The head of our cybersecurity practice Sid Snitkin recently interviewed Claroty Chief Security Officer Dave Weinstein during the ARC Industry Forum in Orlando. I've included some key quotes from the interview below. Claroty has been in the ICS cybersecurity space for many years and is one of the leading threat detection and response solution providers. The company's latest round of investors includes companies like Rockwell Automation, Schneider Electric, and Siemens.
Dave Weinstein of Claroty
Claroty’s Mission
“Claroty was conceived very simply to protect the world's most critical Infrastructure… Critical infrastructure the basis for which is operational technologies, the industrial control systems that automate critical processes across all of our critical infrastructure sectors, whether it be food and beverage or electric utilities, so Claroty's technology and services are focused on a helping end-users and their partners understand their environment, gain deep visibility into their operational technology networks, mitigate whatever vulnerabilities or risks exist in the environment, and ultimately transition this into a continuous monitoring posture so they can not only root out latent threats but also understand, in real-time, what is happening on the network. Everything from the assets that are on the network to how those devices are communicating at a very granular level. “

On IT-OT Convergence
“If you think about the business value of what we do, there's obviously the core security component, but it has to roll up to larger business value. At the end of the day, it's about enabling digital transformation for industrial organizations that are eager to embrace IT-OT convergence without accepting prohibitively high levels of risk.“
“The value for them of IT-OT convergence is clear -- it enhances productivity, enhances efficiency, and in some cases enhances reliability depending on the industry. But they can't simply march down that road without thinking about security and risk management, and that's where Claroty fits in. So it's really all about enabling IT-OT convergence, because quite frankly for a while there was some discussion about [how] maybe we can just kind of maintain this air-gapped posture and not really embrace connectivity, but I think most organizations are beyond that now, and today it's about how we do that while managing the risk in a responsible way.”
On Lowering Barriers to Adoption for Cybersecurity Solutions
“One of our core focuses from a product development perspective is how we lower the barriers to adoption of operational technology security products. That means everything from making sure the deployment is fast, that there's fast time to value, and that throughout the total ownership of the product that maintenance levels are low. “
On Making Deployment Easier
“But also, from a security operations perspective, we need to make sure that the information that's coming into our interface or perhaps a third-party interface like a SIEM or a firewall is actionable. So, one of the major shifts that's happening in our space, as you know, is that end users are increasingly IT security professionals. Not just the IT folks on the factory or plant floor, but folks who have a broader aperture of enterprise security operations who are taking feeds from the corporate network and [are] now taking feeds from the operational technology side of the network. “
“So, what that means for us is not only are we going to have to make deployment easier and maintenance easier, but we have to provide the context around all the alerts and all the information that comes into that enterprise security environment. Otherwise, there's no value to the technology. So, we talk about this in the context of translating the syntax of OT to IT so that a broad array of security practitioners can ultimately ingest and action the information that we're bringing into the enterprise security operations environment.”
On Justifying Investment in Cybersecurity
“The value proposition differs by customer and sector, but we generally talk about the value proposition in the context of uptime, maintaining operational uptime, in the face of all these new cyber risks, which go beyond targeted attacks. So, we're not just talking about a nation state-backed cyber operation against your infrastructure. There can also be collateral damage stemming from commodity malware that's out in the wild.”