마이크로칩 8월
This page was machine-translated and may differ from the original. View original

[Interview] Park Ji-yong, Branch Manager of Nozomi Networks, "Korea entering full-scale OT security adoption phase"

Google 우선 소스Published2026.08.18 12:39

"Korea entering full-scale OT security adoption phase"


Arc-Embedded embeds security functions directly into PLCs to reduce blind spots

Vantage IQ shifts from alarm-centric to decision-centric, enabling advanced analysis


[Editor's Note] The domestic OT security market has seen significantly heightened awareness centered on large enterprises, and POC demand is also increasing. In particular, OT security diagnostics are essential for enterprises to identify vulnerabilities without productivity degradation, and demand is growing across hospitals, pharmaceuticals, power generation, and manufacturing sectors. In this context, Nozomi Networks' Arc-Embedded, which embeds security functions directly into PLCs to reduce blind spots, and Vantage IQ, which shifts from alarm-centric to decision-centric operations enabling non-specialists to perform advanced analysis, are receiving spotlight as key safety assets in OT security. Accordingly, we met with Park Ji-yong, Branch Manager of Nozomi Networks, to discuss OT security and Nozomi Networks' solutions.


Park Ji-yong, Branch Manager of Nozomi Networks

■ Recently, digital transformation in manufacturing and industrial infrastructure is progressing rapidly. Compared to the past, what is the most significant change in the domestic OT security market, and to what level has enterprises' security awareness risen?


Nozomi Networks has been conducting business in Korea for exactly five years as of this month.


The first three years were quite challenging.


The term "OT security" itself was unfamiliar, and most people did not know the company name Nozomi Networks.


During this time, I worked hard with partner companies to imprint the importance of OT security and the brand image of Nozomi Networks in the minds of security managers.


Whether as a result or not, it now seems that everyone in the domestic security industry has heard the names "OT security" and "Nozomi Networks" at least once, and it has become a name that OT security managers universally recognize.


Compared to when Nozomi first entered the Korean market, the major difference is that CIOs and CISOs now recognize the necessity of OT security.


In the past, the most common question was why OT security was necessary when IT security was already well implemented and systems were air-gapped. However, now for large enterprises, OT security is recognized as a necessary solution, and the number of companies and organizations considering adoption is increasing significantly.


Since the end of last year, there have been many requests for POC (proof of concept) testing on OT security.


On the other hand, large enterprises with large-scale production facilities and relatively large security budgets are prioritizing preparations for OT security adoption. However, small and medium-sized enterprises still lack awareness, understanding of necessity, and budget consideration for OT security.


Compared to advanced nations globally, Korea's start in OT security lags significantly, and government regulations are also inadequate for OT security.


The figure below shows a graph depicting the growth stages of OT security.


Most small and medium-sized enterprises in Korea are in the "happy ignorance" stage.


Most have not yet become aware of OT security vulnerabilities.


Even large enterprises preparing for OT security are currently considering only OT asset visibility, with about 60% adopting solutions at this level.


Only approximately 10% of global enterprises are implementing ultimate risk management for OT security.




Nevertheless, the most significant change is that most large enterprises now recognize the meaning and importance of OT security, and most are considering adoption within the next 2-3 years.


■ Nozomi Networks emphasizes Arc-Embedded technology that directly embeds security functions within PLCs. Compared to conventional network-based OT security approaches, what is the most significant differentiator that field customers experience?


OT security architecture commonly uses the Purdue model as shown below.


Levels 0 through 3.5 are typically referred to as OT networks or OT domains.


Traditional OT security appliances are usually installed at level 3.5 or level 2.


They aggregate traffic through mirroring on network switches and monitor OT traffic in the sections above and below.


This results in blind spots in environments where network switches cannot be used or at the lowest levels such as levels 0 and 1, where aggregation or installation cannot be performed.


In contrast, Arc-Embedded does not require switch mirroring. Instead, OT security sensors are installed as modular components directly into PLCs or RTUs installed at level 1, making the PLC itself function as an OT security sensor, enabling direct collection and analysis of traffic information around the PLC.


This approach is significantly differentiated from conventional OT security information collection methods.


There is no need to install separate OT security information collection/analysis equipment; the PLC itself performs that role, reducing spatial constraints and architectural blind spots.


In simple terms, it is a structure where a finer mesh is cast deeper, allowing capture of both small and large fish.






■ You mentioned that the AI-based security analytics platform Vantage IQ enables a transition from "alert-centric" to "decision-centric" approaches. How is AI actually transforming the work of security managers in industrial settings, and what roles do you envision it will take on in the future?


Most OT security solutions display numerous alert messages after installation, making it difficult for security managers to individually analyze this content and compile only meaningful information.


Professional technicians create complex queries and perform manual analysis, which takes considerable time. However, there are limits to generating meaningful analysis results relative to the effort invested, and re-editing aggregated data for reporting also requires significant time and effort.


Consequently, many steps and effort are necessary before decision-making.


As a result, OT security management had to rely on simple asset visualization and threat detection rather than serving decision-making purposes.


Nozomi Networks' AI-based assistant solution, Vantage IQ, has transformed OT security into a deeper-level analysis and decision-support solution.


In the OT security journey graph shown earlier, you can think of it as opening a path to the top 10% level.


Through Vantage IQ, more diverse and in-depth query and response interactions become possible, and AI can automatically perform planning and reporting tasks that previously relied on manual work.


Tasks that previously required multiple managers over extended periods can now be handled quickly and accurately by a single person, delivering results in an excellent report format. OT security analysis and operational management can be conducted as if conversing with an expert.


Korea currently faces an absolute shortage of OT security solution specialists and analysts.


Many cases exist where solution adoption is hindered due to inability to secure OT security operational staff. Nozomi's Vantage IQ addresses these customer challenges, enabling even non-specialists to use OT security solutions easily.


Additionally, it enables rapid processing of diverse and complex questions from various departments, providing advantages such as improved operational productivity and enhanced analytical capabilities.


■ In smart factories and industrial settings, maintaining productivity is important, but operations often cannot be halted for security. What do you believe companies should primarily check first to balance between security and productivity?


This is the most significant difference between IT security and OT security.


To maintain production facility availability, appropriate software version management and equipment upgrades are often not performed, and facilities are operated for extended periods. Consequently, numerous OT security vulnerabilities inevitably arise, and operations must continue in a state vulnerable to cyber attacks.


To identify these vulnerabilities and establish improvement plans, enterprises must first conduct OT domain diagnostics.


OT security diagnostics (POC) are performed using OT security solutions that do not impact availability. Based on diagnostic result reports, latent vulnerabilities, areas requiring priority consideration, and future improvement plans can be established.


It is equivalent to receiving regular health checkups as we do.


There is a significant difference between operating facilities with prior awareness of threats and vulnerabilities and operating without any such information.


Anticipated threats can be defended against.


■ You mentioned that domestic business is growing as you enter your fifth year in Korea. What industry sectors or use cases are domestic customers most interested in, and what strategy does Nozomi Networks intend to focus on in the Korean market going forward?


Recently, the industry sectors receiving the most interest and inquiries from us are hospitals, pharmaceuticals, power generation facilities, manufacturing, and shipbuilding/maritime sectors.


Potential growth industry sectors include data centers, defense, port and airport infrastructure, railways, robotics, and logistics industries.


Nozomi Networks will continue emphasizing the necessity of OT security solutions and expanding customer cases.


By establishing a large-scale demo center, anyone can easily experience OT security solutions operating in actual equipment without concerns about operational issues.


We will work to create OT security operational systems that anyone in Korea can conveniently use.


We will expand the educational environment so that customers and partner companies can obtain OT security certifications.


(Left) Branch Manager Park Ji-yong and Director Jang Jae-an of Nozomi Networks are taking a commemorative photo at the 20th International Security Conference (ISEC 2026).


An OT security solution demo unit is demonstrating an alert when detecting an attack.



■ Finally, please share some closing remarks with our readers.


OT security incidents can result in significantly greater economic and human damage compared to IT security incidents.


OT security regulations are also being strengthened by industry and region, and Korean companies operating globally must consider how to respond to these regulations.


I urge each customer to definitely conduct OT security diagnostic testing to ensure there are no issues with their facilities.


Meanwhile, Director Jang Jae-an of Nozomi Networks is scheduled to present on "New Direction of Data Center OT Infrastructure Security in the Physical AI Era" at the 'e4ds Tech Day 2026' event on September 8.


Registration for 'e4ds Tech Day 2026' can be completed by clicking the banner below.




본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
배종인 기자
배종인 기자