Artificial intelligence (AI) in manufacturing has successfully been used to automate manual cyber tasks, parse and reduce the alerts coming across SOC analysts’ desks, and improve forensic investigation speed and analysis of incidents.
Business pressures and an expansive threat landscape, however, will soon force security and operations leaders in manufacturing to re-examine their programs strategically to use AI to help protect cyber-physical systems (CPS). Manufacturing enterprises well understand that business outcomes depend on the availability and reliability of industrial control systems (ICS), programmable logic controllers (PLCs), robotics, automated logistics, supervisory control and data acquisition (SCADA) systems, intelligent sensors, and building management systems that keep production running safely and efficiently.
An AI-powered CPS security strategy in manufacturing should establish operational resilience as its prime mission statement. That means ensuring that uptime of manufacturing assets is paramount. It also means strategizing about how to handle the growing influx of vulnerability disclosures driven by frontier AI models such as Claude Mythos and ChatGPT-5.6 Sol.
AI can bring a worthy measure of relief to security and operations teams by reducing the manual analysis work dragging down security operations teams. Many organizations are already using AI to triage and enrich security alerts with context driven by asset visibility and management tools. Incoming threat intelligence feeds coupled with asset inventories provide insight on which assets/ systems to prioritize for remediation or mitigation. AI is also already hard at work at root-cause analysis during investigations. Of course, all of this enriches and aids compliance reporting.
Now manufacturing organizations need AI that understands the operational context of cyber-physical systems —not simply cybersecurity events. This is particularly important in the context of the expected “vulnapocalypse” as a result of Claude Mythos and ChatGPT Sol becoming adept at finding and exploiting software and firmware vulnerabilities, even without human direction.
Mythos has drastically reduced the time between vulnerability discovery and exploitation, and already we’re seeing dramatically higher numbers of disclosures from vendors such as Microsoft, Cisco, and others at the core of computing infrastructures.
Manufacturers now face hundreds—or thousands—more vulnerability disclosures affecting industrial environments than traditional vulnerability management programs were designed to process. This is going to dramatically tax security and operations teams; AI greatly help reduce this burden by not only identifying vulnerable assets but also making determinations as to their value to important business outcomes, which compensating controls (network segmentation and host hardening being the top such controls) best mitigate these vulnerabilities, and whether updates to firmware or OS patching, for example, introduce new operational risks.
The current manual approach to these important tasks would immediately put security and operations well behind the eight ball they likely will not emerge from. An AI-driven defender can, at machine-speed, assess asset criticality in the context of the business, process dependencies, exposures, attack paths, safety implications, and production necessities. This is how operational resilience can and should be built for critical, modern manufacturing companies. A vulnerability management approach based on CVSS criticality ratings doesn’t cut it in 2026. AI can present remediation priorities based on the likelihood that a vulnerability could disrupt operations and even within guardrails mitigate autonomous AI-attacks. This fundamental shift moves vulnerability management from compliance-driven patching to operational risk management.
The security and operational constraints on CPS protection are well understood given reactive patching isn’t always an option; often expensive downtime is required for host updates; unsupported legacy technology still and rightly so proliferates organizations; safety remains the overriding concern on the shop floor. Fortunately host hardening technology exists today as a protection tool for physical systems to complement and aid OT cyber ecosystems.
A CPS protection strategy must consider the unique complexities explained above, as well as the technology realities around CPS and operational technology (OT). AI can reduce this pain if trained to understand the multitude of proprietary industrial communication protocols, data flows, how engineering workstations communicate with PLCs and human-machine interfaces (HMIs), safety systems, physical asset groups, and overall industrial network architecture.
Operational awareness of the asset groups enables AI to recommend remediation strategies that improve security without compromising manufacturing availability or safety. As we’ve mentioned, vulnerability management has a new paradigm: exposure management. Rather than treating every vulnerability equally, manufacturers need continuous visibility of the attack chain into how human attackers or autonomous AI traverses through interconnected operational environments. AI can help security teams with complex integrated systems and identify exploitable pathways between IT and OT assets, reveal unintended trust relationships, evaluate segmentation effectiveness, and suggest defensive actions to be acted upon.
An exposure-centric approach enables security teams to better focus their limited resources where they can reduce the greatest operational risk.
While one should acknowledge that most organizations aren’t ready for machines to make autonomous decisions— just yet—AI can greatly improve human decision making today. Security and operations teams within manufacturing must insist on AI technology that understands CPS in the context of the business.
Organizations that combine AI-powered asset intelligence, exposure management, and operational context with CPS host hardening will be far better positioned to manage the growing volume of vulnerabilities without overwhelming already constrained security and engineering teams.
Ultimately, the reality is the goal is not to remediate every vulnerability. It is to ensure that the vulnerabilities most likely to interrupt production, impact safety, or disrupt business operations are identified and addressed first. In the age of AI-assisted CPS protection, intelligent manufacturing shifts from vulnerability management to operationally informed exposure management coupled with true CPS host protection as the defining characteristics of a resilient manufacturing cybersecurity program.
Jim LaBonty is the retired Director and Head of Global Automation Engineering for Pfizer's Global Engineering & Technology division. In this role he primarily focused on establishing the strategic direction and harmonizing control system solutions across 42 manufacturing sites globally, including securing the development of Pfizer's COVID-19 vaccine. Previously, LaBonty held senior engineering and system architect roles at Rockwell Automation, Eli Lilly & Company, and Eastman Kodak Company. He now leverages his decades of experience to help firms with their corporate OT cyber strategy and global program execution, with the goal of protecting manufacturing.