Nozomi Networks' Chief Revenue Officer, Kevin Isaac, recently met with ARC in our Dubai office to discuss the landscape of industrial cybersecurity. Kevin was visiting the region (Saudi Arabia, United Arab Emirates) to meet with clients and CISOs.

In our discussions, Kevin emphasized that the regulatory environment has finally moved into the OT environment. After years of cyber-related incidents and attacks across the globe. Since he has personally set up cybersecurity businesses for other companies in the region in the past, Kevin has witnessed several major cyber-attacks globally and some specific ones that have haunted the Middle East.
The Regulatory Environment Attracts Board Level Attention
According to Kevin, regulatory compliance is a board level issue. The board of directors manages the shareholders, the profitability of the company, and therefore they are interested in mitigating risk. Regulatory compliance is coming into Middle East and Asian countries as well. But what happens then? CISOs are reacting by thinking simply, “How can I use my existing infrastructure to make all of these issues go away?”
The issue becomes one of how to implement. Much of the world of industrial cybersecurity is not technology that can just be implemented out of the box. This technology must be implemented in a manner that it’s tuned, OT and IT data are collected, how alarms and alerts are handled, and there are several other considerations.
Making OTT Cybersecurity Work
Training, understanding, and professional service is important, but it’s not possible for Nozomi Networks to scale as rapidly as the market requires without support. That’s why they have created an environment where partners play a larger role in successful growth in MEA.
Kevin notes that there is a significant skills shortage in OT cybersecurity. Knowing that the OT environment requires a different kind of understanding than IT, he shares several instances where organizations have taken an IT-approach to cybersecurity in OT, which almost led to industrial incidents and loss of business for companies in the region. There needs to be a different approach with OT-specific subject matter expertise.
Why Nozomi Networks Is Confident of Progress In Middle East & Africa
“We are already there where the PLC and silicon is.”
Nozomi recently made several announcements regarding successes with its new security offering – Arc Embedded -- that provides extended, real-time visibility of internal operations of industrial control systems and their field assets to power enhanced anomaly and threat detection. They have managed to move much deeper on the protection aspects, going as far as Layer 0 in the Purdue/ISA 95 reference model.
"The big ones are data centers, the air conditioning, the generators are at risk and that’s where Nozomi sees important areas of review."
As we discussed a wide range of industries where several companies are trying to raise both awareness and adopt new innovations, I asked for his thoughts on what Nozomi views as the important aspects to focus on in the region. Kevin agrees that there is a huge opportunity in signaling on trains, medical devices, areas that require HMI, and others. According to Kevin, however, the big opportunity and the biggest risk for operators lies in the operational technology behind datacenters, such as the systems and related sensors that control HVAC, power, fire suppression, and access control.
"Specific Middle East countries are leading the charge in OT Cybersecurity technology change."
As you move to scale this is an intensive environment where you need to build cost, time and understanding. This is like a network detection system where you get real time compromise. And every country struggles with it. “You end up with an experience and no outcome.”
“Many international companies fall into a trap of unknowingly making commitments they can’t keep. When it comes to delivering solutions that secure critical infrastructure, building an effective ecosystem with partners and training competent people in country is vital.”