Webinar: Bridging IT–OT Gaps: OT-Led Data Transformation in Action

Introduction

There are many technology infrastructures that are handling one or more processes in the Operational Technology (OT) networks environment. Due to the complexity of management and growth of these large number of infrastructures, this drives the industrial sectors to digitize and automate processes at an increasingly rapid rate.

Process automation application for industrial control systems are designed and purpose build for different industries for example: oil and gas, energy production and power distribution, mining, water processing and distribution, manufacturing, traffic control systems, and facility management.

While connected systems deliver added value and improved productivity, they also increase Cyber Security risk. Many attacks on OT systems seem to target older devices running unpatched Operating Systems (OS) and software. Malware and other attacks, specifically designed for OT systems, seem to be on the rise, with Industrial Control Systems (ICS) increasingly being a target. All of this is happening against a backdrop of accelerating concern about cyber threats by organization’s and world leaders.

However, we need solutions that will accelerate digital transformation by providing exceptional network visibility, threat detection and operational insight to this environment.

 OT Networking Challenges and Solutions

Considering the sudden rise of cyber risks to the OT environment, and increase of newly discovered vulnerabilities and threats posed to these environments, business and asset owners need to address these pressing issues with urgent attention. Moving forward, they have to assess the risk and potential damage to critical assets and other attacks against ICS infrastructures that may cause the organization serious or unrecoverable harm related to loss of production, loss of life, environmental or reputational damage.

This can be achieved with the help of Network Monitoring and Anomaly Detection (NMAD) tools. These tools should be able to perform some major tasks to mitigate threat posed by the Cybercriminals. Also, many OT systems use a wide range of protocols, which might not be understood by some NMAD tools. This can create many challenges as assets owners tend to combine many tools to mitigate these attacks and creating complexity from different vendor offerings these products.

The following top five NMAD challenges provide an overview of the most critical and common challenges to OT networking environments.

 1. Asset Visibility

In any effective Cyber Security environment, keeping the assets current (i.e. software and firmware level, and security configurations) can be extremely difficulty, time-consuming and required experienced technical expertise. Majority of the OT environments are confronted with the same challenges: have a large number of devices from multiple vendors; assets are being added and changed frequently; inability to detect new devices; and many unknown devices that can attract Cyber-criminals that you do not know existing on your network. Security and Network Professional will not be able to completely defend systems against sophisticated cyberattacks, but visibility into these threats will help to minimize security risks.

Hence, a complete and accurate, well formatted, and centralized asset inventory is very key for an effective OT network. An NMAD solution should automatically track all OT assets and immediately visualize the networks for contextual communication flows – revealing who “talks” to who. It should have automatic asset discovery with network visualization abilities. The feature should include up-to-date asset inventory which enhances cyber resiliency and saves time as automated asset inventory identifies all communicating devices.

More so, it should provide extensive node information including name, type, serial number, firmware version and components, and should also present risks information such as security and reliability alerts, missing patches and known vulnerabilities. Extensibility or customization of the asset repository with additional information such as owner, location, back-up status, endpoint security posture, and other related information is desirable. This capability should provide instant awareness of all OT network devices and their activity patterns.

Key network data such as traffic throughput, TCP connections, traffic flows (who talks to who), error transmissions, and protocols should also be presented. The presentation of the key data is required to improve the understanding of normal operations. There should be intuitive dashboards and reports which provide the ability to explore macro views and drive downs into detailed information on endpoints and connections. It should be able to filter views by subnets, type, role, zone, topologies and visually group discovered assets in lists and detailed single asset views.

2. Detection of Anomalies and Suspicious Activity

Majority of OT networks today are faced with sophisticated cyberattacks due to inability to detect and block unauthorized access to devices operating outside the normal set parameters. Especially, the current effect of zero-day attacks can be so overwhelming. The potential impact that can be achieved by their exploitation and the difficulty of finding and tracking all instances of the vulnerable library is wearisome. If a threat agent manages to get into the OT network, by exploiting zero-day exploits for instance, it may infiltrate the OT assets directly or through a subsequent attack. Unfortunately, many anti-virus and email security products are not able to detect these attacks, causing the adversary or threat agent to silently gather information and cause damage.

An NMAD solution should be able to quickly detect and disrupt threats and anomalous behaviours in OT multi-vendor operations environment. The solution should be able to provide irregularity-based detection to detect ‘zero-day’ attacks and provide the capability to detect OT assets behavior based on asset profile reporting on suspicious behaviours by providing detailed anomaly-based monitoring, so that deviations from the baseline will be detected and alerted.

Furthermore, OT networks need to adopt a solution that has the ability to use and/or combine network traffic and packet matching rules, payload/data content to trigger on signatures of anomalous and malicious behaviours, and custom rules as devised by a particular customer operations team to trigger on specific use cases and scenarios.

Early indicators of attack or compromise (IOC) are crucial to the OT environment. The tools should be able to categorize detected alerts based on threat severity or risk rating. Alerting system should have the ability to aggregate related alerts into a single incident. The detection of all malicious and anomalous activities should not be limited to protocol misuse, malware communication, tunneling attempt, as well as intrusion and hacking attempts from desktops, laptops, mobile devices, etc.

3. Centralized Monitoring System

The OT network environment is normally made up of multiple vendors devices and applications. These are usually administered and monitored individually, most times from different systems located at different locations. Majority of OT networks have no centralized security management platform across all diverse infrastructure components, as a result, different vendor systems are managed individually.

An NMAD solution should deliver a platform that supports most, if not all the different vendors systems and applications used in the OT network. It should be able to monitor and administer Cyber Security risks and threats from a single pane of glass platform. More so, an NMAD solution should be able to deliver a centralised OT network security management platform – no matter how large or distributed the customer’s processing infrastructure domestically or globally.

The solution should provide one management console interface that can monitor all network segments locally and remotely delivering aggregated summaries with drill-down to detailed information by the site which should aid questions resolution fast with the use of powerful queries capability.

The solution should deliver instant awareness of OT networks and their activity patterns to capture key data such as traffic throughput, TCP connections, protocols used between zones, and as well, accelerates incident response and troubleshooting efforts.

4. Vulnerability Management

There are multiple examples of malware, ransomware and other attacks that have caused financial, operational, and reputational damage to various industries. Potential threats scenarios could be executable files and applications containing malicious codes, or insider misuse of privileges resulting in data leakages, malware infections, and system or process disruptions. Inability to easily detect unpatched devices and to know the patch status of all the IT/OT devices are often presented as an excuse for the limitation of using automated scanning tools that are not allowed based on the threat of disruption in production infrastructure components. It is very difficult to have visibility into security vulnerabilities and potential penetration points in the OT networks without deep network insights into all levels of the OT network.

An NMAD should provide vulnerability assessment capability with supported automated identification of devices with vulnerabilities including severity levels. There should be an easy way to visualize, find, and drill down on asset and vulnerability information. We should be able to have a clear visibility of the known vulnerabilities and notify users when systems installed in the monitored network suffer any known issues. Vulnerabilities should be taken and synchronized from the National Vulnerability Database (NVD) and other sources, and matches based on updateable fields.

The NMAD solution should be able to present published vulnerability data on systems and devices that exist within the OT network environment, this information shall be gathered in a non-intrusive manner and without performing active network device scans.

The detection of Zero-day and other attacks are paramount. The NMAD solution should detect non vulnerability-based attacks or attempts such as zero-day attacks, brute force attack, information theft and application scanning.

 5. Common IT/OT Platform

The major issue in deploying solution across IT/OT networks is the ability to have a common compliance driver across all the network segments. There are hundreds of protocols that need to interoperable across and within these mixed environments. Additionally, there are limited support to integrate the OT network to Security Information and Event Management systems (SIEMs) which typically lives in the IT network.

There is a need for a solution that will provide a unified OT, IIoT and IT security integration and monitoring platform across all the networks. The solution should be easy and fast integrated easily with IT asset, ticketing, identity management systems and SIEMs, as data and security processes are streamlined across all the business network systems. The solution should make the existing infrastructure works better and more effective. Streamline security processes across IT/OT and make it easy to harmonize security data for cohesive response with in-built integrations for asset, ticket, and identity management systems, as well as SIEMs.

Conclusion

Dexcent with several years of experience in Industrial Control Systems (ICS) and having successfully delivered a number of industrial Cyber Security solutions has noted that modernization of OT network traffic insights is key to OT asset discovery, network monitoring, vulnerability management, and threat detection challenges that are common in the present day industrial Operational Technology (OT) environment. In addition, deploying a modern NMAD solution helps to align businesses’ cyber security goals as well as it hastens processes and better decision making.

About Dexcent

Founded in 2006, Dexcent Inc. is an engineering consulting and industrial automation company that provides a range of specialized solutions for clients in a variety of industries throughout the world. Our professionals have modernized IT and OT engineering methodologies into comprehensive solutions, specializing in information analytics, cyber security, infrastructure, and control systems engineering. As such, we pride ourselves on truly transforming industrial operations to optimize business performance and deliver bottom-line results.

Sarah Burghardt

CPHR President

Read Bio

Sarah Burghardt is the President of Dexcent, responsible for the day-to-day leadership of the organization, enabling strong execution across teams and delivering exceptional value to customers. With a track record of building high-performing teams and strengthening delivery capability, she has been an integral part of Dexcent’s growth and evolution. Sarah is known for a leadership style grounded in authenticity, clarity, and collaboration, consistently embodying Dexcent’s core values of Integrity, Care, and Excellence. She brings experience spanning executive leadership, consulting, and business operations, helping organizations align people and priorities to achieve meaningful outcomes. 

Andrew Capper

Vice President of Industrial Digital Transformation

Read Bio

Andrew Capper is Vice President of Industrial Digital Transformation at Dexcent, helping industrial organizations improve data-driven decision-making by optimizing the data journey, reuniting siloed information, and delivering a trustworthy version of the truth.

With more than 25 years of experience, he is known as a results-driven leader who delivers on commitments and tackles complex information management challenges with a practical, human-centric approach. His work spans digital transformation strategy and roadmaps, governance, digital maturity assessments, and performance measurement through clear KPIs and metrics. Andrew is a NAIT graduate with training in Instrumentation Engineering Technology and Security Systems, and he brings a strong focus on safer, more effective operations from data producers through to data consumers

Nader Asgharinia

MP, P.Eng.

Vice President of Enterprise SCADA & Advanced Applications.

Read Bio

Nader Asgharinia, PMP, P.Eng., is Vice President of Enterprise SCADA & Advanced Applications at Dexcent, leading the delivery of complex, mission-critical solutions with a clear focus on client experience and operational excellence. With more than 30 years in business execution and over 25 years managing multi-million-dollar programs for mission-critical and SCADA systems, he brings a pragmatic, delivery-at-scale approach to every engagement. Nader is recognized for building high-performing teams, driving disciplined portfolio execution, and delivering measurable business outcomes, including significant growth in program portfolios and team capacity over time. He holds a B.Sc.(Hons.) in Electrical and Electronics Engineering from the University of Newcastle-Upon-Type in the UK, a B.Sc. in Computer Science from the University of Calgary, completed Georgetown University’s Director’s Program, is a Professional Engineer in Alberta, and a Project Management Professional.

Gerrit Nel

CISSP, CISM – Vice President of OT Infrastructure and Cyber Security Services

Read Bio

Tobias (Gerrit) Nel, CISSP, CISM, is Vice President of OT Infrastructure and Cyber Security Services at Dexcent, leading the development and delivery of practical services and solutions that integrate, complement, or replace OT infrastructure and protect OT assets from cyber threats. He is known for building resilient security frameworks, governance processes, and integrated solutions that reduce risk and support compliance across diverse industries. Gerrit has over 40 years of relevant IT/OT experience and has built and delivered highly skilled and high-performance delivery teams. His strengths include Cyber Security roadmaps, security architecture, incident response, and alignment to standards such as IEC 62443, NIST, and NERC CIP. Furthermore, he has deep foundational technical experience in Networking and OT infrastructure systems architectures that he leverages in building and leading successful delivery teams. Gerrit holds a B.Sc. in Computer Science from the University of Johannesburg and brings deep cross-sector experience supporting clients in oil and gas, mining, chemical, healthcare, financial, and government environments.

Jaydeep Deshpande

P.Eng. – Chief Strategy Officer (CSO)

Read Bio
Jaydeep Deshpande, P.Eng., is Chief Strategy Officer at Dexcent, where he helps shape the company’s future by connecting strategy, innovation, and execution. Having led Dexcent as President for six years, he combines 28 years of experience with a deep understanding of what it takes to scale a business while staying true to its culture and purpose.
 
Known for his people-first leadership and ability to navigate complex transformation, Jaydeep plays a central role in advancing Dexcent’s strategic priorities, strengthening key relationships, and unlocking new growth opportunities. He brings a disciplined yet human approach to change, aligning teams, accelerating growth, and ensuring the organization evolves with clarity and intent. He is passionate about building strong teams, fostering a culture grounded in integrity, care, and excellence, and positioning Dexcent to create lasting value for its customers, people, and partners.
 
He holds a Bachelor of Science in Engineering from the University of Alberta, is a Prosci Certified Change Practitioner and a Project Management Professional (PMP), and completed the CMA Accelerated Accounting Program, complemented with more than 20 years of financial management expertise.

Karim Amarshi

Chairman of the Board

Read Bio

Karim Amarshi is Chair of Dexcent’s Board of Directors, providing governance leadership and strategic oversight to support the company’s long-term strategy and executive team. With nearly 40 years as an entrepreneur and owner-operator, he is recognized for building high-performance organizations and forging strategic alliances across Information Technology, government, health care, education, and energy. He is the former co-owner and Chief Executive Officer of one of Canada’s leading enterprise Information Technology solution providers, where he led the organization through three successful mergers and helped scale long-term client and vendor partnerships. Karim remains active across a diverse business portfolio, serving as a founding principal, officer, and advisor to organizations spanning Information Technology, hospitality, manufacturing, retail, and real estate in Canada and internationally.

Yasmin Jivraj

FCIPS, I.S.P. | Board Member

Read Bio

Yasmin Jivraj, FCIPS, I.S.P., is a Board Member at Dexcent, providing executive guidance and strategic oversight to support corporate management and long-term business direction. Over a 35-year career, she has held senior leadership roles across private, public, and non-profit organizations, with a track record of building operating foundations and driving profitable growth. Following a 15-year tenure as a co-owner and President of one of Canada’s leading strategic Information Technology solution providers, she expanded her governance leadership through active board service in post-secondary education and community-focused organizations. She is recognized for decisive, purpose-led leadership, clear communication, and deep expertise in technology, business models, and methodologies that help enterprise organizations advance digital transformation.

Nadir Jivraj

CEO, Board Member

Read Bio

As Chief Executive Officer, Nadir is accountable for providing overall leadership and Dexcent’s Industrial operational performance. Nadir has been involved as an executive sponsor with Oil & Gas and Mining companies for over 35 years, and through the years has developed a strong working relationship with the Executive leadership team of many Fortune 500 companies.

Nadir is known for recognizing value and superior investment opportunities in the technology services sector. His pursuit of highly prospective technology companies around the world has resulted in numerous company start-ups. Prior to starting Dexcent, Nadir had led companies through highly profitable business transactions, including the merger of Atlas Systems Group with CompCanada (later renamed Acrodex) in 2000 and later as Chairman of the Board of Axcend Pvt – an engineering solutions provider – based in Bangalore, India from 2004 – 2014. Acrodex and Axcend were sold in 2015