Background Image
 
Request a Demo
Claroty Toggle Search
Return to Blog

Understanding AI-Powered Cybersecurity in OT Environments

/ 7 min read
Featured image for our blog: Understanding AI-Powered Cybersecurity in OT Environments

Autonomous actions aren’t likely to get the green light in operational technology (OT) environments any time soon. Physical processes on plant floors may suffer operational and safety consequences in the event of a cyber incident, and engineers and asset operators are unlikely to relinquish responsibility for those processes from human hands.  

However, there is immediate value in AI-powered cybersecurity for manufacturing, energy and utilities, water and wastewater and other critical industries. Instead of acting on behalf of a security team, AI should be viewed as a partner, an intelligent analyst that delivers machine-speed information from connected assets. 

That data enhances visibility and brings important context to analysts and other security and risk management decision makers. Tasks such as alert triage or the correlation of OT security events can be offloaded to an AI agent, which, through its speed and contextual understanding of assets in the environment, can quickly deliver answers that teams can act upon faster than through manual triage

This blog will examine AI-powered cybersecurity through several lenses:

  • The impact of frontier AI models on OT security teams

  • How AI may revolutionize exposure management

  • The context-rich insights that inform threat and anomaly detection

  • How Claroty Claire™  operationalizes agentic security

The Rise of Frontier AI Models in the Cybersecurity Landscape

Understanding Frontier AI and Large Language Models (LLMs)

The introduction of frontier AI models such as Anthropic’s Claude Mythos and OpenAI GPT-6 Astra has created an unprecedented upheaval in the cybersecurity industry. These models’ ability to uncover and exploit vulnerabilities at machine-speed has rendered traditional vulnerability management strategies virtually obsolete. 

Since Mythos and its counterparts arrived on the scene, an overwhelming number of disclosures and updates from leading vendors such as Microsoft, Cisco, and others are forcing organizations to re-think remediation in order to handle the deluge. For example, security and network teams can no longer regression-test a Patch Tuesday update and deploy the 50 updates that were once the monthly norm. 

The hundreds or thousands of updates coming through monthly require a remediation program that prioritizes updates according to the business impact of affected assets, and the risk posed by taking an asset offline for an update. This requires an exposure management approach that tackles securing OT and other cyber-physical systems (CPS) beyond just vulnerabilities. AI as a partner can gather, correlate, and deliver actionable advice related to insecure asset configurations, poorly secured or unmonitored remote access, and the risks associated with legacy communication protocols that still pervade many OT networks. 

Revolutionizing Exposure Management with AI

Exposure management begins with visibility into connected OT assets and the creation of a verifiable asset inventory. AI is a valuable partner in sorting passive and active traffic collections to discern the assets that collect data, manage physical processes, and keep plants up and running. AI-powered analysis of traffic can make sense of the myriad protocols at work on an OT network, as well as the legacy software and firmware running on industrial assets, many of which were never designed with connectivity or security in mind. 

AI can analyze asset inventories, vulnerabilities, configurations, network communications and threat intelligence to help establish a more meaningful picture of exposure. Instead of treating every vulnerability equally, AI can help determine which weaknesses actually matter based on factors such as asset criticality, network connectivity, exploitability, compensating controls and potential impact on physical operations.

This moves exposure management from a vulnerability-counting exercise to a risk-prioritization exercise. For the CISO, the objective isn’t simply to reduce the number of vulnerabilities; it is to reduce the organization’s most consequential paths to operational disruption.

Utilizing AI-Powered Cybersecurity for OT and ICS

Alert fatigue is not exclusive to IT. OT also has an information overload problem that slows down remediation and mitigation of cybersecurity events. A human analyst spends significant time connecting not only asset data and vulnerability information—some advisory information is not always complete—but also asset configurations and external threat information. 

AI brings contextual intelligence to this puzzle, providing analysts with not only a CVE number or an alert, but the role a vulnerable asset plays on a physical factory line, how it communicates to other assets or engineering workstations, and its overall business impact in the event of a disruptive or damaging event. This is an invaluable context that not only shortens remediation time, but also provides analysts with data that informs security and risk decisions. 

For example, the appropriate response to a vulnerability affecting an internet-connected engineering workstation may be very different from the response to the same vulnerability on a safety-critical controller. AI can also establish behavioral baselines for assets, users and communications and continuously evaluate deviations from those patterns. This is the hallmark of continuous threat detection; in an OT environment, for example, unexpected changes to controller logic or abnormal communication between network zones may warrant investigation even when there is no known malware signature associated with the activity.

AI can help distinguish those scenarios and recommend appropriate mitigation strategies, such as segmentation, access restrictions, configuration changes, monitoring or compensating controls when immediate patching is operationally unsafe. The result is not simply faster remediation. It is better-informed remediation.

Operationalizing Agentic Security with Claroty Claire™

Delivering CPS-Native AI Visibility and Contextual Insights

Claroty is building Claire, which is the industry’s first CPS-native AI security agent, and the agentic partner to the all-important humans-in-the-loop necessary for safe operations and overall resilience. Claire is being built to orchestrate asset discovery through active and passive queries, delivering a single source of visibility and operational truth necessary to an OT and CPS security program. Its capabilities inform the actionable recommendations asset operators may use to prioritize remediation for critical assets. Claire is the backbone of OT and CPS risk reduction. 

Claire’s foundation is a decade of industry knowledge, experience, and depth of data that is unmatched in the industry. Claire was trained on data from more than 40 million protected assets, 20,000 deployed sites, and more than 6,500 unique OEM and MDM vendors. There is extensive industry knowledge behind Claire, including data from 50-plus industries that Claroty supports, in addition to Team82’s dedicated research of OT and CPS exposures and attacks. By applying AI to this data, we are able to deliver meaningful outcomes: risk reduction, compliance, and operational resilience.

A key part of that foundation is Claroty’s CPS Library, the industry’s first AI-driven global standard for correctly identifying assets that transmit imprecise or conflicting product codes, allowing exact asset inventories and risk identification.

Governance’s Role in AI-Powered OT Security

Asset operators are unlikely to relinquish control over OT environments to an AI agent, but there is room for AI to act as a partner that closes visibility gaps and provides context-rich insights to improve exposure management and threat detection capabilities. 

Security, risk, and business leaders striving for overall operational resilience understand how AI is a competitive necessity. They must also understand the guardrails necessary—such as humans-in-the-loop—to maintain safety and availability in the hands of humans as much as possible. Autonomy can be granted to low-risk and reversible tasks where AI excels in such restricted environments. 

Governance equates to trust that AI operates only within defined boundaries and humans remain responsible for decisions that can be consequential to the business or public. Guardrails must be core AI capabilities, and not an add-on, throw-away feature, especially in environments where resilience, safety, and compliance are paramount, such as OT. 

Learn more about AI-powered cybersecurity and how Claroty ClaireTM brings CPS-native intelligence to your security stack. Explore Claire or schedule a demo with our team today.

Interested in learning about Claroty's Cybersecurity Solutions?

Background Image

Life, uninterrupted

We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.

Claroty
LinkedIn Twitter YouTube Facebook