AI-Driven OT Security Is Only as Good as the Telemetry Feeding It

Fewer than 10 percent of OT networks have meaningful monitoring in place, according to the 2026 Dragos OT Cybersecurity Year in Review. Until that changes, layering machine-learning tools on top of industrial control systems may create more risk than it resolves.

ThreatVectr Newsdesk· 5 min read
AI-Driven OT Security Is Only as Good as the Telemetry Feeding It
Share

The 2026 Dragos OT Cybersecurity Year in Review carries a finding that should stop any C-suite AI strategy in its tracks: fewer than 10 percent of operational technology (OT) networks worldwide currently have meaningful network monitoring in place. In 30 percent of last year's incident response engagements, investigations began not with a detection alert but with a plant-floor worker noticing that something seemed wrong. That gap is where AI-driven security initiatives quietly fail.

The problem is not algorithmic. A model trained on enterprise telemetry — HTTP, DNS, Windows event logs — will encounter a Modbus or PROFINET segment and flag routine industrial traffic as a threat. If that model is connected to an automated response playbook, the result can be a self-inflicted outage. During one simulation conducted for a Tier-1 automotive supplier, a security orchestration, automation, and response (SOAR) platform attempted to isolate a critical programmable logic controller (PLC) in what the platform classified as a containment action. The plant manager later calculated the simulated event would have cost a six-figure sum per hour in downtime. In OT environments, an automated "isolate host" command is often functionally indistinguishable from a denial-of-service attack.

This tension traces back to a foundational difference between IT and OT security priorities. IT frameworks place confidentiality first; OT frameworks invert that order, with availability at the top. Any security tooling that does not account for this inversion is operating on false assumptions.

Passive monitoring is not optional

When evaluating platforms such as Nozomi Networks Guardian, Claroty Platform, or Microsoft Defender for IoT, a single question tends to eliminate candidates faster than any feature comparison: does the tool require active queries? Actively polling a 15-year-old Siemens S7-300 or a Rockwell Automation ControlLogix to extract metadata can crash the device. Operations directors at multiple sites have refused to approve deployments on precisely this basis.

For AI to function in OT, it must be fed by passive network monitoring drawn from Levels 0 through 2 of the Purdue Enterprise Reference Architecture, the layered model that defines the boundary between corporate IT and plant-floor OT systems. Without S7Comm, DNP3, and similar industrial protocol traffic, the model is performing inference on an empty corpus. (The Purdue model is frequently referenced but less frequently implemented; many organizations discover during an inventory exercise that their Level 2 to Level 3 boundary is largely theoretical.)

And the unpatched endpoint problem does not disappear because a dashboard exists. A maintenance laptop running Windows 7 with no endpoint detection and response agent, no patches since 2017, and a physical connection to legacy protection relays is not an edge case. It is a recurring fixture across energy utilities, pharmaceutical manufacturing sites, and automotive plants.

Identifying what actually matters

Successful OT security programs tend to begin not with a 300-page AI roadmap but with a narrow question directed at plant managers: which three processes cannot be interrupted for even one hour? At a power utility, the answer is typically the protection relays, not the billing system. At a pharmaceutical site, it is a single fermentation line. At an automotive plant, it is the welding cell feeding the body shop.

That list, once established, collapses the AI scope from the entire network to the systems that carry genuine operational risk. It also separates the assets that require real-time anomaly detection from those that require only monthly compliance reporting. Conflating the two categories is a reliable way to exhaust an OT security budget without measurable risk reduction.

But the list itself is contested terrain. Security teams consistently over-count critical assets; operations teams consistently under-count them. At one manufacturing site, the security team had catalogued 47 systems as critical. The plant director, in a focused conversation, named six.

The threat actors are already present

Volt Typhoon, the People's Republic of China-linked intrusion set, has been documented using living-off-the-land techniques to embed persistently in critical infrastructure networks, as detailed in CISA advisories published in 2024. These techniques generate minimal telemetry by design, which means that networks lacking passive OT monitoring will not detect the intrusion at all, regardless of how sophisticated the AI layer above it may be.

A tabletop exercise tracing a ransomware path from a phishing email to a contractor's USB drive to a maintenance VLAN illustrates the timeline precisely. Minute zero: a procurement employee opens a malicious invoice attachment. Minute fourteen: the contractor connects the same laptop to the maintenance VLAN to push a firmware update to a human-machine interface (HMI). Minute twenty-three: the ransomware encrypts the engineering workstation. Minute thirty-one: operators notice screens going dark, though production continues on the PLCs themselves, because OT controllers do not require Windows to execute their logic. The illusion of normality holds for nearly an hour, until an operator attempts a setpoint change and receives no response.

So the sequence that makes AI viable in OT environments is fixed: inventory the floor, segment the network, establish passive telemetry from Purdue Levels 0 through 2, and only then introduce the machine-learning layer. Each step is a prerequisite for the next. Skipping any one of them produces a well-funded dashboard for a network that remains effectively invisible.

The Cybersecurity and Infrastructure Security Agency (CISA) has not issued formal rulemaking specific to OT AI deployment timelines. CISA's current cross-sector guidance on OT security, including its recommendations on network segmentation and passive monitoring, remains advisory in nature for most critical infrastructure sectors, with sector-specific mandatory requirements governed by individual regulatory bodies such as the North American Electric Reliability Corporation (NERC) under its Critical Infrastructure Protection (CIP) standards. NERC CIP-007-6, which addresses system security management, includes patch management obligations but does not specify AI tooling requirements. The next NERC CIP standards development activity window is scheduled to open in the second quarter of 2025.

© 2026 Threat Vectr