case study

How Ahlstrom secured their OT environment with security awareness and phishing training

Client logo
About

Ahlstrom is the global leader in fiber-based specialty materials. Sustainability, innovation, and quality are central in all their solutions such as compostable food and beverage processing and packaging materials, liquid and air filtration media, diagnostic materials, and protective medical fabrics.

Employees: 7,000

Industry: Manufacturing

Headquarters: Helsinki, Finland

Challenge

Cybersecurity is particularly important to global manufacturing companies like Ahlstrom, where data breaches that disrupt the operational technology (OT) environment can be financially and operationally catastrophic.

Solution

Creating measurable phishing and cybersecurity skills amongst blue and white collar workers alike, Hoxhunt helped Ahlstrom secure the OT environment and ensure uninterrupted operations for their customers.

Key takeaways:
Featured image

"Phishing is a relevant threat to OT environments, since it can be the first step where threat actors gain access to the OT environment.  The consequences could be of course devastating...With Hoxhunt, we have a constantly developing service that requires low-maintenance efforts from the internal team. In cybersecurity, we don’t normally get positive feedback from our end users. However, Hoxhunt is an exception to the rule. It’s much cheaper to prevent a cyber attack than to clean up the mess afterwards." -- Antti Palokangas, CISO of Ahlstrom

"Hoxhunt is a part of our training and is in the whole organization. Through experience, and especially through the failures we make in training, it gives a good possibility to discuss why we moved forward with a link. It’s discussed not only between white collars, but also with blue collars. Hoxhunt enables this journey by challenging us as individuals and as a team to be alert to the risk." -- Mads Kiilerich, Plant Manager of Ahlstrom

Transcript

Mads Kiilerich, Plant Manager of Ahlstrom: Potentialcyber attacks can also enter into the operation system, so we need to grow theawareness even more on operation technology because that is where they’rereally high financial risks are for the company. My name is Mads Kiilerich. Iam the plant manager at the Tampere plant in Finland.

Antti Palokangas, CISO of Ahlstrom: Ahlstrom operates across the globe in 13 different countries. We have about 7000 employees globally.

Mads Kiilerich, Plant Manager of Ahlstrom: Here in Tampere, we are making paper or media for filtration. Of top importance for us is that we serve our customers and we deliver on time, so their production is not influenced by ours.

Antti Palokangas, CISO of Ahlstrom: Cybersecurity is, of course, crucial for Ahlstrom.

Mads Kiilerich: For me, it is to secure that our production IT is working as intended all the time.

Antti Palokangas: Phishing is a relevant threat to OT environments, since it can be the first step where threat actors gain access to the OT environment.  Consequences could be of course devastating.

Mads Kiilerich: In the worst case, it will ruin our production equipment. It will ruin our data structure.

Antti Palokangas: If such things would happen to us, of course, we would be in a crisis mode for a long time.

Mads Kiilerich: Awareness is hugely important. For me, this is like with safety, we have the physical safety, we have the process of software safety, but in the end, when those fail, then we are back to the behavior of people and their awareness and understanding of the risk.

Antti Palokangas: Ahlstrom has been using Hoxhunt for five years now. Hoxhunt is a good service because it offers regular training to our users so that they remain cautious all the time.

Mads Kiilerich: Hoxhunt is a part of our training and in the whole organization. Through the experience and especially the failures we make, it gives a good possibility to discuss why did we move forward with a link. It’s discussed not only between white collars, but also with blue collars. Hoxhunt enables this journey by challenging us as individuals and as a team to be alert to the risk.

Antti Palokangas: We can see the benefits of Hoxhunt, clearly from these statistics. As our users take more and more simulations, the failure rate keeps decreasing, even if they faced tougher simulations.

Mads Kiilerich: It keeps challenging me and my awareness of cyber security.

Antti Palokangas: The threat landscape keeps changing as cyber criminals look for new ways to scam the victims. With Hoxhunt, we have a constantly developing service that requires low-maintenance efforts from the internal team. At cyber security, we don’t normally get positive feedback from our end users. However, Hoxhunt is an exception to the rule. It’s much cheaper to prevent a cyber attack than to clean up the mess afterwards.

Want to match these results?
Hoxhunt adaptive phishing training dramatically increases training engagement and security resilience.
Request a demo