Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
AI Won't Breach Your OT. Complacency Will.Incident & Breach Response
4 min readFor CISOs

AI Won't Breach Your OT. Complacency Will.

Organizations are being told to urgently deploy AI-powered defense tools to counter AI-assisted attacks against operational technology (OT). Security briefings often highlight how threat actors use large language models to generate exploits. The natural response seems to be to fight AI with AI.

Why We Disagree

This perspective misses the core issue. The Siemens PLC campaign flagged by CISA isn't dangerous because attackers are using AI. It's dangerous because organizations are running internet-exposed programmable logic controllers with outdated software.

Here's what happened: Threat actors used publicly available large language models like Mythos and Fable to script exploits against known vulnerabilities. They combined these scripts with open-source industrial automation libraries to create tools disguised as legitimate monitoring solutions. This isn't sophisticated. It's automation of reconnaissance and exploit development that skilled attackers have been doing manually for years.

The AI component lowered the skill barrier and increased the speed, but it didn't create new vulnerabilities or bypass hardened systems. The advisory explicitly states that attackers were "using internet scanning services to find internet-exposed PLCs running outdated software or that are otherwise poorly protected."

You don't need AI defense tools to fix that. You need to stop leaving your control systems accessible from the internet.

The Evidence

CISA's advisory describes "persistent reconnaissance in targeted facilities to develop capabilities and prepare to cause operational effects." This is pre-positioning. Attackers are mapping networks and identifying targets in critical sectors like manufacturing, energy, and water.

The advisory also reveals that threat actors used internet scanning services to find vulnerable targets. They didn't breach air-gapped networks or exploit zero-days in hardened systems. They scanned the internet for exposed devices and found them.

Consider the campaign against water utilities that struck dozens of facilities across at least 12 states. Those attacks also targeted PLCs, including Siemens S7 series models, along with devices from Rockwell Automation and Schneider Electric. The common thread isn't AI sophistication; it's fundamental security hygiene failures.

The ANSI/ISA-62443 standard addresses network segmentation and zone isolation. Section 4-2 requires that control systems be separated from enterprise networks and the internet through properly configured security zones. Most targets in these campaigns would have been unreachable if organizations had implemented basic ISA-62443 controls.

What to Do Instead

First, inventory your OT assets and identify anything with internet connectivity. If you're running a water treatment plant, chemical facility, or manufacturing operation, your PLCs should not be directly accessible from the internet. Exceptions are specific remote access scenarios requiring jump hosts, multi-factor authentication, and session monitoring.

Second, implement proper network segmentation according to ANSI/ISA-62443 zone and conduit models. Your OT network should be isolated from your IT network with industrial demilitarized zones and unidirectional gateways where appropriate. This isn't new guidance. ISA-62443 has been around since 2007, and NIST SP 800-82 has provided OT security guidance since 2011.

Third, patch your systems. The advisory notes that attackers targeted PLCs "running outdated software." If you're managing critical infrastructure with unpatched controllers, you don't have an AI problem. You have a change management problem. Yes, OT patching is complex. Yes, you need maintenance windows and testing. But if your patch cycle is measured in years instead of months, you're creating the attack surface that AI tools are now efficiently exploiting.

Fourth, implement proper monitoring and anomaly detection for your OT environment. The attackers in this campaign disguised their tools as legitimate monitoring solutions. That works when organizations don't have baseline behavior profiles for their control systems. If you understand normal PLC communication patterns, unauthorized scanning and script execution become visible.

Finally, review your vendor security practices. The NIST Cybersecurity Framework (CSF) 2.0 includes guidance on supply chain risk management in the Govern function. If you're deploying PLCs without understanding their default configurations, remote access capabilities, and update mechanisms, you're trusting vendors to secure systems that control physical processes.

When the Conventional Wisdom IS Right

There's one scenario where the AI-defense narrative has merit: when you've already implemented foundational controls and need to detect novel attack patterns at scale.

If your OT environment is properly segmented, your assets are inventoried and patched, your network traffic is baselined, and you're still seeing sophisticated reconnaissance that evades signature-based detection, then machine learning models trained on OT-specific behaviors can help identify anomalies.

But that's step five, not step one. The organizations getting compromised in these campaigns haven't reached step five. They're stuck on step zero: basic asset visibility and network hygiene.

The other valid use case is threat intelligence enrichment. AI tools can help security teams process the volume of vulnerability disclosures, proof-of-concept exploits, and threat actor techniques that now flood public repositories. If you're a CISO managing OT security across multiple facilities, using AI to prioritize which threats actually apply to your specific PLC models and configurations is reasonable.

Just don't confuse intelligence processing with defense. The best threat intelligence in the world won't protect an internet-exposed PLC running firmware from 2019.


The real threshold we're crossing isn't AI-assisted attacks. It's the end of security through obscurity in operational technology. For decades, OT systems were protected partly by the specialized knowledge required to exploit them. AI hasn't made those systems more vulnerable. It's made that specialized knowledge more accessible.

Your response shouldn't be to deploy AI defenses. It should be to implement the controls that make that specialized knowledge irrelevant. Segment your networks. Patch your systems. Monitor your environment. These aren't exciting recommendations, but they're the ones that would have prevented the campaigns CISA is warning about.

The attackers are using AI to scale across the skills gap. You need to close the implementation gap.

Green background, the words "The Biggest AI Security Risk Isn’t the Model. It’s the Agent." A robot drawing. A button for "Get the Free Guide."

You Might Also Like