Palo Alto Networks and Siemens today announced a partnership that combines the security vendor’s VM-Series firewalls with Siemens’ Ruggedcom networking and security appliances.

“This allows companies to protect their industrial control systems and other key infrastructure without compromising on security, performance, or the ability to scale,” said Anand Oswal, SVP of network security for Palo Alto Networks. The partnership also allows customers to “extend security policy from IT, to critical OT [operational technology], to industrial control systems,” he added.

Under the agreement, Siemens will sell its Ruggedcom networking and security platforms with Palo Alto Networks’ VM-Series firewalls built in. These Ruggedcom platforms are small, ruggedized appliances built for industrial customers in harsh, mission-critical environments. They can also host third-party cybersecurity applications, like Palo Alto Networks’ firewalls.

Meanwhile, Palo Alto Networks’s VM-Series firewalls serve as a perimeter gateway and secure all traffic including encrypted traffic. They use segmentation and policies that the security vendor says allow operators to control applications communicating across different subnets to block lateral threat movement and achieve regulatory compliance. The Ruggedcom appliances can also be deployed to provide application-level monitoring for control centers running SCADA systems.

Additionally, centralized management allows customers to extend security to industrial systems wherever Siemens Ruggedcom RX1500 Multi- Service Platforms are deployed.

Critical Infrastructure Security Reaches Critical Mass

Despite everyone, including U.S. President Joe Biden, talking about the need for zero-trust infrastructure and the importance of securing critical infrastructure, “attacks are increasing at an exponential rate,” Oswal said. “And they are expanding too quickly to critical infrastructure.”

Additionally, as legacy systems running in OT networks and critical-infrastructure environments become digitized and connected, they can exposure previously unknown vulnerabilities, Oswal added. “They require a really robust and resilient security stack to identify them and protect against these vulnerabilities.

And third, securing OT and industrial control systems requires an integrated approach, he said. “A really robust security solution that is deeply embedded and not super complex,” Oswal explained. “We want to make sure that we have the deep integrations and provide visibility, but also all the level of controls that are needed for the systems.”

Palo Alto Networks’ partnership with Siemens comes about a week after OT security company Dragos closed a $200 million funding round on a $1.7 billion valuation, highlighting the growing importance of OT and critical infrastructure cybersecurity — and the heightened awareness of threats against these systems.

As this market becomes more attractive to IT security vendors, many of them including Microsoft, Forscout, and Cisco have acquired OT and IoT security startups in a push to move into industrial security.

Can Palo Alto Networks Extend Its OT Security Reach?

While Dragos’ CEO says this approach won’t work, because IT enterprise security companies don’t understand industrial and critical infrastructure systems, Oswal argues partnering with Siemens gives Palo Alto Networks an in across these industries including electric, oil and gas, chemical, pharmaceutical, water, and manufacturing.

“Siemens has a broad reach across many of these verticals,” Oswal said. “And they’re looking for the best-of-breed security solution that can integrate seamlessly.”

Plus, Palo Alto Networks isn’t taking its enterprise IT security product and sticking it in an OT environment, he said. The platform includes specific capabilities for OT environments: “the new protocols that we need to understand, the applications that we need to identify, so we can have the right level of visibility and granular control for these customers.”