Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor with KuppingerCole Analysts, and I'm the host of this podcast. And as this host, I welcome Warwick Ashford. He is a senior analyst with KuppingerCole in the UK.
Hi, Warwick. Hi, Matthias. And this time, I do one thing differently. Usually at the very end of the podcast, I say, if you have any questions, leave them in the comments. And it makes much more sense to ask that in the beginning. So if you have any questions about what we're talking about today, Warwick and I, please leave your questions in the comments or reach out to Warwick and myself. And we are happy to reply to you. We love to get in contact. We love to get your feedback. You can influence this podcast, actually. So take this opportunity. But what is this podcast about, Warwick?
We want to talk about, and I said that before we started, we want to talk about the unloved step-sibling of cybersecurity. We want to talk about OT security, industrial control systems, and proper security for that. It's a very important topic for EIC, and we're running up to EIC. So that's one of the reasons, but it's not the only one. You did some research about SRA, another three-letter acronym.
So TLA, three-letter acronym. But what is SRA? So this time we're talking just about secure remote access. So that's in this context of OT. It's just where all the providers and engineers and so on need access to industrial systems, but they're doing it remotely. So it's just as simple as secure remote access. But to be honest, at least remote access has been around for decades. So we have been talking about, I don't know, Telnet, SSH, all these fancy, more OT-specific protocols that allow access to some machine, some box that is out there in the field or on the factory floor.
So what has changed? What even added the S to the SRA? So why has it changed or how has it changed from a connectivity tool to a security control?
Well, I guess it's just the demand has increased as it becomes technically possible for engineers and support people, as I mentioned, to connecting to these things. It's kind of far more cost effective for them to jump online and investigate something or investigate a system or correct something rather than have to make a journey there physically. So the fact that we can do it now just means that there is that demand for it, there is an economic imperative for it, and it has increased a lot.
So we just now need to make sure that the people who are connecting to these systems, which were now traditionally segregated from the IT systems, were all air-gapped and that kind of thing, now are remotely accessible via web interfaces and other networks used by IT. So it's kind of just expansion of the attack surface, things that were nicely isolated and contained before are now literally on the network. And so we need to make doubly sure that the access to that is secure because these are often critical systems.
Right, but when they are on the network right now, so why not apply the technologies that are around anyway? So if you think about operations people, MSPs, if we talk about developers quickly logging into their system to finally fix a bug, they use VPN, they use SSH, they log in via a virtual machine and then jump on from there. Why do you need something special for OT?
Well, you said it yourself, it's not so much about just getting access or enabling access, it's about controlling, it's about control. You use the word control and that to me is the key. So this whole market has now grown up around SRA, where it's a type of platform where you can control not only who has access, but what they have access to, for how long, under what circumstances, what they can do once they have that access. And then at the same time, it's continually monitored, it can be live monitored and it is all recorded. So it's highly auditable and stuff.
Obviously, this is now all being driven by regulations. This is kind of, there's growing regulatory pressure requiring controlled auditable access to critical systems. So I think that's kind of all come together, not only the technical capability, as I mentioned earlier, but now the economic imperative and the regulatory pressure requires it not only to just be connectivity, but controlled connectivity, monitored connectivity. It's also having insight into the sessions that are taking place.
So, and if we add another aspect that we have in the IT area for quite a while, it's this ominous term of zero trust. And I think that is something that applies to OT even more, because it's even more spread out into the infrastructure, into the architecture, into something that is out of the control of the organization. If you think of, I don't know, energy providers who have some boxes, legacy boxes somewhere out in the field in the green, that way you would need to have access. So what are, and I think zero trust applies to OT even more.
And I think that should be the starting point before you go to IT. Actually, you should do it in parallel anyway.
But OT, it needs to happen there as well. And these boxes are old. So we are talking about legacy. We are talking about OT on the one hand. We're talking about zero trust and the control that you've mentioned. How does that come together? Where are the challenges and how are they solved?
Well, as you said, you mentioned VPNs earlier. I think a lot of organizations just used VPNs, especially for third-party service providers. But VPNs just granted broad network access once they connected, so they lacked that granular control. So zero trust was just not possible. It was just, well, here is an access, we vaguely believe who you are, go for it. So there was limited ability to restrict access to specific devices, as I said earlier, and functions. There was none of that visibility and monitoring of what the user activity is, as I also mentioned.
And yeah, so there was just no zero trust control over critical OT assets. And they didn't meet the OT requirements of sort of protocol level restriction, because I was just looking at, I won't mention the vendor, but a recent vendor report, they were saying that attacks on OT protocols in 2025, so just in the period of last year, surged by 84%. So they aren't going unnoticed by the adversaries, let's put it that way.
So now, if you put in another layer, I quite like the term third-party access governance, because that kind of TPAG kind of makes a lot of sense to me. And I think more and more vendors are cottoning onto this idea too. I recently spoke to a vendor who's putting in a platform, their piggybacks off their PAM solution, their Privileged Access Management solution. And it's kind of like SRA, but by another name really here, we're looking at sort of third-party access governance. And it's that's providing that oversight, and it's also providing the connectivity.
So the individual suppliers are connecting to a platform, they're not connecting directly to the resources. And then all the direct connectivity is highly controlled, and it's through tunnels and so on.
I think, you know, but I'm not sure whether that answered your question. Yeah, but I think, yeah, that's one starting point.
So really, I love these pictures where you have on the one hand, this old castle and moats and just one bubble around, and that's the old perimeter base security. And then you have lots of tiny systems with lots of tiny bubbles around that, and that's zero trust. So you need to protect the outside of the individual systems as well. As you described, these are the ways how you communicate as well here. So we have secure communication in a hostile network, potentially, or in a hostile world. You have strong identities for everybody who's involved, the machine, the third party, as an example.
And then you can get to something that's closer to the zero trust principle as well. So, yes, I think it partially adds, answers my question. Did I miss anything? I don't know, you know, as you said, like the legacy protocols, they often lacked any authentication or encryption.
So what these new sets of solutions, whether you call them SRA or TPAG, they kind of wrap around these inherently insecure protocols, because as I think you mentioned, they were developed in a time where, you know, these systems were isolated, and you just went into a factory or you went into a plant, and you interacted directly on perhaps a terminal directly into the OT systems. Whereas now, because it's been done remotely, there's kind of all these other steps in between where they can be intercepted and so on.
So that's why this whole new set of controls are so important, especially for critical systems where you can have physical outcomes, you can cause things to go bang in the night, literally. Exactly. And you've mentioned that as well. So when people walk in and have physical access to the terminal, where you have full access to the system, because you most probably think you need it, not that you actually need it, but you think you need it.
So this is the equivalent, or maybe it is just route access, because you are finally at the machine and you do something and you are capable of everything that you want to do. And if we can, again, think of modern cybersecurity and think of zero trust, the principle of least privilege comes to my mind. And if we have secure remote access as a control for achieving better insight, better manageability, better auditability, that should come with at least the implementation of least privilege. And if you're piggybacking on PAM, yeah, that should be in there, right?
Yeah, well, you see, I guess what we're kind of driving towards and what's most relevant for EIC coming up in May is that for me and I guess for the entire community, security and identity have always been closely related. But I know from working on the EIC agenda, it's at one time we were kind of more able to separate identity from security topics. But now the security topics and the identity topics are intertwined. You can't really separate them.
I think what that's telling us is that more and more organizations or the practical realities of the world we now live in is that the way to control or the way to improve security is through identity. Identity is at the center of everything. And I think that's kind of what we're going to be looking at EIC is where identity is becoming now the control plane more than ever, where you can then have robust access to ensure that only users access what is required, only the right people. And as you said, the just-in-time or just enough access, I also quite like that idea.
It expands on the least privileged thing is just enough access. You don't get any more than you need and you only get it for the time that you need it. And SRA platforms often have sort of context-aware control so they can adapt based on the user or the device or the risk, because that's a whole... Another thing that we at Cooping a Call, as you know, talk about a lot is kind of a risk-based approach to everything.
So, you know, you've got to assess the risk and then in terms of that, apply the controls. So yeah, and then granular policy controls. That's something we also talk about at EIC and will be this year again, the whole idea of policy-based access control, where it's something that's centrally managed so that it's not on an ad hoc basis.
I mean, you just know that at the point of contact, you're going to be scoped to specific assets or applications or protocols. Right, and I think you've mentioned that implicitly.
And yeah, we even did an event last year that was called Identity-Centric Cybersecurity Impact Day. So this actually shows it. And if I think back for how to access, and I'm old enough to remember that, that when you did log on to the system, but there was no relation actually to the actual person who did this. So there was a technical account that was able to log into an OT device, into an OT system, but there was no personalization.
And I think that is the same principle that we see with PAM, so that you not only see, yeah, there's a root acting with this box or a DB admin talking to this database. It is Matthias using the DB admin account towards the system. And then you have identity-centric cybersecurity. Then you can apply least privilege because you understand who's actually pulling the strings, who is working with the systems. I think that makes, first of all, control, least privilege possible. And of course, I want to tick the boxes. Also visibility and auditability in industrial networks, finally.
And also support segregation of duties. Because if you don't know who it is, you can't do SOD. And the accountability expectations in regulated and safety-critical environments are much higher. So there are regulations around those. You've got to be able to say, as you say, who did what exactly, who did exactly what and for what reason. Right.
And again, you almost maybe tick the next box. So it's, of course, regulatory requirements. NIST 2 is on the plate of many organizations and organizations that did not expect to be there. So they need to comply with NIST 2 as a strong regulation, which includes also third-party access governance as a requirement. So SRA in the current form is actually solving problems and issues or solving challenges here, right?
Yeah, well, it's supporting compliance. But I think, as we all know, it shouldn't be about compliance. It should be about improving the security of the situation. But it just means that if you can see that someone who has ostensibly got the rights to do something is doing something in a strange way, some of these more sophisticated SRA systems enable administrators to shut down sessions in real time. And if they see things are going awry, they can suspend the session and then say, well, before any more damage is done, let's rectify this or whatever.
It just gives a whole level of control that wasn't there before, a whole level of accountability that wasn't there before. Right, so yeah, and you're controlling the supply chain, so in all directions, even across many hops. And I think that really helps organizations in getting better what they have already achieved, well and done properly already with privileged access management for the traditional IT environments. But when I hear what you're saying, there is lots in parallel between PAM and SRA, if I understand that correct.
So A, okay, I have to step one step back. You did research on that. You did a leadership compass, if I remember correctly, on SRA. You did additional advisory notes on how to use that on actually how to create infrastructures that combine this. So I expect there is a convergence between SRA and PAM. On the other hand, they remain separate solutions, question mark. So how does it change?
Okay, that was the question. Yeah, yeah, yeah, well, yes and no.
I mean, as I mentioned earlier, there is one vendor that I've been looking at, and they've developed a platform that sits on top, works with their PAM solution. So they use the PAM solution for all the credential management and the bolting and all that kind of thing. But then the kind of third-party access governance side is kind of specific to OT environments and is geared to handle those protocols. So it just means it's almost a specialized version of PAM, and it combines the sort of the credential management with session control and monitoring.
It centralizes approval so that it's kind of all in one place rather than being on an ad hoc basis or kind of not under the purview of administrators. And we mentioned the auditability.
Also, it creates a unified framework for managing privileged access and actions across OT systems. So you're right, it's almost like a subdivision of PAM. But I mean, I know PAM itself is kind of evolving in all sorts of ways, and it's quite difficult to say, well, where does PAM begin and end these days? Because at one stage, it used to be a fairly discrete area, but now the edges of that is also blurring because where do you stop saying something is kind of privileged or critical or important?
I mean, all access is now, so that's why I'm saying that I think one of the key themes that will come out at EIC this year is this whole idea of identity as kind of the control plane now. I mean, we've been hinting at it for a couple of years, but I think now, because of all the different things coming together all at the same time, from my perspective anyway, is that identity is becoming the control plane. Absolutely, and you said it, so PAM is changing while we are talking.
So we are adding secrets management, we are adding teams or cloud infrastructure, entitlement management, and we are adding parts of NHI. So the non-human identities or this huge umbrella term, which includes everything from technical accounts to machine identities. And now we are at machine identities and we're talking about OT, there is not too much difference between those two. So there is an overlap from a topic perspective and from an infrastructure perspective between PAM and machines anyway.
Yeah, no, no, you're absolutely right. I think one of the biggest shifts in industry 4.0 is this rise of non-human identities. We've seen a rapid growth in machine-to-machine communication across OT, IT, and cloud environments. And there's also increasing use of APIs. And of course, automation is the word of the day at the moment because everything that can be automated, it can be made more efficient, can be made more cost-effective.
But now we're moving into the brand new world of autonomous processes and in industrial operations, which is kind of slightly scary because, well, it's exciting and scary. So on one hand, you're opening up a whole new vista of efficiency and visibility. But on the other hand, we've just got to make sure that we're doing this in a secure way because if we don't, it could be rather calamitous. We're seeing now with the various conflicts that are happening around the world, there's very definitely a cyber component of this. It's no longer confined to the air and the land and the sea.
We've got the cyber component. And a couple of years back, NATO recognized that. We've seen that critical infrastructure is a target. It's kind of definitely out there as being a target.
So again, why send a bevy of drones when you can just tap into something remotely and cause problems and shut people's electricity off? So yeah, I guess, as I think you said earlier, if secure access is important anywhere, it's important within the kind of OT, ICS, industrial control system arena.
Right, and there's this old saying, the bad people, they don't break in, they log in. So this is, I think, something that needs to be prevented here. So if there are any questions in the audience regarding that topic, please feel free to reach out to Warwick, to reach out to me, reach out to our team. You can do this below this YouTube video. You can do this by mail. And you can do this at EIC.
So if you want to visit us at EIC and talk to Warwick and all the experts that are doing this OT security right now, so the practitioners, those who have the expertise, those who can give you the best practices, be there in Berlin in mid of May and join us there. You've mentioned that my final question, Warwick, you are part or one of the important players in the agenda committee of the EIC. What can we expect specifically for the OT-ITS section of our agenda? There will be practitioners and there will be vendors, so we can get it firsthand?
Yeah, there are a couple of sessions in this area, but I think most of the debate is going to be definitely in the AI arena, because that's what everybody's interested in. It's kind of the great unknown, and everybody's inherently aware of the risk. One of the sessions that I know that's coming up in the OT arena, though, is that there is a session highlighting the need for identity systems, including non-human identities, to operate securely, even in disrupted or low connectivity environments. I think they call them DDIL things.
So we have a session on DDIL and sort of looking at this whole idea of secure identity management within these sort of constrained environments. And so that would also fall into the category of critical infrastructure and OT environments.
Okay, that sounds interesting, and that's close to my heart as well. I'm not an OT guy, I have to admit. But as you said, it's really merging, it's really converging. I think there is not much difference between a properly run PAM system and a properly run system, SRA system, sorry. So I think that is really the main point. Maybe sometimes different principles, maybe you want to think more of resilience rather than security, rather have the system running rather than killing a rogue process. So there might be different approaches for that, but that's mainly it.
But the technologies are converging and AI plays an important role. And final sentence for those in the audience who are interested, and sorry, I know Warwick, you don't like it, but if you like great moderations on the keynote stage, please look forward to having Warwick moderating the first day of VIC and the keynote stage in the BCC in Alexanderplatz, Berlin. You were in for a treat because these are always great. Looking forward to that. So we will see each other in Berlin, Warwick. And we are looking forward to meeting many of you out there also in Berlin.
If you don't make it, reach out to us. It's not a must, but it should be there.
So yeah, looking forward to EIC, looking forward to learning more about OT and ICS security, about SRA and this other four letter acronym that you just mentioned. We don't explain it right now, so there is still an open question left. Thank you very much, Warwick, for being my guest today.
Well, thank you. And looking forward to more.
Yeah, looking forward to seeing everybody at EIC. Thank you, see you.