IKO

Headquarters
Ontario, Canada

Industry
Manufacturing

Overview

Raghu Jaswal, Global Director of Information Security for IKO North America, discusses how manufacturers can secure increasingly connected IT and OT operations. He emphasizes that identity must serve as the foundation of manufacturing cybersecurity, supported by least-privilege access, just-in-time authorization, multi-factor authentication, credential protection, session recording, and strong third-party governance.

As remote employees, contractors, and vendors require access to operational systems, Raghu recommends granting access only to the specific trusted assets they need and only for an approved period. Once that period ends, access should be automatically revoked. Privileged access management is critical to this approach because it allows third parties to connect without exposing internal credentials, while rotating credentials and recording activity for auditing, investigation, and training.

Looking ahead, Raghu argues that manufacturers cannot prioritize one security capability in isolation. Zero Trust access, reduced standing privileges, visibility, auditability, third-party controls, and resilience across distributed sites must work together as part of a holistic security strategy.

Key Takeaways

Identity is the foundation of secure IT and OT access.
As manufacturing environments become more connected, organizations need to manage identities consistently and ensure every user has only the access required for their role. Just-in-time privileges and MFA, particularly for remote access, are central to reducing risk.

Remote access should be limited by user, device, and time.
Internal users should receive least-privilege access only to trusted systems they need. Contractors and third-party vendors should receive approved, time-bound access that is automatically revoked when the authorized window ends.

PAM protects credentials while enabling secure third-party access.
Privileged access management allows vendors to connect without seeing or handling internal credentials. The PAM platform can manage and rotate those credentials while maintaining control over access to internal systems.

Session recording improves auditability and knowledge sharing.
Recording privileged sessions gives security teams a clear record of vendor activity for audits and investigations. Those recordings can also be reused as training materials or knowledge base resources for internal teams.

Manufacturing resilience requires multiple security capabilities working together.
Zero Trust provides the overarching framework, but it must be supported by reduced standing privilege, logging, auditability, third-party governance, visibility, and reliable access across distributed sites. No single control is enough on its own.

Hi, my name is Raghu. I’m Global Director Information Security for IKO North America, based out of Toronto, Canada.

As manufacturing organizations become more and more connected across plants, corporate IT, remote teams, third-party partners, what are the biggest cybersecurity challenges you see especially as IT/OT environments continue to converge?

I believe it starts and ends with identities. Managing those identities, making sure that they have the right access that they need, just-in-time privileges, enforcing multi-factor authentication especially for remote access, are the key components to build this. Because at the end of the day, the identities that are going to be the deciding factor.

Secure remote access has become essential for supporting distributed manufacturing operations. How should security leaders balance fast, reliable access for your end users, third parties, and vendors with the need to minimize risk in operational environments?

It boils down to having the right privileges, making sure that your internal end users have the unrestricted access only to the trusted devices that they need. When it comes to your third parties or your remote access contractors, you need to make sure that they all have access, but just-in-time access. 

What that means is that the access is authorized, approved by someone internally for the time that they desired that access for, and then that access is revoked once that time is up.

Privileged access management has historically been built around IT administrators and credential vaulting. How is the role of PAM changing as manufacturers need to secure OT assets, shared system service accounts, and high-privilege sessions across hybrid IT/OT environments?

For me, the adoption of privileged access management when it comes to the third-party contractors, when it comes to IT/OT, is paramount. The reason being is that you want to secure your internal assets, your internal identities, while providing secure access, remote access, to your third-party vendors or partners.

Using PAM, it is very important for me to ensure that when a third party is trying to connect inside my network, yes, they get the access when they need it. That is, after someone has approved that access. But they do not have access to my internal credentials. That is now being managed and rotated by the PAM solution. 

And also, with remote access, the whole session is being recorded so that if there is ever a need to go back and look at what this vendor did, we are able to go and see that. It’s also an opportunity for training because if we are deploying some new solution, we can record the whole session using a secure remote access recording solution and make it available for the internal resources to go back and look and become a training guide or knowledge base article of sorts.

When you look at the future of manufacturing operations, what security capabilities do you think will matter the most? Zero Trust access, reduced standing privilege, better visibility, third-party governance, or resilience across distributed sites?

I want to say all of them because you need all of them to work together in unison, in synchronized ways. That way you have the just-in-time access, you have the logs, and the auditability factor.

You need to make sure that from a resilience perspective, the solution is available when the need is there: it’s not that things are down and your solution is down as well. 

So I would want to say that it is going to be everything. You cannot just use one or prioritize one. 

Of course, Zero Trust, I would say, is the overarching framework that you need to apply to your holistic solution holistically. But it will be basically each and every vertical that you spoke about that will help us achieve that next security resiliency.