Nozomi’s Plante says CISOs must rethink OT and IoT security as old models fail converged industrial environments


SOURCE: INDUSTRIALCYBER.CO
JUN 25, 2026

CISOs operating across OT and IoT environments are being urged to reassess cybersecurity priorities as industrial attack surfaces expand and threat actors become more persistent, stealthy, and operationally embedded. In this context, Nozomi Networks highlights that traditional security assumptions no longer hold in environments where IT, OT, and IoT converge, forcing security leaders to shift from perimeter-focused defense models toward continuous visibility and risk-driven decision-making across cyber-physical systems. Clearly, growing complexity of industrial networks, combined with increasingly targeted intrusion activity, is pushing organizations to prioritize asset discovery, anomaly detection, and contextual threat intelligence as foundational elements of resilience in critical infrastructure environments.

“The weaponization of Mythos and other frontier AI does not create a new OT/IoT security problem. It changes the economics and timeline of exploitation,” Michael Plante, chief marketing officer at Nozomi, wrote in a Wednesday blog post. “Attackers have long used automation, exploit kits and vulnerability intelligence to accelerate attacks. What’s changing now is the speed and scale with which frontier AI models can help adversaries discover weaknesses, understand unfamiliar code, generate exploit logic, chain vulnerabilities, adapt tooling and move from disclosure to exploitation.”

Traditional IT guidance often emphasizes scanning faster, patching faster, and increasing automation. While these practices remain important, they do not map neatly onto OT and IoT environments, where industrial systems, embedded devices, remote assets, and critical infrastructure operate under strict uptime requirements, safety constraints, OEM dependencies, legacy protocols, long asset lifecycles, and limited tolerance for untested change. In this context, the strategic priority for CISOs is not speed alone but reducing an attacker’s ability to turn newly discovered weaknesses into operational disruption.

Plante provides the industry with 10 recommendations designed to accelerate OT and IoT security outcomes and clarify why conventional IT approaches must be adapted for industrial environments.

CISOs should treat continuous visibility across OT and IoT as a strategic control rather than a hygiene task. Large enterprises need complete awareness of assets, software and firmware, communication paths, exposure, vendor dependencies and operational impact across industrial controllers, HMIs, engineering workstations, network devices, remote access systems, embedded devices, wireless infrastructure, building systems and industrial IoT environments. The key test is whether an organization can rapidly determine exposure, reachability and business impact when a new vulnerability or advisory emerges. In OT and IoT environments, unknown assets can represent safety, uptime and continuity risks, especially where legacy protocols and non-standard systems limit traditional discovery approaches.

Security prioritization should move beyond vulnerability severity scores and focus instead on operational consequences. Risk decisions must reflect safety impact, environmental damage, production disruption, equipment failure, service interruption, regulatory exposure and business continuity. Organizations are advised to define operational ‘crown jewels’ and build explicit resilience strategies around the systems and processes whose compromise would cause the most severe physical or operational impact. In OT and IoT environments, risk is defined less by data sensitivity and more by the potential to stop production or endanger physical systems.

CISOs are also encouraged to assume that prevention and detection alone will not always be sufficient as threat timelines compress. Critical processes should be engineered to fail safely, degrade gracefully and recover quickly, with validated fallback modes, safe-state definitions, known-good baselines and rehearsed restoration procedures. Resilience is defined by the ability to maintain safety and continuity of physical operations under compromised conditions, not just the ability to restore data or systems.

Vulnerability management should combine patching, where feasible, with aggressive exposure reduction where it is not. Many OT and IoT assets cannot be patched quickly or safely, making connectivity reduction, segmentation, hardened remote access, strict identity controls and lateral movement prevention essential. The focus shifts from simply identifying vulnerabilities to determining whether they are reachable, exploitable and capable of impacting operational processes. In parallel, segmentation and isolation are positioned as primary controls for systems that cannot be patched for extended periods, limiting blast radius and preventing localized issues from escalating into enterprise-wide disruption.

In a message for CISOs, CIOs, and boards, Plante said that the weaponization of frontier AI changes the tempo of cyber risk. It does not change the fundamentals of OT/IoT defense. “The organizations best positioned for this new era will not be those with the most AI hype. They will be those that know their operational assets, understand their exposure, control access pathways, segment critical environments, detect abnormal behavior, prioritize by operational consequence, work effectively with OEMs, and maintain resilience when patching cannot happen fast enough.”

He added that “In OT and IoT security, the winning strategy is not simply faster remediation. It is faster understanding, faster exposure reduction, faster containment and greater operational resilience.”

Earlier this week, the ‘Five Eyes’ global cybersecurity agencies issued a joint warning that AI (artificial intelligence) is rapidly reshaping cyber threat landscape, arguing that the timeline for disruptive AI-enabled cyber capabilities is now measured in months, not years. In a statement published by the Australian Cyber Security Centre, the alliance said frontier AI models are accelerating the speed, scale and sophistication of attacks, shrinking the window between vulnerability discovery and exploitation while simultaneously offering defenders powerful new tools to improve resilience.

Anna Ribeiro

Industrial Cyber News Editor. Anna Ribeiro is a freelance journalist with over 14 years of experience in the areas of security, data storage, virtualization and IoT.