About Ashish Agrawal
Ashish Agarwal, Director of Operational Technology at Agco, discussed the role of visibility in OT cybersecurity in an October 2024 appearance. He described visibility as a "foundational piece" of a cybersecurity program, stating that without knowing how many OT devices an organization has, it cannot produce solutions for connectivity or protection. Agarwal noted that three years prior, his organization began its cybersecurity journey with no knowledge of its OT devices and started by manually collecting data in a spreadsheet. He identified legacy technology as a challenge to attaining visibility, explaining that 15- to 20-year-old machines that work perfectly cannot communicate with current protocols, requiring solutions to convert their data. Agarwal also highlighted the next challenge as IoT devices embedding 5G adapters that vendors want direct open internet access to for maintenance, which his organization addresses by enforcing firewall routes and not allowing direct 5G or 4G connections.
In a September 2023 appearance at the ET Annual Gas Conclave, Agarwal, then Managing Director & CEO of Seros Logistics, praised the event for its relevant speakers and diverse topics. He stated that hearing different perspectives and sharing one's own perspective, along with audience engagement, makes an event successful. Agarwal expressed excitement about a panel on opportunities of 60 billion dollars in the space, noting that it allows for holistic decision-making by hearing everyone's views rather than taking decisions in silos.
Source: AI-verified profile updated from Ashish Agrawal's recent appearances.
Browse all interviews →
Transcript (22 segments)
I
Interviewer0:03
So first question about visibility. This is a really foundational concept for OT and the security and protection of these systems. What, in your opinion, does complete visibility enable in the context of cybersecurity?
A
Ashish Agrawal0:19
Mike, it is like without knowing what you have, how would you get the solution? So visibility is a very critical and foundational piece of a cybersecurity program. Earlier, if I didn't know how many OT devices I have, I cannot produce a solution for connectivity, I cannot produce a solution to protect them behind a firewall or segmentation. So visibility is a critical part. I'll tell you, three years back when we started our cybersecurity journey, we had no clue how many OT devices we have in our environment. We started with manually going back to the factory and collecting that in a spreadsheet, which was a good start. Then we started with SRA, which provided us visibility of the asset we are onboarding. But now we are in the journey of implementing XDome at all our factory locations, which is going to give me a broader picture of every single OT device connected into my network. Based on that, I can do segmentation. So it's a critical piece for me.
I
Interviewer1:32
Mm-hmm. And so what are some of the challenges that get in the way of attaining visibility?
A
Ashish Agrawal1:39
I would say the biggest challenge would be the legacy technology. The other one would be that a lot of machines are not even connected. Until you manually go physically and find out, 'Oh, this is the PLC which is not connected to my network sitting over here.' So a lot of manual effort, a lot of physical efforts you need to do to identify those devices. Two challenges: old technology which cannot be detected by our new stuff we are implementing now, whether XDome or a traditional way for active monitoring to look at it, and the second one is non-connected machines.
I
Interviewer2:22
Is there such a thing as shadow OT? I know everybody knows shadow IT as well.
A
Ashish Agrawal2:30
Yes. So I wouldn't call it shadow OT, but yes, every single manufacturing location we have, we have called manufacturing maintenance team. Traditionally, they are the ones who used to take care of everything within the factory, right? Connectivity of OT devices, data transfer, PLCs, HMIs, everything. IT just used to get involved when they have an issue with a firewall or they don't have internet connectivity or they can't have email. So yes, we still have a maintenance department, but since we have transformed and established the OT program to roll it out, we work hand in hand. It's like a partnership between IT/OT plus the manufacturing maintenance team together.
I
Interviewer3:25
So as a cybersecurity leader, why is it important if you can explain why it's important to understand the business value of OT exactly? I imagine that informs your program.
A
Ashish Agrawal3:39
Oh, absolutely. So it goes back to the question of why we are doing it, the funding decision of doing anything in the cybersecurity space in OT. You have to bring the business value on the table. Just give you an example: visibility is a good example. We are rolling out the solution like Clarity XDome for getting broader visibility of all OT devices in all our factories. But at the same time, we have a program Industry 4.0. In that program, we wanted to get machine efficiency data. Now, some of the data I'm collecting from XDome can fill that gap for that program. I'm just giving you an example. So this is a very big and critical use case for me to show the value to the business: 'Hey, this is not only protecting our asset from outside threat, but it will also give you insight into your own manufacturing operation, which helps you define better planning and execution.' So it's just one example, but other examples are very similar. You know, 'Why am I doing segmentation?' The reason I'm doing segmentation is because I don't want to leave a big open hole in our infrastructure where tomorrow some bad actor can come in and halt my entire manufacturing operation, which is millions and millions of dollars loss for a day. So that's the business value we need to bring on the table.
I
Interviewer5:16
I just want to go back to you brought up legacy technology. In this context of visibility, asset inventory, I would imagine that since these devices are running for 10 years, 20 years, that's just the way they were implemented and built. How does that get in the way of complete visibility?
A
Ashish Agrawal5:41,
This legacy technology does, and it will, because these machines which are 15 years old, 20 years old, working perfectly fine as they're supposed to do. We just can't replace them because they cannot talk to our technology in the current protocol, current environment. But there is a solution. There are some solutions available in the market which we are implementing anyway that can talk to the machine in a certain way and convert that into our language which we can understand. It's extra effort to get the visibility, but yes, answering your question, it creates additional work.
I
Interviewer6:25
I imagine it creates a lot of work overall for security patching, everything.
A
Ashish Agrawal6:31
Absolutely, absolutely. And that's the whole point of having the cybersecurity program: the visibility, the asset management, incident management, vulnerability response, and patch management. So it's like everything is all tied together.
I
Interviewer6:47
Another piece of that is remote access, and there's a lot of demand for additional access now given that we've connected everything to the...
A
Ashish Agrawal6:57
Absolutely. We don't want anybody to just have an open access to our network and connect to our machines without us knowing what they are doing and in a controlled manner.
I
Interviewer7:07
I know you spoke about secure access here at Nexus. Any general pieces of advice, you know, just from managing these remote access demands without getting in the way of business? I mean, third parties want access, your partners, your vendors, your suppliers, internal people need remote access for maintenance.
A
Ashish Agrawal7:27
I would say partnership. This is the battle I have seen in my entire IT career. Prior to IT, I was in engineering, and we always used to see IT as a hurdle, creating a hurdle for us. So partnership is very important. What we are bringing is the infrastructure for business to succeed, but business has to see it and business has to own it. That's what I said earlier about shadow IT. So we brought them as a partner in this journey. It's not an IT initiative, it's an OT initiative. They are the ones who own it. They are the ones who actually onboard vendors into the SRA solution. They are the ones who authorize every single access point inside the factory. It's managed in a centralized system, but all these individual logistics at the site level and the vendor level are managed by our manufacturing maintenance team. Partnership, partnership. That's the key.
I
Interviewer8:35
I mean, every discussion I'm having eventually comes back to culture internally and just the importance of getting with business leaders and making them understand your needs, you understand their needs.
A
Ashish Agrawal8:49
Absolutely, absolutely. Partnership with all the stakeholders is the key to success in this area.
I
Interviewer8:56
So just to get back to remote access for a second, do you have any specific dos and don'ts? Like obviously connecting PLCs directly to the internet is bad, but are there some more subtle things that people should or should not be doing?
A
Ashish Agrawal9:12
Yeah, so as I mentioned earlier, part of this journey and different programs we are doing, segmentation is one of them, which is already segmenting our manufacturing operations in a completely isolated form, implementing zero trust on top of it. So we anyway stop having anybody have any direct connection to our factory devices, any OT devices. That definitely we should not do, we should not allow. The one other thing which I see right now a pattern of is IoT. IoT is now coming with OT. What does that mean? Any single industrial device which you see now, the new ones coming, whether it's Rockwell, Siemens, they are embedding a 5G adapter on top of it with a maintenance agreement which they are forcing you to allow them a direct access to that device via 5G internet, open connection. That's the challenge. That's the next frontier, that's the next challenge. And we are trying to address that, whether it's through SRA or if the vendor has a really solid, mature solution, they still have to use our firewall route, no 5G, no 4G. So that's the biggest challenge I would see.
I
Interviewer10:37
But I mean, that is coming though. All these edge devices, the edge connections to networks that you don't necessarily control...
A
Ashish Agrawal10:43
Yes, it's a problem. It's a big challenge.