Events
,
Governance & Risk Management
,
Nullcon
Merck’s Luis Contasti Aguirre on Building Resilient OT Security Programs
Operational technology environments contain legacy systems, insecure protocols and complex global networks. Without visibility into assets, companies face gaps that attackers can exploit, leading to production risks and regulatory compliance challenges. Asset awareness is the first step toward securing critical operations, said Luis Contasti Aguirre, global OT security lead at pharmaceutical manufacturer Merck.
See Also: AI, Zero Trust and SASE: Modernizing Security
Technology improves defenses, but it only succeeds when organizations build a cyber risk culture that prioritizes awareness, hygiene and collaboration with OT teams to validate anomalies and reduce false positives, he said.
“Security is risk mitigation. You can operate in a safe environment. And I know that budget is not infinite,” Aguirre said. “We have restrictions, but we can’t lower the security or try to balance security instead of IT. You will have really good IT or really good machinery, but it could be not usable, because you don’t have the right measures.”
In this video interview with Information Security Media Group at Nullcon Berlin 2025, Aguirre also discussed:
- Using standards such as ISO 6443 or new CISA guidelines to manage assets in the environment based on taxonomy;
- How people, process and culture shape effective OT security;
- Best practices for incident response and reducing false positives.
Aguirre has more than 15 years of cybersecurity experience. He leads initiatives across IT and OT, focusing on threat management, security governance and cloud protection. He has worked across Europe and Latin America for firms in energy, pharma, telecom and finance.