Headquarters
Dublin, Ireland
Industry
Manufacturing
Overview
Adnan Ahmed, CISO at global food manufacturer Ornua, discusses the cybersecurity challenges created by increasing connectivity between IT and operational technology environments. As manufacturers adopt smart factory technologies, cloud connectivity, IoT, ERP integrations, and AI, security teams must protect decades-old industrial assets without disrupting production, safety, or business continuity.
Ahmed explains how Ornua applies Zero Trust principles to control access for employees, IT teams, equipment manufacturers, and other third parties. He also highlights the role of frameworks and regulations such as IEC 62443 and NIS2 in strengthening MFA, least-privilege access, segmentation, auditability, and broader cyber resilience.
Key Takeaways
OT security must prioritize availability and safety.
Unlike enterprise IT, where confidentiality is often the primary concern, manufacturing environments must first protect operational availability and worker safety. Cybersecurity controls must therefore reduce risk without interrupting production.
Legacy manufacturing assets require compensating security controls.
Industrial equipment may remain operational for 20 to 50 years and often cannot support modern security capabilities or frequent patching. Organizations need mitigating controls such as Zero Trust access, segmentation, MFA, and tightly controlled connectivity.
Smart factory initiatives are expanding the attack surface.
ERP integrations, IoT devices, cloud connectivity, automation, and AI use cases create valuable operational opportunities, but they also introduce new access paths and risks that manufacturers must address.
Access should be limited by identity, purpose, and time.
Employees, internal IT teams, equipment vendors, and other third parties should receive only the access they need and only for the required period. The same verification and least-privilege principles should apply to both internal and external users.
Security cannot come at the expense of production.
Manufacturers must provide secure and usable access while maintaining plant productivity, equipment availability, and health and safety requirements.
Regulatory frameworks help establish a consistent security strategy.
Frameworks and regulations such as IEC 62443 and NIS2 reinforce foundational practices including MFA, least privilege, assumed breach, controlled connectivity, backups, segmentation, and auditability.
Segmentation is essential for containing IT-originated attacks.
Because many manufacturing incidents begin in enterprise IT, organizations must prevent compromised users or systems from moving laterally into OT. Strong segmentation between IT and OT reduces the potential impact of a breach.
”“As Chief Information Security Officer at Ornua, I am delighted to share how Xage Secure Remote Access Solution has revolutionised our security posture for operational technology. By moving away from traditional VPNs, Xage enabled us to adopt a truly modern, Zero Trust approach to remote access, delivering robust protection without introducing unnecessary complexity.
Xage’s granular access controls, MFA, comprehensive policy enforcement, detailed logs, audit trails, and session recording capabilities have provided us with a resilient and scalable foundation for securing our OT assets. The Xage team delivered hands-on support throughout deployment and beyond, resulting in a seamless transition for Ornua.Xage has empowered Ornua to modernise secure access, protect sensitive data, and enable flexible, secure connectivity for our employees and partners. I strongly recommend Xage to organisations seeking to enhance remote access security while maintaining usability and scalability.”
Adnan Ahmed
CISO, Ornua
About Ornua
Ornua is a dairy co-operative which markets and sells dairy products on behalf of its members; Ireland’s dairy processors and, in turn, Irish dairy farmers.
Ornua is Ireland’s largest exporter of Irish dairy products, exporting to 110 countries worldwide. Headquartered in Dublin, it has annualised sales of over €3.4 billion and a global team of 2,900 employees. Ornua operates from 10 business units worldwide, including 13 production facilities, and has sales and marketing teams working in-market across all four corners of the globe.
The Group is structured across two divisions: Ornua Foods and Ornua Ingredients. Ornua Foods is responsible for the marketing and sales of Ornua’s consumer brands including Kerrygold, Dubliner, Pilgrims Choice, Forto and BEO. Ornua Ingredients is responsible for the procurement of Irish and non-Irish dairy products and for the sale of dairy ingredients to food manufacturing and foodservice customers across the world.
Read the Transcript
I’m Adnan Ahmed, CISO at Ornua. Ornua is a global food manufacturing company, headquartered in Dublin.
Food and beverage production environments increasingly depend on connected operational technology. What makes securing IT/OT converged environments in food manufacturing different compared to securing traditional enterprise IT?
In the food manufacturing sector, the main reason behind OT and IT environments being different is because their priorities are different.
For example, in the IT environment priorities align to the CIA triad: confidentiality, integrity, and availability. Whereas in the OT environment, availability is very important, then safety, then integrity, and confidentiality comes last.
The environments are also designed and developed in a different way. For example, in the OT environment, the devices that we have last for 20 to 50 years. This is very common practice, especially in the food sector where the profit margin is very small, so companies tend to stay with those devices.
Recently, we are seeing the proliferation of different technologies, for example, with smart factories. The difficulty for CISOs with smart factories is that the business and operations would like to do more automation, integration with the ERP systems, IoT using cloud access connectivity. We’re also talking about AI use case proliferation in the factories. These objectives bring challenges, and those challenges need to be addressed with regard to the new way of working. These are just some examples of how the traditional environment is different from the OT environment.
We are trying to bring the same IT aspect into the OT environment. When we bring all those things, we need to make sure we need to have the same level of security available. That’s difficult because the environment is different, the demands are different, regulatory compliance requirements are different.
The answer to all of these is to make sure that the devices are protected using Zero Trust network architecture. Before you trust anything, you need to make sure you need to validate every individual employee.
You need to make sure you have Zero Trust in place in your environment, but also make sure that the devices the that you are not going to patch have mitigating controls. There is a series of events that you have to do to make sure the environment is protected.
For a global company like Ornua, with employees, partners, and third parties needing access to sensitive environments, how do you balance secure connectivity with usability and business continuity?
This is a really important question for CISOs. We produce Kerrygold butter, so we need to make sure that there’s high availability and security when producing it. Health and safety are also key concerns.
From CISO perspective, we need to make sure that when the external OEM vendors try to access those devices, that access is controlled and protected through Zero Trust network architecture.
The most important thing is to make sure that whoever is connecting to your environment feels comfortable gaining access to whichever solution they are using, and making sure to give them just-in-time access. For instance, if they need access for a couple of hours, make sure to give access only during that particular timeframe.
The same principle applies to your internal IT staff as well. The Zero Trust principle shouldn’t be only for external people. Trust everyone, but verify. If you use that principle, make sure that even the internal employees and external contractors are both using that principle to gain access to the environment. In my opinion, that is very important.
At the same time, you need to make sure that the productivity of the production plant is not impacted. So make sure it’s still highly available, it is secure, health and safety issues are not compromised, and also your environment is patched whenever it is feasible or possible to do that patching.
For a global manufacturer like Ornua operating across multiple regions, how do regulatory and compliance requirements influence cybersecurity architecture decisions, especially around access controls, MFA, auditability, and privileged sessions?
Regulatory compliance actually helps CISOs make sure that they’re aligning all their strategies to a specific framework. The OT industry is not as mature as the IT industry in the food and manufacturing sector. For instance, in IT they may try to gain an ISO certification or follow a NIST framework. In OT, mostly companies, including Ornua, try to comply with IEC 62443, but that whole framework is not as mature when compared to ISO or a NIST framework.
Once you start aligning all the principles of security under one framework, it makes your life easier. You should adhere to always-verify principles with MFA, assume breach principles, and principles of minimum access.
There are also new regulations coming. In the EU, there is a network information security directive called NIS2 being implemented. A number of countries within the EU already have transposed NIS2 into their local laws. This has already been done, for instance in Germany, where we have a big footprint. In Ireland and Spain, where we have large footprints as well, we are still waiting for the local governments to transpose it into law.
NIS2 is also re-emphasizing the basic principles like MFA. MFA is required for OT equipment. In OT environments the devices are, by default, quite old, and sometimes MFA is not possible. If you can’t do MFA, make sure you have mitigating controls.
Zero Trust principles still apply, MFA requirements still apply. Make sure the basic security hygiene, the backups of the environment, and environment connectivity is controlled.
Network segmentation is critical in OT environments. Organizations cannot afford to operate flat networks that allow attackers who compromise IT systems to move freely into OT. Strong segmentation makes it significantly harder for adversaries to reach critical operational assets and disrupt production.
Most breaches, especially in the manufacturing and food sectors, start from IT, not from OT environment. So if you protect your IT environment, make sure you have microsegmentation and physical segmentation to make it as difficult as possible for the hackers to try to gain access from the IT into the OT environment.
These are some examples of how the regulations’ principles can help you. So from CISO community perspective, we actually love those regulations because they make our life easier. You’re aligning your strategy against specific principles that are already available. So IEC 62443 and NIS2 are not two different things. They are talking about the same thing, but you are trying to align to principles that you can then follow.
