What AI Actually Changes for OT Security: Observations from the Field

Table of Contents

For years, Dragos declined to put AI on a conference booth. The use cases were not real yet, not for offense and not for defense, and the company was not seeing it in the field one way or the other. That has changed. This is a field view of what AI actually changes for OT security: where the threat is real, where it is hype, and what defenders should do now. Over the last nine months, Dragos has worked first-hand with frontier AI models, watched its own red team and offensive specialists put those models to work, hardened its own products against them, and investigated incidents where adversaries were already using AI in the early stages of their operations. The view is now real, and it is grounded in what Dragos is seeing rather than what the market is speculating about.

Dragos has historically taken the wind out of the hype. The headline that a phishing email will take down the power grid was never how any of this worked, and there is no single grid to take down. So it matters when Dragos says that what it is seeing now is genuinely concerning. There is real opportunity here for defenders. There is also legitimate cause for concern. This post walks through what Dragos is seeing: how AI is changing the OT threat landscape, where the concern is real, and where it is not. Those insights come from first-hand work with frontier models, including Anthropic’s Project Glasswing, from Dragos teams using the models offensively and defensively, and from incidents where adversaries were already using AI.

OT cybersecurity has moved through distinct eras, each defined by who was attacking and what they could do. From the 1980s through 2021, adversaries in operational environments were overwhelmingly intelligence agencies. They were, for a long stretch, more curious than destructive, learning what industrial control systems were and what value there might be in reaching them. Intelligence agencies tend to prefer intelligence work: espionage, patience, watching. Destructive operations were rare because they required senior government sign-off, and because the environments themselves were hard targets. OT was heterogeneous. A refinery in one country had almost nothing in common with an electric substation or a water treatment plant somewhere else, so every attack with real physical consequence had to be expensive, specific, and slow. The result was a long era of low-frequency, high-consequence activity.

That divide broke in 2021, when the industry crossed into something more homogeneous, more digital, and more connected. Under the hood of controllers from different vendors sit common software stacks, common protocols, and cookie-cutter installations repeated site to site. That commonality is what lets an adversary model, train, and scale an attack. 2021 brought the first cross-industry, reusable framework capable of causing physical effects across multiple sectors. Once offense stopped requiring an eighteen-month classified program, militaries entered the conversation. By 2024, Dragos could assess with high confidence that state actors were arming non-state actors, handing groups that had previously defaced internet-facing interfaces the OT-specific knowledge to manipulate controller logic and physical processes. Then came AI. Twenty years of one general pattern, then militaries, then state-armed proxies, and now this, each era arriving faster than the last. That pace alone is difficult for defenders to absorb.

The picture is not the one in the headlines. Nothing Dragos sees today supports the idea that AI is going to independently reach out and bring down power plants and water systems. What Dragos does see falls into a few clear patterns.

The first is that AI lowers the barrier and points ordinary IT adversaries toward OT. In an incident earlier this year involving a breach of the Mexican government, a capable firm handled the IT response and brought Dragos in for the OT dimension. The adversary had no OT skills, no OT knowledge, and no apparent OT intent. The AI model supplied all three, unprompted. It flagged that a compromised system was an interface down to a government-owned water utility, explained why reaching that operational network was valuable, and then offered the vendors in use, the default configurations, and the default passwords, along with where to begin. That capability, delivered to the large population of adversaries who never previously cared about OT, is likely to pull far more of the IT threat landscape into operational environments. Dragos expects it to accelerate the frequency of incidents.

The second pattern is vulnerability discovery at scale. Pointed at industrial products inside Dragos control system ranges, with the right harnesses and tooling, these models found combinations of vulnerabilities that are not easy for human analysts to surface. Not a handful. Dozens of strong zero-days across major OEMs, with hundreds into the thousands of additional vulnerabilities. The community is about to be overwhelmed by sheer volume, and the answer is not to sort that volume by CVSS score. It is to ask which vulnerabilities actually matter. Dragos applies a “Now, Next, Never” model for exactly this: the roughly 20 to 30 percent that add no meaningful operational risk and belong in the Never bucket, the 60 to 70 percent worth compensating controls or a place on the list under Next, and the 3 to 6 percent that demand immediate action because they enable safety or control manipulation or are already being exploited. As AI multiplies the vulnerability count across legacy and modern equipment alike, prioritization becomes the difference between a manageable program and an impossible one. Dragos breaks down how AI-assisted vulnerability discovery works in a separate methodology post.

The same discovery capability is a gift to defenders willing to use it. Vendors and OEMs who invest the money to run these models against their own products before shipping will find their flaws before adversaries do. Many will not make that investment, and a great deal of under-tested equipment will continue to enter operational environments. The vulnerabilities that matter most are not usually the ones deep in a PLC. They are the ones closer to the perimeter of the automation environment, in the jump hosts, firewalls, and access points, where a flaw that grants access gets abused quickly. Dragos tracks a threat group that, before adopting AI, could reverse-engineer a freshly released vulnerability and build a working exploit within 24 to 48 hours. In an AI-assisted world, that window shrinks toward minutes. A day or two was already more than most organizations could keep pace with.

The third pattern is the one that should worry defenders who have stopped at prevention. Somewhere north of 90 percent of infrastructure owners and operators have adopted a prevention-only posture, and they are not wrong to have done so, because that is what the guidance told them. Dragos analysis of dozens of standards found that well north of 80 percent, in some cases as high as 98 percent, of the guidance is preventative in nature: antivirus, patching, passwords, access controls, firewalls, segmentation. Prevention remains necessary. It is no longer sufficient. As environments grow more homogeneous, more connected, and more digital, and as adversaries gain reach they never had, a control set that stops at prevention is worth less than it has ever been. Prevention always fails eventually, and when it does, organizations without detection, monitoring, and response cannot even determine whether an event was a cyberattack.

Not every adversary becomes dangerous because AI exists. Most threat groups target IT, and most are less capable than their reputation suggests. Dragos tracks roughly 27 groups that target OT specifically, and within that set, a small number, perhaps four or five, are the genuine concern. These are teams that have run OT operations for fifteen to twenty years and have almost certainly kept their data. That accumulated operational data, layered on top of a frontier model, is what turns a capable adversary into one with reach and scale the OT community has never faced.

This is the crux. Frontier models are strong starting points, but they need context to matter for OT. They need the field knowledge, the assessment history, the incident response experience that only comes from years of operational work. Dragos knows this because it built the same advantage for the defense. The Dragos Intelligence Fabric is the codification of more than a decade of OT-specific telemetry, adversary research, vulnerability analysis, and frontline incident response into a continuously updating loop that gives defenders the context to act. Bad data with a great model produces a bad outcome. Great data, great analysts, and a great model together produce results that were not previously achievable. Assessments that took two to three weeks compressed to two to three days. Threat hunts that took twenty hours compressed to minutes. The model did not replace the analyst. It elevated the analyst, bounded carefully to guard against hallucination.

A handful of adversaries hold a comparable data advantage, and their ability to apply it will give them extraordinary reach. Whether they choose to use it is a human decision Dragos cannot forecast. What Dragos can say is that the question is not whether AI favors offense or defense. It is the same question the security field has always faced: whoever puts in the work wins. If you know your environment better than anyone and you do the work to protect it, you win. If you have cut corners and an adversary does the work, they win. AI extends the reach and scale of both sides, which is precisely why the gaps in under-protected infrastructure are so concerning. Dragos estimates fewer than 10 percent of OT environments worldwide have visibility and monitoring in place.

None of this rewrites the security playbook. AI does not demand that defenders reinvent security. OT compromise still overwhelmingly comes down to known tactics, techniques, and procedures for misoperating equipment, using operational systems against themselves. The SANS Five ICS Cybersecurity Critical Controls, defined by Robert M. Lee and Tim Conway after examining every industrial compromise Dragos could access, still hold: ICS incident response, defensible architecture, network visibility and monitoring, secure remote access, and risk-based vulnerability management. The controls that worked before AI are the controls that work now. What AI changes is the urgency. The community is dividing into organizations that have done the work and organizations that have not. The first group will need to move faster and with more urgency, sometimes in a step change. The second group is heading for a very different level of infrastructure risk than it has experienced before.

Looking ahead, models will keep improving, and OT context will become more widely available as research labs and universities publish on how controllers can be attacked. Dragos already sees a reasonable forecast: models with enough context to operate in automation environments with less human interaction. When Dragos’s own red team applied its knowledge to a model, that model moved through the perimeter, mapped the automation environment passively and accurately, identified the exact OEM and system, and found the right exploits to reach the controllers. That capability is not in public models today. It likely will be. The defense against it is not more AI for its own sake. It is doing the security work: the Five Critical Controls, and then more.

AI-equipped adversaries are coming for critical infrastructure whether or not defenders modernize. The playbook does not change. The urgency does. For asset owners and operators, the path forward is the one that already worked: get visibility into the environment, do the Five Critical Controls, and treat detection, response, and recovery with the same investment long given to prevention. For vendors and OEMs, it is to own the problem, run these models against your own products before shipping, and be ready to show your customers how. The security work has not changed. AI has raised the cost of not doing it.

Want the full field research behind this? Robert M. Lee and Garrett Bladow broke it down in a recent webinar, Frontier AI in OT Defense: What’s Real, What’s Hype.

Watch now

Garrett Bladow is a Distinguished Engineer at the critical infrastructure cybersecurity company, Dragos, Inc. In this role, he is responsible for product development, technical oversight, and delivering solutions to our customers’ hardest problems. In addition to the product responsibilities, he is a champion for the engineers who build those products, mentoring technical talent and setting the standard for engineering practice across the company.