it was born here in the US, but obviously over the years we saw the European and other markets using this standard. Now it's basically a global framework that is named with this big number, 62443, like you said.
You know, I believe you had a pretty good analogy as to how IEC 62443 is similar to nutrition labels relative to NIST. Can you go into that a little bit?
Thank you for that. By the way, as we talk, I love food, right? So sometimes I try to relate a lot of things to food. At least for me, it's an easy and fun way to do it. So can you imagine, for a person that is not in the area, if I talk about NIST, maybe it's not in their day-to-day context. So definitely another way to make a comparison is basically the food industry. So let's imagine that you have the line that builds or manufactures the food, right? So we are seeing now different certifications appearing, and one of them is 62443, that actually can certify the line, for example, in how we build the food, or basically how we build our products. So this is one angle, how 62443 helps the manufacturers in how we can make better products.
The other thing is, actually, historically it was really hard to understand how secure the product could be compared to other products. So if you compare it to food itself, that has the nutritional label, you can see everything that is there, the ingredients and proportions, etc. So we also have, as with food, a product certification where the company, the manufacturer, the industry can buy a product and actually have the full picture, the nutritional information about the product, where it has security, which type of security features it has, and so on, right? So basically it helps in how we build the products, the line, and how we build confirmation of the product itself, that would be the label.
And pretty much a final one: usually, to have the certifications, you should have something that's called a PSIRT, that is a response team, so actually if you find something, you should have a contact, part of the company that is going to respond to that. So we can make the analogy pretty much with the hotline, where you can call and make your comment or request and somebody in the company is going to address that. So we can make the very same analogy to basically the industry side having the certifications. The company should have this type of group or department inside the organization to be able to literally take these requests and work on them and have like the shortcut. So I hope everybody's hungry right now, right? But definitely this is a good example of how we can combine security with our daily lives.
Yeah. Yeah. No, that's it. So I'll just recap that analogy really quickly because I'm a cereal guy. I have a bowl of cereal pretty much every morning for breakfast, right? So using that example, when I look at the nutrition label on a bowl of cereal, the things we're talking about, cybersecurity certifications like IEC 62443, like NIST, it's basically saying, hey, the same way a nutrition label would say, hey, this is, you know, a nutritious product, it would say this is a secure product, like the security products you're creating. Correct?
You got it. Exactly. It helps all of us, right? The manufacturers now know what they should be doing, and also whoever is going to buy it is certain that they are buying the security that they need.
Yeah. Now I probably should have asked this more directly, and it's come up as part of the answers, but I do have to ask it directly: what is IEC 62443, and why is this a certification that manufacturers should be paying attention to, especially
Yeah, we kind of already addressed that, but I believe the best way to define it: it's a standard or a handbook that recommends different things for different audiences. So the thing that makes 62443 very unique is the fact that they address different audiences, basically the manufacturers. As I work at a product manufacturer, definitely they give guidance for people like me that are going to build products. They also help the people that are going to put together the solution, that is the integration part, and they also help the end customer to know how to ask and what to ask, right? So basically they close this loop with all the parties or the roles, as they define them, that should be talking and integrating. So the easiest way to define it: they put the expectations for each part, so each one knows what they should be doing to deliver a system with security.
So this is why, globally, we are seeing the adoption of 62443. Like I said, maybe some folks here in the industry are going to hear ISA 99; it's the same thing. So definitely we are seeing this adoption in different areas because it definitely makes it a lot easier for all of us that are helping the industry, or needing help, to protect the very edge that we discussed. We have some guidance, some handbook that we can follow, and the best part, I would say, is we have third-party labs that can certify; it's not self-stated. So all of us can be sure that we are receiving, delivering, and basically combining the efforts to deliver security.
I appreciate the specific recap on that portion. Anytime I throw out a number or a standard in this conversation, I like to make sure we double down and define it for the folks that are listening, whether they're in the car or at the gym or doing something else. So now that we've dove into that, one of my last questions is: you're at a company that does security solutions. Can you describe how Moxa focuses on cyber resilience in your designs?
Yeah, definitely. As a company we follow basically two major frameworks. Frameworks help us to make sure we are evolving and doing the right things at the right time. So one of them, for, let's say, the IT side, we follow the ISO 27000 series, that is more about how we keep the data and all the information from our customers secured. But specifically for the products, like we said, the line, how we build, how we create products, 62443 has specific, let's say, books or certifications to define what should be included, right? So part of that we addressed in our conversation: there should be a specific team to respond to incidents, right? So this is one thing. The other thing is we should be looking actively in our process for vulnerabilities, so before the bad guys find them, it's our job to try to find them earlier, address them, and provide corrections. So definitely it's also about the process. It is not something that I define following the standard and have some other company come by and make sure I'm doing it; it's good for everybody, right? So this is why we are seeing the standardization in how we define security getting really popular.
The other thing is, okay, now I know that I'm building the right product and I have all the processes in place, that I definitely can help customers, and I'm not delivering supply chain risk because I'm minimizing all of them, we can address specifically solutions. So definitely part of that conversation is around how we can make better protection on the very edge of the network. So basically how we can make better network segmentation. So definitely we have solutions for that. The other thing is visibility. The second major problem, right, after the segmentation itself, is the lack of visibility. So definitely we have some solutions that can help the customer increase the visibility of what's happening at the very end and anticipate if maybe the person is under an incident, right, some type of hacker on the network. So this is definitely something necessary; it's not like a trend. But based on everything that we just discussed, it's absolutely necessary to have this type of visibility, segmentation, and have companies that actually can help by not introducing new vulnerabilities in your system.
Yeah, I think one important point I'd use as a bit of a summary around this topic is, for the folks out there that are in manufacturing, especially for the folks where security isn't necessarily their day-to-day primary focus, what I think you've shared is some very helpful understanding of what makes products and solutions secure by design, so that folks have a better idea of what questions to ask their security teams, folks like yourself, when they're looking to make their processes more secure, which, as we just covered today, is more important than ever because artificial intelligence has changed the threat landscape once again. My final question for you is a future-looking question. You know, what's your outlook on the future development of OT networks?
Yeah. So definitely, looking to the future, we are seeing this AI adoption, and all the goods and the threats that it brings, like we just defined, are going to just increase. I definitely don't see a future where we will not have this need for improvement, right? All of us are being pressured and driven by all these demands. So definitely this scenario that we're describing in this nice conversation, the trend is just getting more and more on both sides, right? More demand and more threats coming from this demand. So although we are seeing these efforts and having certifications that are definitely needed, it's going to take some time for the market to really mature enough to be self-regulated, with the customers deploying, requesting, and the ecosystem actually driving to this scenario where everybody should be working together. So we are in this shifting phase, if you will.
So this is why, if I put it in a simple way, I would recommend, if you are an asset owner, as you call the one responsible for the system, and you are unsure of how to do it — and keep in mind, right, if you change anything in the system it can create incidents, right, if you don't know exactly what you're doing. So this is why the industry is really strict in how to make changes in systems. So in short, you need to really know what you're doing to not generate more problems or extra vulnerabilities, etc. So find a partner, a company, right? Moxa obviously is one of the companies, the one that I work for, that I know that I can recommend, that we take
seriously the topic, but the idea is find a partner that definitely understands about networking and security and can help you build a plan, because it's not just a matter of good products. You should have a lot of knowledge and understanding of the impact that I just described. So based on that, this is our DNA basically in Moxa. We do that all the time. We are defining networks, we are studying our customers to help them to achieve their goals. So basically I believe that helps a lot. You'll find, and you can target or focus on your core business, right, and you can make sure that you're having the extra layer of security, the improvements you need, and leveraging the AI that is definitely necessary here, but in the right way, with the right security in place, and make sure you have the protections that we need in the times that we're living right now.
Yeah. And Felipe, you've had a great career in OT networks and security. I'm going to make sure folks have a way to connect with you over in the show notes page at the end of this episode. Ways to learn more about Moxa's OT security solutions, those will be linked up in the show notes as well. I do have one final question for you. The nutrition labels conversation got this on my mind. So, in the spirit of Manufacturing Happy Hour, I often ask my guests, hey, if we were having this conversation over a drink, what would that drink be? Right. In your case, if we were having this conversation over a meal, you mentioned you were a big foodie, what would that meal be, out of curiosity?
Wow, that's a hard question. Usually, to be fair, I love like junk food in general, right? But I try to be more disciplined about it, a couple things. So nutrition is something that I try to work hard on. So definitely it would be like a protein shake. I guess it's not fun, I know, right? So maybe a lot of people are gonna say boo. But that's true.
I mean, now your nutrition label analogy makes more sense, right?
I read all of them. I read all of them.
I still need to make it to the gym today and I will be having a protein shake afterwards as well. So, that's kind of a fun way to end this. Actually, the first episode of Manufacturing Happy Hour recorded over a theoretical protein shake.
That's, and I want to make sure the guys, like you said, if you're listening to us, definitely we can talk about what we call solution day, that myself or any other professional in our group for security can have conversations about that and definitely help you with no commitment. So definitely something that we are doing and helping a lot of customers. So maybe you can invite me to have a protein shake, right, with you guys.
Sounds good. Well, for anyone out there, whether you're drinking protein shakes or having something else, I always encourage folks, especially with these security focused episodes, to make sure you're having conversations about your operation, about your networks, and you are a great person to have those discussions with. So, Felipe, thanks so much for jumping on the show.
Thank you, Chris, for having me. Thanks for this opportunity, and I hope all of you guys enjoy it.
Cheers. See you.
Article published
