92 views
2 hours ago

The OT attacks hitting GCC infrastructure are coming through the IT door

Bachir Moussa, Regional Vice President, EMEA South at Nozomi Networks, has watched the region’s operators move from asking what operational technology is to demanding measurable protection for the people their plants serve.

When Nozomi Networks first took a stand at GISEC eight years ago, the questions from visitors were elementary. Bachir Moussa, who has spent six and a half years with the company and oversees a territory running from Italy, France and Iberia to the Middle East and Africa, recalls them. “The first few years were all about what’s OT? What does Nozomi do?” he said. Buyers now come with a specific outcome in mind, and they measure it by the safety of the residents and citizens who depend on their power, water and fuel.

Moussa credited the UAE with leading globally on OT security, acting ahead of any regulatory mandate. “Before there were any regulations, the UAE was leading,” he said. Rules from the Dubai Electronic Security Center and the UAE Cybersecurity Council followed, alongside frameworks in Saudi Arabia and the measures Qatar introduced for the FIFA World Cup. The geopolitical climate of recent months has sharpened the pressure, and Moussa said it had pushed urgency up significantly as attacks grow more complex, some of them AI-driven intrusions that start in corporate IT and move into operational systems. Later this month he is due to brief a body that covers the whole GCC.

Security is moving to the drawing board and the asset register

The region’s giga projects are asking the right questions early and specifying protection at the conception stage, Moussa said. “The early involvement is really helping keep those giga projects secure now and into the future,” he added.

The same discipline matters in oil and gas, where operators run equipment that cannot be patched or taken offline, so Nozomi’s work begins with a real-time asset inventory. “At least if they know what they have, they can put the right level of risk across the different assets,” Moussa said. Anomaly detection using the company’s built-in AI follows, along with tools that let operators act quickly when a threat surfaces.

We’re seeing many attacks coming from IT into OT.

Handing OT security to IT departments brings two cultures together, although Moussa said many IT staff have not been properly educated and trained on OT, including the fact that those networks cannot be patched. Regulation and training are narrowing that gap. “IT has cybersecurity as a priority. OT has availability as a priority,” he said. The integration matters because of the route threats are now taking.

Leave a Reply

Don't Miss

Your staff may be feeding company secrets to AI, and Tenable’s Maher Jadallah says legacy security will not catch it

At GISEC, Maher Jadallah, Vice President, Middle East & Africa, Tenable, traced
Help AG unveils post-quantum cybersecurity services in Dubai.

Help AG launches Quantum 360 for post-quantum security in the UAE

Help AG, the cybersecurity arm of e&, has launched Quantum 360 at

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy