AI & TechnologyCyber Security

The next phase of AI must prioritise critical infrastructure security

By Moreno Carullo, Co-founder and Chief Technical Officer, Nozomi Networks

Recent advances in AI-enabled vulnerability discovery, such as OpenAI’s GPT-5.5 and Anthropic’s Mythos, are a genuine inflection point for cybersecurity. Industry testing suggests these systems are increasingly able to reproduce vulnerabilities, identify flaws and reason through complex software environments at significant scale.

For defenders, that creates an opportunity to find and fix weaknesses faster. But for attackers, it can make it easier to find exploitable flaws. This dual-use reality means the industry needs to move carefully.

However, it also presents an even more dangerous problem when it comes to critical infrastructure security and operational technology (OT) environments. The systems that run power grids, water treatment facilities, manufacturing plants and energy pipelines operate with unique hardware, proprietary protocols, operational constraints and physical consequences. If AI enabled cybersecurity is to improve critical infrastructure resilience, OT expertise must be built in from the start.

What makes OT environments different from IT

Enterprise IT environments are built around systems that can often be updated, rebooted or replaced with relative speed. That does not mean patching is easy, but the process is usually familiar and fast: vulnerabilities are identified, patches are tested, updates are deployed and systems are monitored.

In OT environments, it’s much more complicated. A vulnerability in a programmable logic controller, SCADA system or safety instrumented system cannot always be addressed with a simple patch. Applying an update may require a planned outage, production downtime or coordination with engineering and safety teams, causing potential, major disruption to operations.

The underlying technologies between OT and IT are also different. Industrial environments rely on specialised hardware, legacy systems, proprietary firmware and protocols. Many of these were designed before today’s security assumptions existed and are often customised in the field.

This means that vulnerability discovery in OT is a much more technical analysis of software. It requires understanding what the asset does, how it interacts with physical processes, what safety implications exist and what remediation is possible without introducing new risk.

The consequences are physical, not just digital

The distinction is practical as much as technical. In IT, a crash may mean rebooting a server or restoring lost data. In OT, a failure can mean a turbine, pump, production line or safety system behaving unpredictably in the physical world. It is the difference between standard enterprise software and firmware running on a PLC, often using industrial protocols such as Modbus, DNP3, EtherNet/IP or IEC 61850 that predate the modern security era.

This is why context matters so much. A vulnerability that looks severe in a standard IT scoring model may not be exploitable in a specific industrial environment because of segmentation, compensating controls or process design. Equally, a flaw that appears narrow on paper may carry serious operational risk if it affects a safety critical asset.

The question is not simply whether a vulnerability exists. It is what that vulnerability could enable, what systems it could affect, how likely exploitation is and what action can be taken safely.

The dual-use risk is urgent

Any tool that industrialises vulnerability discovery benefits both defenders and attackers. That is the central challenge facing the cybersecurity industry now. The same capability that helps defenders find weaknesses faster can also help attackers identify new paths into critical systems.

This is especially concerning for industrial environments. Many OT systems were not designed for a world where AI can rapidly reason through code, protocols and configurations. Some remain difficult to patch, difficult to replace and deeply embedded in essential operations.

Defenders who have access to AI-enabled tools, and the expertise to interpret their outputs, will be better placed to act before attackers do. Defenders without access to equivalent capabilities, or those using tools that are not calibrated for OT environments, risk being left behind.

That imbalance matters. If attackers can use AI to accelerate vulnerability discovery in industrial systems while defenders lack the right tools, context and expertise, the gap between discovery and resolution could become increasingly bigger and much more dangerous.

OT expertise must be included from the start

While emerging, defensive AI initiatives are a welcome development in the industry, they must not remain centred only on traditional IT environments.

Operating systems, browsers, cloud platforms and open-source software are logical starting points, and the IT security community already has mature tooling, established disclosure processes and the operational flexibility to respond quickly to many vulnerability findings.

OT and critical infrastructure are different and require OT security experts, industrial engineers, critical infrastructure operators and practitioners who understand the constraints of these environments. Their involvement is essential if AI-enabled vulnerability discovery is going to be safe, useful and actionable for critical infrastructure.

The next step for AI security

AI-powered vulnerability discovery represents a major opportunity to improve the security posture of critical infrastructure. It could help defenders surface risks earlier, prioritise more effectively and close gaps before attackers exploit them.

But that opportunity will only be realised if OT environments are included in the design of these tools and initiatives. Critical infrastructure cannot be treated as an afterthought, and OT security expertise cannot be added at the end. 

AI has taken a major step forward. The next challenge is making sure that progress protects the systems society depends on most.

Related Articles

Back to top button