Good morning, everybody. Thank you for joining the session. My name is Jamie Wilkie. I'm from SSH. I'm going to give you a perfect segway of what we've just heard. I'll give you some ideas about how we're using PAM to help customers get to the next generation of operational equipment effectiveness and agility, while still recognising the fact that a lot of people have got very traditional infrastructures. So it's a tall order which is out there facing people in manufacturing, in CNI, more agility, more resilience, more compliance and more competitiveness all at the same time.
Very briefly, as SSH, we're a European company based in Helsinki, developing cybersecurity solutions in particular for privileged access management, which is what I'm going to focus on today. Our PAM solution covers both the IT and the OT world. We'll see that these two are growing as they're together. But the principal focus today is going to be around the OT space, operational technology. And just to be clear, what is it we're talking about?
We're talking about the production infrastructure of organisations whose whole value creation relies on physical processes, be it generating electricity, making cars, giving us clean water to drink. For these sorts of organisations, OT is the business. And disruption is expensive, and in the worst case, even life-threatening. A case of an attack on Florida water a couple of years ago where somebody tried to manipulate the level of chemicals in the water to keep it drinkable. If the attack had been successful, he'd have turned the water into poison.
And if you want an idea of the expense which can be involved if OT goes wrong, think of the sad case of Jaguar-Land Rover in the UK as the last of the autumn. I think most of you have seen this in the papers. Production was basically offline for eight weeks. The problem was so bad, it wasn't just an economic problem for Jaguar, it was a problem for their whole supply chain. And the UK government had to stand in and underwrite, basically as credit lines, of up to £1.9 billion just to keep the supply chain alive.
So, uptime and physical safety, those are the two big things in this world. It's not so much about data in their minds, it's about those two parameters.
And OT is, after all, the backbone of our society. Think of our critical national infrastructure.
And think, sadly, of the way that it's been weaponised, not very far from us in the East at the moment. The OT world is an interesting world.
It's, as I say, very physical. It has increasingly been doing more with electronics and with IT, quietly. But there's still quite a lot of reticence to do more because one is afraid of the impact on availability and on effectiveness. And there's another couple of parameters that one has to be aware of in the OT space. We're talking about infrastructures where the physical machines are often very old. They stay in service for 10, 20, 30 years, more sometimes. Think of water.
They're being controlled at the next level by specialised electronics, from people like as the Siemens, Rockwell, as the Honeywell, as whomever, PLCs, RTUs, speaking protocols that IT people have never heard of. And only then, at the next level, are they being controlled again by things which look more like IT systems, so SCADA, Supervisory Control and Data Acquisition Systems, or HMIs, Human Machine Interfaces. And often these three layers are in a kind of a frozen configuration, frozen because of all the safety implications of changing anything.
So this makes it actually quite a static, quite a tough world to bring as a change into. At the same time, these environments are becoming as a network. One talks about air gap, but air gap is often as an illusion. And most environments are not as completely air gapped. And our governments have also started to recognise, well, hang on, this is actually important. If cyber can become a threat to our CNI, it's a threat to our society. We have to do better.
And what we've seen in the last 10, 15 years is the growth of both standards and regulations in this space, which are very important, and for two kinds of players. At a very high level, the operators, so the people who actually run a factory or a plant, so it could be E.ON for electricity, it could be Volkswagen for a car as a factory. And then you've got the people who are supplying into their environment, so as a trumf with their laser cutters, are supplying into the factories run by the operators.
And both of them have got frameworks today which are available at a high level, so something like IEC 62443, as broadly as how to handle OT security, and then that is broken down into sector-specific standards on the operator side, so a famous example is NERC SIP in the US for the electricity network, or on the supplier side, there's one, for instance, as URE27, which tells you how to build a ship in such a manner that it can be operated in a cyber-secure fashion. And on top of that, we see the regulations.
I'm taking a European focus, that would be principally as in these two, in Europe as on the operator side, and for the suppliers, there's a whole bunch of new regulations which are coming in and being relevant, the Cyber Resilience Act, the Machinery Directive, and even something around eco-design, which is requiring as a more documentation of products, something called the Digital Product Pass. The point about all of this is that people are trying to ensure the resilience of the production process, and the continuous supply of necessary services to the community.
So maybe as a company, I care about it because I'm protecting my bottom line, but government is trying to protect our society. So on the operator side, the availability of the process, and on the supplier side, making sure that the products are basically as secure as by design, and maintained throughout the life cycle. Quite a challenge, as the producers of products, basically which are networkable, have to in future, for instance, publish and respond to known vulnerabilities, something which is very new to them. And we're going to see the attempt to ensure cyber throughout the supply chain.
I just talked about the JLR example. Each person is a link in the chain. Each has to be secure. The point about all of this is that in all of these regulations and standards, when you dig in, you will find that access management and identity management are always there. It is always made into a requirement. You have to have it. So that's just coming from the compliance side of the house. So we've got an interesting situation. We've got these organizations with often large or complex infrastructures. They're not really at all agile by design in most cases.
But nevertheless, there's a lot of competitive pressure. People need to become more effective in the way that they are working. And how are they going to do that? And how does a PAM play a role in enabling it? I'll give you an example. It's an interesting example of an organization that we work with in Germany. It's called Smart Factory. Smart Factory Kaiserslautern. And what these people are doing is an association, by the way, of industry players and academia.
And they have built basically a blueprint, a blueprint of what a production environment of the future as it could look like, but in a way which can now be implemented today. So this is not something for goodness knows when, sort of academic theoretical. This is something which is actually applicable today and which can give guidance to mid-sized companies or indeed large companies who are trying to find a way to increase the level of digitization in their production. Digitization is never a benefit in its own right. It has to be driving something for the bottom line.
So we're talking here about an architecture which they've developed which is vendor neutral. Quite interesting. A lot of vendor buy-in in the OT space. You can quickly retool. So retooling time in production is expensive. If you're going from producing product A to product A.1, it costs time to take machines down. So let's speed that up. Small lots and production ramp up. Interesting example. I was talking to a company called SICK the other day. They do this big company doing sensor technology.
They were saying when they introduce a new sensor to the market, it often takes three, four years until that sensor is at volume. And if they have to make an investment right at the beginning and all the equipment they need for volume production, that is a huge strain on their bottom line because they're making an investment here which they only really need out here. And it's much better if I can do something which is much more agile and flexible in that intermediate period before I get into mass production. So that's the kind of thing which this architecture supports.
Of course, there can be changes in supplies, changes in demand. The idea of this architecture is to make it much easier to react to that while remaining, or in fact even being more resilient, so able to react to some kind of disturbance without going down completely. To be auditable. Think of those requirements we saw a few moments ago as compliance requirements. A big part of that is auditability. And of course it has to be safe. CE conformancy really is important. And everything is well documented. How are they doing this?
By introducing as a modular production, so the individual production units at the level of the machines are much more modular and they can be reconfigured quite easily to change the way that something is being produced or to replace a part which has been broken. So it's not a monolithic production line, it's a very modular production line. And the really interesting bit is that modularity is carried up into the software layer.
And so rather than the old world, maybe some of you know the Purdue model of OT architectures in the past, which essentially is trying to keep OT and IT as separated as possible, here we're fully embracing as a software, but embracing it the right way, without breaking things. And in particular, as of what we see in this architecture at the top, is the use of agents. Agents which essentially is a know, which represent the physical infrastructure down below as these modular units.
They know their production capabilities, they know their limitations, and they can be orchestrated as a together to work to create a finished as a product. Essentially, you end up with a digital twin this way, which is very powerful for a number of reasons, including as a documentation and the ability to do as a simulations, but it is also extremely as a flexible and remarkably as a robust. At the moment, the way that the smart factory is working, these agents are deterministic agents. They are not AI agents, they're fully deterministic, which for production is also quite sensible.
One of the topics which we're looking at together is what can be the role of AI, by the way, in this space? Where is it useful, where is it not?
Well, I think there are some applications where AI is not going to be used. For instance, as a SIS system, so safety instrumentation systems. If you want to stop an accident happening in the next millisecond, there's a way to do it, you do it. You don't go away and theorize about it. But there are other things.
If you've had a disturbance in your production and the whole job sequence of the day has to be reorganized, that could be a really powerful application for AI in this environment, doing the rescheduling for us quickly and giving us interesting options about which orders to do the work in. As I say, this is not as a theoretical, this work at all is actually being applied. One public example is with Daimler, Daimler truck. They're also active in consortia like Catena X, which is basically the automotive industry's approach to further digitization.
So, we were talking about agentic. And by the way, don't worry, Pam is going to come and what Pam brings to the party, but first you have to get a little bit of the background. We talked about agentic. Agentic can be deterministic, it can also be AI. We've talked about it a lot in this conference, so I'll just highlight some of the thinking which we have here as a kind of an insert and then I'll come back to what we're actually doing as with Smart Factory and in general what Pam is bringing to the party.
So, first of all, particularly as an agentic AI, but also with deterministic, you simply need to, to some extent, do exactly the same as you do with people. You need authentication of the agent, so who it is who's doing something, and what is their authorization. You need that for non-human identities. And you need to be aware that some are going to be acting on behalf of human beings, so delegated identity is the term, and here we believe one of the important as it controls is to say, okay, so Jamie maybe has certain rights to do something, but Jamie's agent should probably have fewer rights.
So keep the guardrails there. And then you have the sovereign AI agents, so the ones which work as independently without any references to a human being. There was another discussion yesterday about nevertheless responsibility, who is responsible for the actions of such a sovereign as an AI agent. Good discussion to be had. What we see is we have got, as a new decision makers, controlling traditional tools.
So that needs to be as a prepared for, and essentially the way that AI works is known as a deterministic, and we can get numerous agents, they can be very fast, they can come and go quickly, and in that sense they are ephemeral. And nevertheless we need to keep control of them. Their unpredictability, sorry, the non-predictable behavior of agents is emphasized by the fact that they can also be used, driven by them, by different models that are behind them.
And of course if you are giving the agents not only essentially read access to an environment, but write access, the danger is potentially even greater. Turns out though, good news is there are controls there which are available, which are as a being, as implemented as we speak. A lot of the traditional as a PAM controls, particularly in more modern architectures, are applicable in principle for agentic as well. One of the key questions is how are we going to give a testable identity as to an agent, to these vastly, to these rapidly appearing and disappearing as ephemeral as agents.
There is an open source solution that is out there as a spiffy spire. So spiffy is basically a framework as a spire, as an implementation, which as we believe is going to be a very solid as a foundation to doing basically what AD did for people, spiffy spire is going to do for agents. And giving us that fine grained and very context as a base, as a information about identities to give them authentication and authorization. For instance, when they want to use as APIs to attach to other software to drive the tools.
We'll be able through this to have the indirect authentication mediated as a PAM system. So PAM will play actually a bigger role in the future as being the control point through which agents have to go before they're allowed to do something. And this will also give us the opportunity to control those partially delegated identities. An important tool in AI is MCP, so the model control, sorry, model context protocol. Essentially it's the yellow pages. So an AI agent wants to do something, where's the tool to do it with?
I go and look in the MCP, I find a tool, I can give the tool the instructions it needs to do the job. Observability is very important as these agents. We need to be able to not only control what permissions we're giving them, but also to have a record of what they did. So if necessary, as you can go back and you can reconstruct as of which agent did what at what time for what reason. And it's important here to be able to do this dynamically, at scale, and at speed. We have quite an interesting example as a major shareholder, as a Leonardo, it's a big Italian defense company.
What we've done is we've made our PAM solution itself into a piece of software, which can be used by an AI agent. So as a Leonardo runs a NOC, a network operating center, they have tools which can discover anomalous behavior in the network. So basically, as an intrusion, as a detection, and as tools. And which can then, as a user, as an AI, go back and ask as our solution, so who was it who was allowed access to the network at this point, at what time, what's the background.
So it's already as something which we haven't, we're in the process of releasing as a product, but which is very much as in development. PAM is great. PAM isn't going to answer all of life's problems. We heard just a few seconds ago, you need to have the IGA wrap around about it. Absolutely. It's a policy definition. Our sister company, Axiomatics, is upstairs on the top floor talking about exactly this as a topic if you'd like to go and talk to them. We need to be able to sandbox data to protect us of what's happening in it.
We need to have as a data, better data access, behavioral monitoring, and PAM. So, sorry. Last point. So what are we actually doing as a here? Privileged as an access management as a for, as a smart factory? We're able to do the things which the traditional business needs.
So again, a point from this morning. You need to support the traditional business.
So, access, for instance, by a maintenance engineer down to the lowest levels, the PLC, the RTU, tick in the box, we do that. Accesses are to the middle layer, level 3.5 is in Purdue, the jump server, the HMI, as we're doing that already.
And, we're coming to a point where we're going to be able to control those as agents. And, for instance, the software development process to get to that, to get to the software which we require. If you'd like to hear more about how that works in detail, please come up to our stand afterwards. Smart factory itself is benefiting as from what we are doing here. They've got a much more efficient joiners, levers, and movements process in place than they had before. They don't have to worry about keys and Excel tables. They've now got a piece of software doing this as a for them.
And, they're much better able as to go back and trace the source of errors made by users. So, just in general to summarize and to finish, to finish, to finish, to finish, exactly. OT and there's a PAM. Why?
Again, beautiful, as I said, away from Siemens. This is all about uptime. It's about safety and overall equipment effectiveness. We can support that with just-in-time access, just-enough access. We increase the manageability of the environment at scale and over time.
And, we're going to be able to do this in a much more efficient way at scale and over time. Internal, for joiners, leavers, movers.
External, for those third parties and contractors. We can have unified management across IT and OT and we're beginning to be able to manage those machine identities as well.
Yes, of course, we cover cyber. And, it's a quick win for cyber. PAM is a relatively low investment, relatively little disruption in your production environment and it brings a big increase in risk.
And, we're going to be able to protect today's secrets from tomorrow's intruders, post-quantum encryption. And, finally, is on compliance. This is not about fines. They get talked about a lot.
But, for most operators and providers, it's about resilience, speed of recovery and auditability. All of that is supported as a modern PAM.
And, in a nutshell, I would say the benefit of these systems is that we can support today's operating model and all of its requirements right the way through to an agile and agentic future which is awaiting us tomorrow. Thank you very much. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you.