The instinct in most cybersecurity programs is to look for the intruder. In operational technology (OT), that instinct is only half right.
A sufficiently capable adversary who gains the right access and has an understanding of industrial environments, may not need recognizable malware to create operational consequences. The real objective may be making an unauthorized change to the process itself.
An unauthorized setpoint change, unexpected controller-mode transition, modified logic block, bypassed interlock, or engineering change performed through legitimate tools can potentially alter equipment behavior without producing the conventional indicators defenders are accustomed to hunting.
Importantly, none of these actions are inherently malicious. Engineers routinely modify configurations, logic, firmware and setpoints. The challenge is determining whether a change is authorized, operationally justified, safe and consistent with the expected state of the process.
This is where operational resilience must evolve in the age of artificial intelligence (AI) and AI-powered cybersecurity.
Industrial environments contain engineering workstations, HMIs, controllers, historians and specialized applications specifically designed to modify physical processes. If an adversary compromises legitimate credentials or engineering access, the tools required to affect operations may already be available.
Real-world incidents have demonstrated this principle. In attacks such as Stuxnet, TRITON/TRISIS, and the Ukraine power-grid operations, the ultimate concern was not simply malicious code existing somewhere in the environment. It was the adversary's ability to understand industrial systems and translate cyber access into physical or operational effects.
Defenders therefore need to look beyond malicious files and network indicators and ask:
What changed? Who or what initiated it? Was it authorized? What equipment or process does it affect? And did the resulting behavior remain within safe operational boundaries?
The evidence of compromise may be important. But in OT, the evidence of consequence can be even more important.
AI creates opportunities on both sides of this equation.
For adversaries, AI may accelerate activities that traditionally require specialized knowledge: interpreting technical documentation, analyzing configurations, understanding industrial protocols, examining engineering logic, and connecting cyber access with operational context.
But AI could also provide defenders with an important advantage: the ability to continuously correlate operational signals at a scale that would be extremely difficult manually.
This does not mean simply training a model to “learn normal.”
Industrial operations are rarely that predictable. A facility behaves differently during start-up, shutdown, maintenance, production changes, equipment degradation and abnormal conditions. A statistically unusual setpoint may be entirely legitimate, while a malicious change could remain within an apparently acceptable operating range.
But AI could also provide defenders with an important advantage: the ability to continuously correlate operational signals at a scale that would be extremely difficult manually.
The stronger use of AI is therefore not to replace engineering judgement, but to connect context.
On its own, a setpoint change may mean very little. But suppose the same change occurs outside an approved maintenance window, follows an unusual engineering-workstation login, affects a critical control loop, coincides with a controller-mode transition and has no corresponding approved change request.
Individually, none of these signals prove malicious activity.
Together, they create a very different risk picture.
AI-assisted monitoring could correlate process behavior, controller states, configuration history, engineering activity, asset criticality, identity information and authorized change records and surface combinations that warrant immediate human investigation.
The question for AI should therefore not simply be: “Is this activity malicious?”
A more useful question is: “Does this change make sense in the operational context in which it occurred?”
Engineering activity deserves particular attention.
Logic modifications, firmware updates, configuration changes, and controller maintenance are legitimate and necessary. But because changes to critical systems may be controlled and relatively infrequent, unexpected engineering activity can also provide valuable security signals.
Was the change authorized? Did it originate from the expected workstation? Was the individual authorized for that controller? Did it occur during the maintenance window? What logic changed? Which physical process does that logic influence? Did equipment behavior change afterwards?
AI can help assemble these pieces faster, but it should not become the authority deciding whether a plant is safe.
Stronger architecture combines multiple layers:
Deterministic controls establish what should be permitted. Engineering governance establishes what was authorized. Process monitoring establishes what actually happened. Again, AI helps connect the three.
That distinction matters because operational resilience cannot depend on another probabilistic system making autonomous decisions about safety-critical processes.
There is another limitation: a single facility only sees its own environment.
An unusual sequence of controller-state changes or engineering modifications at one organization may initially appear insignificant. But the same pattern may already have been observed elsewhere, and the actions determined to be malicious.
This makes trusted community intelligence increasingly important.
Sector communities such as OT-ISAC can help operators share observations about emerging techniques, unusual engineering behavior, exploitation patterns and operational anomalies. A technique observed at one organization can become a detection hypothesis for others before each operator has to discover it independently.
The future of OT threat intelligence may therefore need to expand beyond indicators of compromise, and beyond the threat awareness of a single organization.
Hashes, IP addresses, domains, and vulnerabilities remain useful. But communities can increasingly share behavioral and operational intelligence that a lone organization would otherwise miss or find too late. No matter the experience of a security team or the sources of information it subscribes to, one company will never have the “eyes and ears” of a collective defense community.
Together, as AI identifies relationships across these observations, while human analysts and engineers determine whether those relationships are operationally meaningful, and the judgements of both are exchanged in a secure communal environment, defenders can outpace adversaries – most of the time.
AI can accelerate an adversary's journey from understanding the network to understanding the process. Defenders should use that same capability to move from simply detecting compromise toward detecting changes that could affect safety, availability, quality or physical operations.
Moving beyond prevention to mitigation brings another important point. Operational resilience is ultimately not about stopping every intrusion, which is unlikely to be possible.
Operational resilience is about maintaining the ability to understand, operate and recover processes safely even when preventive controls fail.
That requires visibility not only into who entered the environment, but into what changed after they entered.
AI can accelerate an adversary's journey from understanding the network to understanding the process. Defenders should use that same capability to move from simply detecting compromise toward detecting changes that could affect safety, availability, quality or physical operations.
The objective is not AI replacing engineers, deterministic controls, or established OT security practices. It is AI helping defenders connect cyber activity, engineering context and physical-process behaviour quickly enough to recognize when something no longer makes operational sense, and mitigating damage to ensure operation in an impaired state or the ability to rapidly recover.
AJ Eserjose is Regional Director for the Operational Technology Information Sharing and Analysis Center (OT-ISAC), a trusted hub for secure threat intelligence exchange to strengthen the cybersecurity posture of critical infrastructure across Asia-Pacific. AJ leads the strategic growth and operational development of OT-ISAC, focusing on innovation programs, alliance-building, and deepening engagement with members, alliance partners, and key stakeholders.