<script type="application/ld+json">
{
"@context": "https://schema.org",
"@graph": [
{
"@type": "FAQPage",
"mainEntity": [
{
"@type": "Question",
"name": "How is AI changing the threat landscape for OT and industrial control systems?",
"acceptedAnswer": {
"@type": "Answer",
"text": "AI is making reconnaissance, exploit development, and attack preparation faster and cheaper. Recent government advisories have warned that threat actors are using AI to generate exploitation scripts for industrial systems such as Siemens S7 PLCs and using internet-scanning services to identify exposed targets. The underlying vulnerabilities may not be new; AI simply lowers the cost and time required to exploit existing misconfigurations and exposed systems."
}
},
{
"@type": "Question",
"name": "Why is monitoring alone not enough to protect OT networks from AI-powered attacks?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Monitoring and detection tell defenders that something is happening, but they still depend on someone responding before the attacker succeeds. In change-controlled OT environments, defenders may need approval and scheduled maintenance windows before making changes, while attackers face no such restrictions. Faster detection helps, but it does not prevent an attacker from discovering or reaching the asset in the first place."
}
},
{
"@type": "Question",
"name": "What is network cloaking in OT cybersecurity?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Network cloaking makes industrial assets undiscoverable and unreachable to unauthorized users and scanning tools. Instead of allowing an unauthenticated device to discover a PLC, HMI, or other OT system and then decide whether it can exploit it, the network requires authentication before connectivity is established. Unauthorized scans receive no useful information about the protected assets."
}
},
{
"@type": "Question",
"name": "How does microsegmentation reduce the risk of an OT cyberattack?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Microsegmentation limits communication between systems so that compromising one device does not automatically provide access to the rest of the OT environment. A compromised jump host, workstation, or remote-access system can be isolated from other industrial assets, reducing lateral movement and limiting the potential impact of an intrusion."
}
},
{
"@type": "Question",
"name": "Why is passwordless authentication important for OT security?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Passwordless, phishing-resistant authentication removes passwords as an attack vector. Credential spraying, password theft, and many phishing attacks depend on attackers obtaining reusable credentials. Eliminating passwords reduces the value of those techniques and strengthens remote access to critical OT systems."
}
},
{
"@type": "Question",
"name": "Can defensive AI solve the OT cybersecurity problem?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Defensive AI can improve analysis, detection, and response, but it does not eliminate the architectural problem of exposed and reachable assets. OT environments also operate under strict change-control requirements that can slow automated defensive actions. Defensive AI should complement preventive controls such as network cloaking, default-deny access, microsegmentation, and phishing-resistant authentication."
}
},
{
"@type": "Question",
"name": "Why should organizations address exposed OT assets now instead of waiting for better AI defenses?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Attackers are already scanning industrial environments and using AI-assisted techniques today. Organizations have a limited window to reduce exposure before these capabilities become even more accessible. Architectural controls that prevent unauthorized discovery and connectivity can be implemented now rather than waiting for future defensive AI capabilities."
}
}
]
},
{
"@type": "HowTo",
"name": "How to Reduce Exposure to AI-Assisted OT Attacks",
"description": "A seven-step approach to reducing OT attack exposure using network cloaking, authentication-before-connectivity, passwordless access, microsegmentation, default-deny policies, and layered monitoring.",
"step": [
{
"@type": "HowToStep",
"position": 1,
"name": "Identify which OT assets can currently be discovered",
"text": "Review PLCs, HMIs, engineering workstations, remote-access systems, and other industrial assets for unnecessary network or internet exposure. Pay particular attention to systems that respond to unauthenticated scans or are reachable through exposed remote-access infrastructure."
},
{
"@type": "HowToStep",
"position": 2,
"name": "Require authentication before connectivity",
"text": "Move from a model where systems respond first and authenticate later to one where users and devices must be verified before a connection is established. This prevents unauthorized scanners from collecting useful information about protected OT assets."
},
{
"@type": "HowToStep",
"position": 3,
"name": "Cloak critical and unpatchable systems",
"text": "Place legacy PLCs, controllers, and other difficult-to-patch assets behind a network-cloaking layer. The goal is to prevent unauthorized users and automated reconnaissance tools from discovering the systems they would otherwise attempt to exploit."
},
{
"@type": "HowToStep",
"position": 4,
"name": "Eliminate reusable passwords from OT access",
"text": "Use passwordless, phishing-resistant authentication for operators, administrators, vendors, and remote users. Removing reusable credentials reduces exposure to credential spraying, password theft, and AI-assisted phishing campaigns."
},
{
"@type": "HowToStep",
"position": 5,
"name": "Microsegment the OT environment",
"text": "Separate critical devices, systems, and operational zones so that access to one resource does not automatically provide access to others. Apply least-privilege policies that permit only the specific communications required for operations."
},
{
"@type": "HowToStep",
"position": 6,
"name": "Use default-deny policies with logging",
"text": "Block communication that has not been explicitly authorized and record denied connection attempts. This helps protect assets that may have been missed in inventories while also giving security teams visibility into attempted unauthorized communications."
},
{
"@type": "HowToStep",
"position": 7,
"name": "Keep monitoring and AI defenses as additional layers",
"text": "Continue using asset inventory, monitoring, detection, and emerging defensive AI tools. Treat them as part of a layered security strategy rather than substitutes for architectural controls that prevent attackers from discovering, reaching, or moving between OT assets."
}
]
}
]
}
</script>
On August 19, the NSA, CISA, the FBI, the Department of Energy and the EPA signed the same piece of paper. Advisory AA26-231a. Five agencies do not co-sign often, so read what they actually said.
Threat actors are using AI to generate exploitation scripts for Siemens S7 programmable logic controllers. They are disguising those scripts as legitimate monitoring tools. And they are using internet scanning services to find the systems to point them at. Water, food, energy, chemical, manufacturing, commercial facilities. Siemens noted that the advisory describes new techniques for exploiting misconfigurations, not new vulnerabilities in its products.
That last part is the whole story. Nothing new was discovered. Something old just got cheap.
Waterfall's 2026 OT Cyber Threat Report counted 57 OT breaches in 2025 that met its criteria of confirmed physical consequences, down 25 percent from 76. Read only that, and you would conclude last year got better.
Dragos, in its 2026 OT Cybersecurity Year in Review, counted 119 ransomware groups impacting 3,300 industrial organizations in 2025, a 49 percent increase from 80 groups in 2024, with manufacturing taking more than two thirds of the victims.
Both are right. They count different things. One counts the times a plant physically stopped. The other counts the times somebody got in.
Now compare a more recent 2026 number to these. In July alone, CISA observed more than 100 internet-exposed water systems hit across at least a dozen states. One month, one sector, one campaign, and a bigger number than the entire global census of physical-consequence breaches for all of last year.
The words carrying that sentence are internet-exposed. That was not a list of the most important water systems in America. It was a list of the ones that answered. And it was a fraction of those that are vulnerable.
You have heard it at every conference this year, and it deserves its due. The people saying it are not wrong.
Defensive AI is real, it is funded, and it is coming. OpenAI committed a billion dollars on September 3 to subsidize access for frontline defenders, naming water and wastewater utilities and grid operators as priority sectors, over roughly six months. That is real help arriving for the operators who need it most, and I hope every one of them takes it.
However, there is an assumption embedded in "fight AI with AI." It takes for granted that both sides get to pull the trigger at will.
Waterfall's researchers put it better than I can, so I will use their words: engineering teams are legitimately unwilling to deploy automatic intrusion prevention in change-controlled environments, while autonomous AI attacks "have no such compunctions." Your defensive AI has to file a change request. Theirs does not.
So run the sentence the other direction. In an OT environment, defensive AI does not arrive as a better guard. It arrives as a faster alarm in a building where you are not permitted to install sprinklers. And it arrives in about six months, into a plant that got scanned in July.
I trained as a chemical engineer, so the framework I reach for is the hierarchy of controls, which every process safety engineer on your site knows by heart. Elimination first. Then substitution. Then engineering controls. Then administrative controls. Personal protective equipment comes last because it depends on a human doing the right thing under pressure.
Detection and monitoring are administrative controls. They tell a person something is wrong and rely on that person acting in time.
So price the "in time" part. CrowdStrike's 2026 Global Threat Report puts average eCrime breakout at 29 minutes, 65 percent faster year over year. It found 82 percent of detections in 2025 were malware-free, up from 51 percent in 2020, meaning the adversary increasingly arrives holding valid credentials and using your own built-in tools. And it found 40 percent of vulnerabilities exploited by China-nexus adversaries targeted edge devices lacking comprehensive monitoring.
Nobody would accept a process safety case that put PPE at the top of the stack. We accept it in OT security every day and call it a strategy.
Sharper AI makes that alarm faster and smarter. It does not make it an engineering control and it does not shorten your change window. Schneider disclosed a CVSS 9.2 authentication flaw in Modicon M580 Safety controllers on September 8. There is no AI that patches that for you this month.
Every vector in AA26-231a, the July water campaign, and the recon step in every AI-assisted intrusion published this year share one prerequisite. The attacker has to find the asset and reach it. Booz Allen's September testing found that about two-thirds of the frontier models it tested could gain initial access to a defended network without any credentials. Not one of them can connect to something that will not answer.
That step is the only one AI has not made cheaper, because it is not a compute problem. It is an architecture problem, and it is the one thing on this list you can change without an AI budget, a data science team, or a scheduled outage.
That is what BlastShield does, and it is why we built it that way instead of building another sensor. It runs today across more than 5,000 industrial sites in 22 countries and more than 600 million device-hours of production operation, most of it deployed in front of equipment that will never be patched again.
This does not solve everything. An authorized insider is still an authorized insider. Cloaking does not fix your vendor's firmware or your operator's judgment. You still need inventory, you still need monitoring, and you should take the subsidized AI when it shows up.
And the doom version of this argument is overstated. Booz Allen's own testing found every frontier API model it tried scored zero against real-world vulnerabilities that had not been deliberately seeded. Benchmark capability still outpaces live exploitation. There is a window.
That is the actual point. The window is real, which is exactly why this is a decision for this quarter and not a panic. Waiting is a choice, and the people scanning your PLCs have already made theirs.
If you think I have this wrong, come tell me why. I would rather be argued with than agreed with. And if you run a water system, or a plant, or a substation, and you are looking at a list of assets you will never be allowed to patch, that is a conversation I will always make time for.
— Tom Sego, CEO, BlastWave
AI is making reconnaissance, exploit development, and attack preparation faster and cheaper. Recent government advisories have warned that threat actors are using AI to generate exploitation scripts for industrial systems such as Siemens S7 PLCs and using internet-scanning services to identify exposed targets. The underlying vulnerabilities may not be new; AI simply lowers the cost and time required to exploit existing misconfigurations and exposed systems.
Monitoring and detection tell defenders that something is happening, but they still depend on someone responding before the attacker succeeds. In change-controlled OT environments, defenders may need approval and scheduled maintenance windows before making changes, while attackers face no such restrictions. Faster detection helps, but it does not prevent an attacker from discovering or reaching the asset in the first place.
Network cloaking makes industrial assets undiscoverable and unreachable to unauthorized users and scanning tools. Instead of allowing an unauthenticated device to discover a PLC, HMI, or other OT system and then decide whether it can exploit it, the network requires authentication before connectivity is established. Unauthorized scans receive no useful information about the protected assets.
Microsegmentation limits communication between systems so that compromising one device does not automatically provide access to the rest of the OT environment. A compromised jump host, workstation, or remote-access system can be isolated from other industrial assets, reducing lateral movement and limiting the potential impact of an intrusion.
Passwordless, phishing-resistant authentication removes passwords as an attack vector. Credential spraying, password theft, and many phishing attacks depend on attackers obtaining reusable credentials. Eliminating passwords reduces the value of those techniques and strengthens remote access to critical OT systems.
Defensive AI can improve analysis, detection, and response, but it does not eliminate the architectural problem of exposed and reachable assets. OT environments also operate under strict change-control requirements that can slow automated defensive actions. Defensive AI should complement preventive controls such as network cloaking, default-deny access, microsegmentation, and phishing-resistant authentication.
Attackers are already scanning industrial environments and using AI-assisted techniques today. The blog argues that organizations have a limited window to reduce exposure before these capabilities become even more accessible. Architectural controls that prevent unauthorized discovery and connectivity can be implemented now rather than waiting for future defensive AI capabilities.
Review PLCs, HMIs, engineering workstations, remote-access systems, and other industrial assets for unnecessary network or internet exposure. Pay particular attention to systems that respond to unauthenticated scans or are reachable through exposed remote-access infrastructure.
Move from a model where systems respond first and authenticate later to one where users and devices must be verified before a connection is established. This prevents unauthorized scanners from collecting useful information about protected OT assets.
Place legacy PLCs, controllers, and other difficult-to-patch assets behind a network-cloaking layer. The goal is to prevent unauthorized users and automated reconnaissance tools from discovering the systems they would otherwise attempt to exploit.
Use passwordless, phishing-resistant authentication for operators, administrators, vendors, and remote users. Removing reusable credentials reduces exposure to credential spraying, password theft, and AI-assisted phishing campaigns.
Separate critical devices, systems, and operational zones so that access to one resource does not automatically provide access to others. Apply least-privilege policies that permit only the specific communications required for operations.
Block communication that has not been explicitly authorized and record denied connection attempts. This helps protect assets that may have been missed in inventories while also giving security teams visibility into attempted unauthorized communications.
Continue using asset inventory, monitoring, detection, and emerging defensive AI tools. Treat them as part of a layered security strategy rather than substitutes for architectural controls that prevent attackers from discovering, reaching, or moving between OT assets.
Jaguar Land Rover’s cyberattack shut production for five weeks. The lesson: limit blast radius with network cloaking, segmentation, and verified access to OT.
Explore the complete analysis of 23 OT attacks that defeated firewalls, VPNs, and air gaps.
