ICS Advisory Project founder Dan Ricci writes that traditional OT cybersecurity hygiene practices such as strong authentication and virtual network segmentation are solid defensive measures against the capabilities of frontier AI models in 2026. Will that hold beyond remains to be seen.

Frontier AI Models Closing OT Exploitation Gap

Dan Ricci
/
Aug 11, 2026

On July 16, The Coca-Cola Company disclosed through an SEC 8-K filing that its subsidiary fairlife LLC had experienced a ransomware event affecting the company's production-related systems. Product safety was not impacted. U.S. dairy production was suspended. This is the ransomware baseline in 2026, and it is also the last threat model most operational technology (OT) security programs are actually designed against.

Six months earlier, in January, a non-nation-state threat actor compromised the enterprise IT environment of Servicios de Agua y Drenaje de Monterrey (SADM), the water utility serving Mexico's third-largest metropolitan area. Public reporting on the intrusion has documented what happened next. The attackers used commercial frontier artificial intelligence (AI) models to plan the intrusion, write the code, map the internal network, and identify a specific industrial gateway as their next target. They executed multiple rounds of AI-directed password spraying against that gateway. OT authentication held. They pivoted back to IT data exfiltration.

The important finding is not that OT was compromised. It was not. The important finding is what class of attacker just tried, and how they got as far as they did.

SADM Defenses Proved OT Security Works—Today

For 15 years, one of the arguments for OT segmentation has been that OT is a specialized domain. Understanding what a Modicon controller does, what a Wonderware or OSI PI historian holds, or how a SCADA system monitors and manages the process has required time in the field. That specialization was a defensive edge, whether asset owners talked about it that way or not.

Frontier AI closed that advantage. Any moderately skilled IT-native operator can now, in an afternoon of conversation with a commercial large language model (LLM), get a functional understanding of a controller, an HMI screenshot, or a SCADA management interface. Not perfect understanding. Not process semantics for a specific plant. But enough to try.

The SADM intrusion is what "enough to try" looks like in practice. The attackers were not a state-sponsored threat group based on threat intelligence reporting. They did not have a decade of industrial control systems (ICS) tradecraft. What they had was a commercial AI model, and they used it primarily for technical development and execution of the operation. The AI wrote the intrusion tools, including one Python framework of more than 17,000 lines. It identified the industrial gateway as a strategic target during internal reconnaissance. It generated context-aware credential lists that mixed default vendor values with SADM naming conventions and reused passwords from other compromised Mexican government systems. The attackers bypassed the AI's safety controls by framing their requests as authorized security research.

What stopped them was ordinary OT hygiene done correctly. The authentication boundary at the gateway held up against the attack. Credentials were not reused. Segmentation was in place. That is the good news that should not be disregarded or understated. But it should also not be overemphasized. It held against a threat actor using commercial AI in January 2026. It may not hold against a more patient version of the same actor a year from now.

The Disclosure Surge is Already Here

The AI capability shift is only one challenge facing OT security programs. The other is a decade-long surge in disclosures that is now poised to accelerate.

CISA ICS Advisories Published per Year, 2010 to 2026

Source: ICS Advisory Project data on CISA ICS advisories.

CISA published 17 ICS advisories in 2010. It published 508 in 2025. That is roughly a thirtyfold increase over 15 years. 2026 is on pace for 548, which would set a new record and continue the curve without factoring in any AI-driven acceleration. Frontier AI-assisted vulnerability research against OT products is scaling in the security community now, but the six-to-12-month lag between discovery and coordinated CISA publication means the impact will not appear in these totals until 2027.

CISA is the visible tip. Based on ICS Advisory Project tracking, CISA advisories represent approximately 19% of the total OT-relevant disclosure landscape in 2025. The remainder, roughly 2,200 advisories in that year alone, is published weekly through vendor Product Security Incident Response Teams (PSIRTs) or through other Cybersecurity Emergency Response Teams (CERTs) that are not accounted for in this chart. Frontier AI models are being used right now by security researchers to accelerate vulnerability discovery in OT-relevant products. Even a modest multiplier on the baseline rate produces a disclosure volume that no OT vulnerability management program built around patch-first prioritization can absorb.

The math problem is not new to anyone who has spent time working closely with plant operations teams, business units, and operations and maintenance technicians. Maintenance windows are quarterly at best in most environments and annual in many. Some assets never receive a security patch across their entire operational lifetime. Vendor patch availability is on the vendor's schedule, which is not correlated with the severity of the underlying vulnerability. Patch-first vulnerability management was already inadequate for OT before AI-driven acceleration. What the acceleration does is make the inadequacy impossible to ignore.

What Organizations Should Do

Four recommendations, and none of them are special in any way. All of them are already known and what a well-run OT program should be doing, but the frontier AI shift and the disclosure surge make them urgent instead of aspirational.

Authentication, Segmentation are Primary Defenses

First, treat authentication and segmentation at the OT boundary as the primary defense they are, and audit them under the assumption that they will be tested this quarter. The SADM gateway held because credentials were unique and the interface resisted password spraying. Verify that yours do the same. Every industrial gateway, every engineering workstation jump host, every vendor remote access path. If your environment allows password reuse from another compromised network, you have the same authentication surface SADM had without the defenses that saved them.

Take a Countermeasures-First Approach to Exposures

Second, move vulnerability management from patch-first to countermeasures-first. This is not a rejection of patching. Patch when you can. But build the program around the assumption that most disclosed vulnerabilities will not be patched on the vendor's recommended timeline because they cannot be. Every new advisory needs to be assessed against questions that CVSS does not account for: where is the affected asset located, how is it connected and accessed (locally and remotely), what operations does it support, what network changes have occurred, what monitoring rules are in place, or what process adjustments can be made to reduce our exposure to this vulnerability until we can patch, if we ever do. Programs that cannot answer those questions for open advisories in their environment are running on borrowed time.

Frontier AI Models are Defensive Tools

Third, use frontier AI on the defender side, but use it correctly. The value is not autonomous defense agents. Those are not deployed at scale in OT today. The value is context. A model that can reason about your specific plant, your tag names, your interlock logic, and your safety envelope is a force multiplier for the humans making countermeasure decisions. Leverage it as an assistant to your engineers and analysts, not as a replacement for them.

Update OT Incident Response Playbooks

Fourth, update incident response playbooks to assume the attacker does not understand what they are touching. Traditional OT threat modeling was gauged against savvy adversaries who knew exactly what they were doing. The next wave of AI-enhanced attackers will not. They will have the syntax to write to a controller register, but not the context to understand what that register controls or what happens to the process when they change it. This is worse than Sandworm, not better. Response playbooks need to account for the possibility that the attacker's actions inside your OT environment are neither surgical nor rational.

The Window is Now

The knowledge gap that protected OT for two decades is gone. It was not going to survive the arrival of commercial frontier AI. The good news is that the specific defenses that stopped the SADM intrusion are not unique. They are segmentation, authentication hygiene, and monitoring, applied deliberately at the OT boundary. The bad news is that the volume of disclosed vulnerabilities they need to defend against is climbing on a curve patch-first programs cannot absorb, and the threat actors testing those defenses are getting more capable faster than the industry is used to.

Organizations that come out of the next 18 months in good shape will be the ones that no longer think of OT vulnerability management as a smaller version of IT vulnerability management, and have started running it as its own discipline with its own formula and its own countermeasures-first posture. The AI shift made this urgent. It did not make it optional.

Dan Ricci
Founder, ICS Advisory Project

Dan Ricci is founder and CEO of Industrial Data Works, and the founder of the ICS Advisory Project, an open-source project to provide DHS CISA ICS Advisories data visualized as a dashboard to support vulnerability analysis for the OT/ICS community. He retired from the U.S. Navy after serving 21 years in the information warfare community.

Stay in the know Get the Nexus Connect Newsletter
You might also like… Read more
Latest on Nexus Podcast