In this episode of the Evolution Exchange Podcast, Teemu and Ari from Valmet’s cybersecurity team discuss OT cybersecurity within the company. Valmet, a global supplier of paper machines, pulp mills, boilers, and automation systems, operates in 40 countries with 90,000 employees. Their automation solutions business provides distributed control systems, project services, and after-sales support. The cybersecurity team, part of automation solutions, focuses on educating internal experts and customers, managing supply chain risks, and integrating third-party security tools—not on running a security operations center. OT cybersecurity matters because regulations like NIS2 mandate protection of critical infrastructure, while cyber criminals and state actors target production availability, causing financial or societal damage. Safety and environmental risks are also key, especially in marine and energy sectors. Customer expectations are rising with regulations, but Valmet emphasizes that risk assessment ownership lies with the end customer. Challenges include multi-vendor environments, legacy systems, and adapting IT practices to OT without disrupting production. Future plans involve the EU Cyber Resilience Act, which demands thorough vulnerability management across all digital components, including third-party ones. Valmet advises customers to manage supply chain risks and align IT and OT security policies.
[Music] Welcome to the Evolution Exchange Podcast. A melting pot of ideas and inspiration shared by some of the most successful technical leaders in the world. The views expressed by the speakers on this podcast are their own and not necessarily representative of their organization. [Music] Hi everyone and welcome back to the latest episode of the Evolution Exchange Podcast. Today we're running an episode alive from the Valmet office in temporary with a couple of the cybersecurity team from the organization. Let's get to know today's panel. First up is team. Yeah, hello everyone. So, they will give you a daily working here as a soloist and minister in the world together. Our old and the most innocent, and a part of the Valmet house and working mostly developing outside the cybersecurity services that we provide to one and one with customers. Great. Thanks for joining us and Ari. Hello everybody. My name is Ari Rhyme. I'm working closely with the team in the same organization. So yeah, I just more like a technical product, many sort of services that we are providing to the old decide without customers. Thanks guys. Just before we jump into the full episode today, I thought it'd be a good place to start by asking just a little bit more about who Valmet are, what you guys do. And teaming over to you. Yeah, Valmet is got arrested on a mess in their company. So we build big mess in. So we're very, very well known in pulp and paper industry because of what Valmet makes has always made paper messes, board messes, tissue messes, pulp mills, and also boilers to, to a, for example, power part. But yeah, says if pop a paper mess maker, we have something almost 90,000 worldwide in 40 countries and the customers everywhere. But what we are now today, we are from Valmet, what's called, automation solutions, a business area, I guess, that is, and we have a 2400 around the world and we make a process automation system. So we have four easiest brand district control system brands, biggest business. Let's go from the TNA and then. So we we we've developed that manufacturer that market that then we have extensive project services and then after after sales services. So so kind of what we are automation vendor for process industries and biggest of those is pop and paper but very heavily in in a energy production also can and kind of a nicely curious data speakers, cruisers, those vessels that you think you can be a cruist, they may have walnut DNA, all boards or we supply also to so I'm adding automation and then yeah, that's what we are. My parents have just been on a Caribbean cruise, I'll mention it to them but let's go over to Ari just give us a quick overview of I suppose the cyber team that you guys sit within Valmet. Yeah, like demo and so we are quite big company and global level whole Valmet so and we are like a sitting on the automation solution side. So we have a lot of law service service people and then like we have people in the area, these side who are developing the automation products and components so but what we don't have is that we don't have like a maybe like a global cyber security unit but we have a lot of people for the processes development software development and then we have this expert on the service side who knows their automation processes and our systems how we are implementing them and providing services for who we are like a more more teaching and trying to educate on their cyber related things. And what we don't use what we don't have is is that we don't have like group of people sitting and waiting with backpacks that they can go and rest to the cyber cyber incident so we don't have that but we have a lot of expert expertise on the R&D side services and also people working with the processes in the whole world for the better, say good and a commercial say good solutions. Thanks guys I think that gives really good context to today's episode pretty much everyone in Finland will know Valmet as an organisation but the purpose of this episode is to highlight a bit more about what you guys are up to within the cyber side of the company. So today we're here to talk about OT cyber security and what Valmet are doing in this line of work. The first discussion point we're going to look at is why OT cyber security matters in the modern world who wants to get started her? Well I guess that's so yes as everyone probably knows Valmet they can make big machines and all the way Sun and the valves and such things and the why Valmet is interested in cyber security and the answer is that especially in EU area the latest layer in the regulation is bound to low now this so if you want to be in this like we hear it well that I'm making this distributed control systems and related automacist also so you have to do for one perspective and of course from EU or or Nases perspective or companies perspective cyber criminals are very interested in all these systems because there's potential potential huge possibilities to make make kind of a customer harder products on plan in a such situation that everything stops and everything expensive so potentially extra money plus the Nases that operatives want just that kind of their animation if you will their critical infrastructure cutoff power and so forth and since one is heavily in this kind of a business so we just need to be in OT cyber security. Yeah I couldn't say it better but yeah I guess also like in the OT usually it's it's all like a safety and environment issue also so nowadays it's more like a thinking of what kind of cyber secluded scenarios complete to the people safety issues or challenges in the environment especially in the marine sector and so like in these cruise ships nowadays they have taken to cyber security in the progress because the people safety so they are sailing with all of people it's all about their tent view to be safe on the sea. Could I just ask guys as well with the kind of customers that you guys work with I presume some cyber criminals will target organizations for monetary gain or information but within OT cyber security is the sometimes the risk that they're not the cyber criminals aren't actually always looking for that kind of thing but they're looking to damage reputation scare people and the kind of businesses that you operate within where is that so to speak. Do you poll? Yeah okay if I pick it up so yeah so this kind of industry can industrial HBNR in OT is not that big thing as it is in IT so you steal somebody's some company's credit card in from a self-employed cloud or something like that that you extort that company that we will reveal this or sell this yeah there's such things in OT as well but I think this this traps or products are causing financial damages or damages to the society it's it's a bigger thing this this attacker prevents you to do your productions the availability is the king health you can if you can stop the product and not so much that you steal information. Yeah maybe like it's not it's not necessarily always that they are targeting them of course they are a lot of for the critical use of the targeting attackers but it's also a lot of a lot of that people who are maybe watching watching like a hacker videos or like learning things they might end up defining some kind of automation system online it's it's just not know what it is doing so it might be like they are just trying different things because it's open to internet so many times the second level targets that that our customers are setting off they are actually trying to avoid and protecting from from very basic things if it's open in the internet very old operating system or whatever device so it's just fun to understand that how to be like a also protecting from the script kiddies or all these kind of people who are just the experienced yeah fighting devices I just moved on to section two the why of end is most own cyber part yeah it's because customers are expecting that so I don't think that if Wal-Met would say the Tokio reads a soup by our Wal-Met DNA easy assistant to we know they care of cypress security at all first of all as I said it's in the latest recent we have to do at least something but the but the customer
Ta designimme siitä, mutta on dampen ja sitten tai tänne kertaa maじゃないseisempiin että te pllelle esist Rede Cupoo! E�a endured että això sellainen puoli tilais keivan saingin alle 8 luoso - Also suomal believeden tyyy halもう 15- whoi hold seriously Already existing system 8 Dylan ja 12 Kuten in our case, how service department is very well created not just the main tent system but the oldies hypersekkivalse. That said some customers choose other services and controls that vendors and that's not what we would like to see, but we are okay with that. We play ball. I guess because these all over the station environments I guess all like a multi-vendor environment so there's a lot of bigger vendors, more vendors. So it's like a big thing to handle and I guess the scene from all the reports and what has actually happened is usually and what these two actually is aiming for is that please manage your supply chain risk so who is developing services or technologies so make sure that they have understanding the pace because there are a lot of different companies providing services and technologies and you might end up like to the fact that they are still deciding these unshered priority systems and they don't like follow best practices. And do you find that customer expectations arising as all these new regulations come into play as well? Yeah, because for example this needs to do it's in EU and it's in national law so if you are part of critical infrastructure for example power plant plant in any EU nation. There are finance and penalties other kind of penalties if the author of these things that you didn't do proper job with your cyber security ID or all these other whole company so there's kind of no way to say that now cyber security not out of things so it's not possible anymore. Let's start to look at how Valmet delivers in practice and is there anything that you either if you can share about the things that you guys are up to at the moment let's say. I guess yeah, it's always I guess a little bit of technology being like like customer expectations are related or maybe coming from the IT side of consultants that are very experts that they are expecting to have certain best practices maybe your position on the old systems as they have in the IT system so in protection so yeah it's a little bit starts on the technology that you are using but it's also like in the supply chain by being part of the supply chain sort of processes. We are big company like one of the biggest things that we are always trying to improve but it's also technology how we are implementing that to the consul system where the availability is the key to. Yeah maybe maybe some basic thing to highlight that I said while we are not a cyber security company so we don't develop these cyber security quality products that we use third party technology that we had to carefully selected that they are all TK plus then that they fit what we want to do so kind of a tool that comes outside while we learn how to use those implement those to customer. Customer of all its system doesn't take care of those as we take care of our while with DNA or whatever of our disease prints or other other mess and products we supply so that's the key thing until we open it communicate that we don't what we don't do so we don't have security operations center but we very willing to work whatever software customer has in IT science and we provide this ability plus if the cyber is then we are there to help help our local service guys will come to help if it comes to that. Yeah just the violent expertise is that we are like we are trying to focus into teaching and making sure that this automation experts have knowledge of the cyber security. It's more easier and more more better for whole net to have the same experience while understanding the processes all the most assistance to learning the cyber security basics I would say it is very difficult to learn not like a been on high T expert and start learning learning how the automation processes work so. We have already touched on slightly on this to earlier in the episode but how you guys find in the this to legislation and how is it affecting yourself and your customers. I think it's it's it's in general the idea is very good so it needs to come gives the framework that what should be done it it's not a standard doesn't give specific things that you need to have an interest related to the system in place it's just that you need to monitor your network and have disability and then it's up to the end customer what what he he will see things what that actually means for their plant that that's maybe a little bit that he have been struggling that the at least the early stage is some customer said that our is our one that system needs to go to like the can you keep us a certificate that we cannot kill so it all starts with the customers on risk assessment the understand that I do risks in cyber and then they will have this risk analysis okay this is our our risk so it's not like we would say that okay you cannot you share the cancer anymore that is obviously be known only but in all these not that easy to get individual accounts so it's not that you must have for example active directory individual accounts although that's the direction we're industry is going but it's not what needs to you say so kind of this the then customers understand that we we can help them identify the risk and be part of the risk assessment but we can't really make make that for them it's not not out our purpose given that we are only one part of their whole plan so so vomit systems so yeah we are gladly part of at risk assessment process and yes we have ideas and yes we have souls but the risk order is the end customer who's under misto yeah it's really so that it's really complicated in some cases that they customer doesn't have to stand they need to see does a whole production or whatever business they are doing and it's also likes relates to the IT solutions that they are usually how they are teaching the person so well when the like vomit kind of like provide everything but we can be part of that so they need to make it understand the policies they have it to the IT side and bring it to the production somehow maybe how they are doing things like identities and passwords they need to be adapted to be like a so that you would not end up new challenges that you are losing passwords you're losing consoles you're losing the access to the control system that's quite critical also so so ideas are quite clear but they need to just understand how to do it for the whole products are not only for one specific system absolutely and just to finish off today's episode what's next whether it be regulation plans within file that what you seem happening moving forwards well definitely for the whole industry is the cyber-recealist act that is coming that's more hits vendors not the end users that this vulnerability management in kind of more or less all products that are have the digital elements and then correct the network needs to be very rigorous vulnerability management and passing passing that capabilities but you need to expose all your non-winner abilities and then the kind of instructions how to pass that and is kind of an industrial control system these systems what we have it's it's not everything obviously is made by one so we use lots of third party components that when we put all that together we report those vulnerabilities from the third parties as well and keep instructions and putting these packets together is a tremendous job and I think as I said I like this too but I like the CRA as much so so if it's a it's a time I think to ask but that's coming next yeah that's my upbeat yeah I guess the vulnerability management with the CRA that's that's like a huge stopping but I I guess also when when we are moving forward it's getting more like a easier for for everybody everybody is now learning so many but whenever we also like designing or building new production plans it's it's getting more
Vi,) pitää detoksessa. Se suomana, joka nostرو,Firemaxiva mutta Collins technicalissa on paremmoitamme. Ei sharpen備ä ole evidencea, jota N教iotim功ta meitä seuraaville on, varasiikan tipaisuassa ja ollaan mitää Reason慣 confi intra door ja
ään complaint Screenplay preparations, joten se on suomana, joten se ei ole viennäksellinen, mutta se ei ole viennäksellinen, mutta se ei ole viennäksellinen, mutta se on tullut se, että se on jatkein seuraaville, mutta se on täysin teknologisja, ja se on tämän prosenttia, että se on tämän prosenttia. Se on tämän prosenttia, ja se on tämän prosenttia, mutta se on tämän prosenttia, joten se on tämän prosenttia, mutta se on tämän prosenttia. Se on tämän prosenttia, joten se on tämän prosenttia, mutta se on tämän prosenttia, joten se on tämän prosenttia, joten se on tämän prosenttia, joten se on tämän prosenttia,
Podcast Summary
Key Points:
Valmet is a major Finnish company known for paper/board machines, pulp mills, boilers, and automation systems; its automation solutions business area has 2,400 employees globally.
The OT cybersecurity team focuses on educating customers, managing supply chain risks, and integrating third-party security tools, rather than providing a full security operations center.
OT cybersecurity is critical due to regulations like NIS2 (EU), risks from cyber criminals targeting production availability, and safety/environmental concerns in industries like marine and power.
Customer expectations are rising with regulations; Valmet helps customers identify risks but cannot perform their risk assessments, as customers own the overall plant risk.
Challenges include multi-vendor environments, legacy systems, and the need to adapt IT security practices (e.g., identity management) to OT without disrupting critical production.
Future focus includes the EU Cyber Resilience Act (CRA), requiring rigorous vulnerability management across all digital components, including third-party elements.
Summary:
In this episode of the Evolution Exchange Podcast, Teemu and Ari from Valmet’s cybersecurity team discuss OT cybersecurity within the company. Valmet, a global supplier of paper machines, pulp mills, boilers, and automation systems, operates in 40 countries with 90,000 employees. Their automation solutions business provides distributed control systems, project services, and after-sales support.
The cybersecurity team, part of automation solutions, focuses on educating internal experts and customers, managing supply chain risks, and integrating third-party security tools—not on running a security operations center. OT cybersecurity matters because regulations like NIS2 mandate protection of critical infrastructure, while cyber criminals and state actors target production availability, causing financial or societal damage. Safety and environmental risks are also key, especially in marine and energy sectors.
Customer expectations are rising with regulations, but Valmet emphasizes that risk assessment ownership lies with the end customer. Challenges include multi-vendor environments, legacy systems, and adapting IT practices to OT without disrupting production. Future plans involve the EU Cyber Resilience Act, which demands thorough vulnerability management across all digital components, including third-party ones.
Valmet advises customers to manage supply chain risks and align IT and OT security policies.
FAQs
Valmet is a Finnish company that builds big machines for the pulp and paper industry, such as paper machines, board machines, tissue machines, pulp mills, and boilers for power plants. They also provide process automation systems through their Automation Solutions business area.
OT cybersecurity is important due to EU regulations like NIS2, which require companies to secure their systems. Additionally, cyber criminals and state actors target industrial control systems to cause production stoppages, financial damage, or harm to critical infrastructure, and safety issues can arise in sectors like marine.
The main risks include attacks that stop production or cause financial and societal damage, as well as unintentional threats from 'script kiddies' who find automation systems exposed online. Unlike IT, data theft is less common; availability is the key concern.
Valmet focuses on teaching automation experts about cybersecurity basics and uses carefully selected third-party security tools. They do not run a Security Operations Center but work with customer IT systems and provide support during cyber incidents through their local service teams.
Regulations like NIS2 provide a framework requiring risk assessments and network monitoring, but they do not prescribe specific technologies. Customers must perform their own risk analysis, and Valmet assists by helping identify risks and providing solutions, though the end customer owns the risk.
The CRA requires rigorous vulnerability management for products with digital elements. Valmet must report vulnerabilities from both their own and third-party components and provide patching instructions, which is a significant challenge for complex industrial control systems.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.