Artificial intelligence is changing how organizations develop software, analyze data, and automate business processes. It is also beginning to change how security researchers and threat actors approach vulnerabilities in industrial environments.
A recent experiment reported by SecurityWeek highlights this shift. Researchers from Forescout used an AI model to help port a remote code execution exploit between different WAGO programmable logic controller models. The research demonstrated that AI can assist with adapting existing security research to a different industrial control environment, although the process still required significant human expertise, time, testing, and financial resources.
The experiment is important because PLCs sit at the heart of many physical processes. They control machinery, production systems, utilities, building systems, transportation infrastructure, and other operational environments.
As AI capabilities continue improving, the security community needs to consider what happens when techniques traditionally requiring specialized industrial cybersecurity expertise become easier to reproduce or adapt.
Why PLC Security Matters
Programmable logic controllers are fundamental components of Operational Technology environments.
They are commonly used to control:
• Manufacturing equipment
• Industrial production lines
• Water and wastewater systems
• Energy infrastructure
• Building automation
• Transportation systems
• Chemical and processing facilities
• Critical infrastructure operations
A compromise of an enterprise application may result in data theft or business disruption.
A compromise of an industrial control system can potentially affect the physical world.
Depending on the environment, unauthorized manipulation of industrial equipment could result in production outages, equipment damage, safety concerns, environmental consequences, or disruption of essential services.
AI Can Reduce the Barrier to Specialized Security Research
Historically, adapting an exploit between different hardware platforms could require extensive knowledge of processor architectures, firmware, memory layouts, operating systems, industrial protocols, and application behavior.
AI can assist researchers with parts of this work.
The Forescout experiment demonstrates that an AI model can contribute to the process of adapting existing exploit research for another PLC model. However, the research also shows that AI does not eliminate the need for human expertise.
The process still requires:
• Understanding the target technology
• Reviewing technical documentation
• Analyzing software and firmware behavior
• Validating AI generated output
• Troubleshooting failures
• Conducting controlled testing
• Understanding industrial environments
• Maintaining appropriate safety controls
This distinction is important.
AI may accelerate portions of cybersecurity research without making complex industrial exploitation completely automated.
The Bigger Concern: Scaling Cybersecurity Knowledge
The most important lesson may not be the specific exploit involved in the experiment.
It is the possibility that AI could gradually reduce the amount of specialized knowledge required to adapt known vulnerabilities across similar technologies.
Industrial environments often contain equipment from multiple vendors and generations.
Organizations may operate:
• Legacy PLCs
• Modern PLCs
• Industrial gateways
• Remote terminal units
• HMIs
• Engineering workstations
• Industrial network equipment
• Proprietary control systems
When similar vulnerabilities or attack techniques can potentially be adapted across related platforms, defenders need to think beyond individual devices.
The focus should shift toward securing the entire OT environment.
OT Security Is Different From Traditional IT Security
One of the biggest challenges in industrial cybersecurity is that Operational Technology cannot always be managed like conventional enterprise IT.
In an office environment, organizations may be able to quickly reboot a server, install a security update, or replace an application.
Industrial systems can have very different requirements.
A PLC may control a production process that cannot simply be taken offline.
Security teams must therefore balance:
• Cybersecurity
• Availability
• Safety
• Reliability
• Production requirements
• Equipment lifecycle constraints
A security control that is appropriate for an enterprise laptop may not be appropriate for a PLC controlling a critical physical process.
Legacy Technology Creates Additional Risk
Many industrial environments contain systems that were designed before today’s cybersecurity threats became common.
Some equipment may have:
• Long operational lifecycles
• Limited security capabilities
• Older firmware
• Infrequent patching
• Weak authentication mechanisms
• Legacy protocols
• Limited monitoring
• Difficult maintenance windows
These characteristics can make vulnerability management particularly challenging.
Organizations cannot assume that older systems are safe simply because they have been operating reliably for many years.
The Importance of Segmentation
Strong network architecture is one of the most important defenses for industrial environments.
Organizations should consider appropriate separation between:
• Corporate IT networks
• Industrial OT networks
• Engineering environments
• Remote access systems
• Vendor connections
• Internet facing services
Segmentation can reduce the ability of an attacker who compromises an enterprise environment to move directly into critical industrial systems.
Industrial environments should also be monitored for unusual communication patterns and unauthorized changes.
Remote Access Deserves Special Attention
Remote administration can provide significant operational benefits, especially for organizations supporting geographically distributed industrial infrastructure.
However, remote access can also introduce substantial risk.
Organizations should evaluate:
• Remote vendor connections
• Privileged accounts
• VPN access
• Multi factor authentication
• Jump servers
• Administrative sessions
• Remote maintenance tools
• Session monitoring
• Access expiration
Remote access should be granted based on business need and monitored continuously.
AI Security Requires AI Governance
The growing use of AI in cybersecurity creates an interesting challenge.
Organizations can use AI to improve defensive capabilities, but attackers and security researchers can also use AI to accelerate technical work.
This creates a need for responsible AI governance.
Organizations should establish policies covering:
• AI usage within security teams
• Protection of confidential technical information
• Validation of AI generated security recommendations
• Human oversight
• Data privacy
• Access controls
• AI model security
• Monitoring of AI enabled systems
• Security testing of AI applications
AI should support security professionals rather than operate without appropriate controls.
What Industrial Organizations Should Do
The emergence of AI assisted security research provides another reason for organizations to strengthen foundational cybersecurity controls.
1. Identify Critical OT Assets
Maintain an accurate inventory of PLCs, HMIs, engineering workstations, gateways, servers, network equipment, and other industrial assets.
2. Assess Vulnerability Exposure
Regularly evaluate firmware, software, configurations, exposed services, and known vulnerabilities.
3. Strengthen Network Segmentation
Separate critical OT environments from corporate networks and unnecessary external connectivity.
4. Secure Remote Access
Use strong authentication, least privilege, controlled access paths, monitoring, and time limited permissions.
5. Monitor for Anomalous Activity
Security monitoring should identify unusual network communication, authentication events, configuration changes, and unexpected administrative activity.
6. Test Incident Response
Organizations should have procedures for responding to cyber incidents involving industrial environments.
These plans should account for operational continuity and physical safety rather than focusing exclusively on IT recovery.
7. Conduct OT Security Assessments
Security testing should be performed carefully and within authorized environments so that testing does not disrupt production or create safety risks.
Industries Most Affected
The lessons from this research are particularly relevant to organizations operating industrial and critical infrastructure environments.
Manufacturing
Manufacturers can strengthen PLC, HMI, industrial network, cloud, and enterprise security while reducing the risk of disruption to production operations.
Energy and Utilities
Energy organizations require strong protection for industrial control systems, remote access infrastructure, substations, generation environments, and operational networks.
Water and Wastewater
Water organizations can benefit from OT security assessments, network segmentation, vulnerability management, access control, and continuous monitoring.
Transportation
Transportation operators depend on interconnected control and operational systems that require strong cybersecurity and resilience.
Healthcare
Healthcare organizations increasingly operate building automation, medical devices, connected infrastructure, and critical technology environments that require protection against cyber and physical risks.
Government and Critical Infrastructure
Government agencies and critical infrastructure operators can strengthen OT security, third party risk management, incident response, vulnerability management, and compliance programs.
The Future of Industrial Cybersecurity
The experiment involving AI assisted PLC exploit research provides a broader lesson for cybersecurity leaders.
The question is no longer simply whether AI can help create new attacks.
The more important question is how quickly AI can help transform existing cybersecurity knowledge into techniques that can be adapted to different environments.
Defenders should prepare for this possibility by strengthening the fundamentals.
Strong asset visibility, segmentation, identity security, vulnerability management, monitoring, secure remote access, incident response, and continuous security testing remain essential.
AI should be viewed as another factor changing the threat landscape, not as a replacement for established cybersecurity practices.
Conclusion
The Forescout experiment demonstrates that AI is becoming increasingly relevant to industrial cybersecurity research. While the process of adapting a PLC exploit still required human expertise, the ability of AI to assist with technically specialized work deserves serious attention from organizations operating Operational Technology environments.
As AI capabilities continue to improve, organizations should assume that cybersecurity research and attack development may become faster and more accessible over time.
The best response is not to avoid AI.
It is to strengthen security controls, improve visibility across OT environments, reduce unnecessary exposure, secure remote access, continuously assess vulnerabilities, and build resilient incident response capabilities.
For industrial organizations, cybersecurity must protect both digital systems and the physical processes those systems control.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
In addition, COE Security helps organizations strengthen Industrial Control System and Operational Technology security through OT security assessments, network architecture reviews, vulnerability assessments, penetration testing, secure remote access assessments, segmentation reviews, incident response planning, threat monitoring, and cybersecurity risk assessments.
For manufacturing organizations, COE Security can help protect PLCs, HMIs, industrial networks, connected systems, enterprise applications, and cloud environments while supporting secure operational practices.
For energy and utility organizations, we help strengthen OT security, remote access controls, vulnerability management, network segmentation, monitoring, and cyber resilience.
For water and wastewater organizations, we help assess internet exposed and operational technology environments, strengthen access controls, improve monitoring, and reduce unnecessary attack surfaces.
For transportation organizations, we help secure connected operational systems, industrial networks, applications, cloud infrastructure, and third party technology environments.
For healthcare organizations, we help protect connected infrastructure, applications, cloud environments, medical technology, and sensitive information.
For government and critical infrastructure organizations, we help strengthen OT security, third party risk management, vulnerability management, incident response, compliance readiness, and cybersecurity resilience.
As AI increasingly influences both defensive security and cybersecurity research, COE Security helps organizations evaluate AI related risks, strengthen AI governance, validate security controls, and build security programs designed for evolving cyber threats.
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.
Click to read our LinkedIn feature article