Artificial intelligence isn’t just transforming how we work—it’s quietly reshaping the threat landscape for operational technology (OT) in ways many organizations aren’t fully prepared for.
AI has dramatically lowered the barrier to entry for cyber threats. What once required skilled human operators can now be executed faster and more efficiently by machines.
- Automated exploit development: AI can analyze vulnerability disclosures and generate working exploit code in minutes.
- Self-directed attacks: AI systems can perform reconnaissance, identify vulnerabilities, move laterally, and exfiltrate data—before a human even intervenes.
- Machine-speed execution: Attacks happen in milliseconds, far outpacing human response times.
The Hidden Risk: Indirect AI Exposure
- Uploading sensitive data (e.g., network diagrams) into AI tools
- Using AI to generate automation scripts or PLC configurations
- Leveraging AI-powered assistants or browsers that may elevate permissions
When AI Gets It Wrong: The Risk of Hallucinations
- Incorrect PLC settings
- Faulty safety thresholds
- Automated actions that disrupt physical systems
Why OT + AI Is a Perfect Storm
- Legacy infrastructure
- Flat network architectures
- Slow human-driven response cycles
- Perform reconnaissance in milliseconds
- Move laterally without credentials
- Constantly mutate to evade detection
The Myth of Defensive AI
- Immature deployment in OT environments
- Continued reliance on detection and response models
- Inability to adapt as quickly as offensive AI
What Actually Works Today: A Shift in Strategy
- Assume Breach: Operate under the expectation that: Credentials will be compromised, Users will make mistakes and AI agents will behave unpredictably
- Eliminate Discoverability: If attackers can’t find your network: Reconnaissance fails, Automation breaks, and Opportunistic attacks move on
- Stop Lateral Movement: Most OT attacks originate in IT environments and spread internally. Breaking that pathway collapses the attack chain.
- Enforce Human-in-the-Loop Validation: AI can steal credentials—but it cannot: Perform physical authentication, Pass out-of-band validation, Meet device-bound access requirements. This is one of the few areas where humans still have a decisive advantage.
Why This Matters for Federal and Military Environments
- Mission assurance
- Continuity of operations
- Critical infrastructure resilience
- Operational safety
From Theory to Execution: Operationalizing Zero Trust
- Translate zero trust from policy into practice
- Reduce attack surfaces
- Segment IT and OT environments
- Implement controls that AI cannot bypass
The BLUF
Organizations that succeed in the age of AI won’t try to outmatch attackers with more AI. They’ll design systems where:
- Networks are hard to discover
- Access is tightly controlled
- Lateral movement is impossible
Synopsis
This episode focuses on AI as an indirect, increasingly automated threat to operational technology (OT). Drawing on a Blastwave webinar, it argues that offensive AI can rapidly exploit or even generate vulnerabilities, making “patch and pray” and human-speed detection/response inadequate for OT environments where mistakes can cause real-world safety impacts. We highlights risks from indirect AI exposure such as accidental data sharing, AI-generated scripts or PLC configurations, and hallucinations that can produce unsafe settings. It emphasizes fundamentals that scale against AI: assume breach, prevent discovery, stop IT-to-OT lateral movement, and use human-in-the-loop authentication and zero trust controls, positioning Blastwave and ATPGov as partners to operationalize these measures.
- 00:00 Introduction
- 00:38 AI Threat To OT
- 02:10 Machine Speed Attacks
- 03:13 Indirect AI Exposure
- 04:50 OT And AI Storm
- 06:10 Why Defense AI Lags
- 06:39 Zero Trust Fundamentals
- 07:53 Blastwave In Practice
- 08:35 Bottom Line Recap
- 09:14 Next Steps And Outro
This episode is brought to you by ATP Gov. Visit us online at www.atpgov.com or follow us on LinkedIn.
Transcript
[00:00:00] Host: Welcome to The Bottom Line Up Front, the podcast that cuts through the noise to deliver distilled insights from today’s most important technical webinars, presentations, and demonstrations. Designed for federal and military IT leaders, each episode breaks down complex technologies into mission-ready takeaways so you get the key points fast.
Whether it’s cybersecurity, cloud architecture, or emerging defense technologies, we highlight what matters most and how trusted integrators like ATPGov can help implement and operationalize these solutions across your agency or command. No fluff, no filler, just the bottom line up front. Today’s episode is all about AI as an indirect threat to operational technology.
Not the Hollywood version of Skynet, but the subtle, accidental, and increasingly automated ways AI is already creating risk inside of federal and military networks. We’ll return to the world of OT security in a recent industry webinar from Blastwave focused on AI-enabled [00:01:00] threats and what actually works right now, not five years from now, to protect mission-critical systems.
[00:01:06] Cam Cullen: For anyone who understands security products, uh, at all, uh, should scare the you know what out of you. It used to be AI was really good at if someone found a v- a zero day and even put out a description of it, they could figure out how to exploit that. In fact, there was a study a while back which showed that if you fed ChatGPT the description of an exploit that was in a CVE notification, within 10 minutes it could figure out how to exploit that and actually coded it and, and figured it out.
So now it’s not just taking advantage of ones that are, are known or discovered, it can create its own and find them. So patch and pray is no longer going to work.
[00:01:42] Host: As discussed previously, AI isn’t just an IT problem. AI is being weaponized against OT and federal infrastructure, mostly without human operators, while defensive AI is still playing catch-up.
[00:01:55] Cam Cullen: So a- and basically that is no longer acceptable to expect a [00:02:00] human to be the one to, to fix this. So we don’t need to react faster. We wanna make the attack impossible or at least hard to start, and we’ll talk about kind of that in a bit as well.
[00:02:10] Host: This isn’t theoretical. The technology curve is currently upside down because offensive AI is fast, automated, and already in use, and defensive AI is promising, but not operationally mature for OT environments.
Moreover, humans simply cannot react fast enough to machine-speed attacks. And for federal and military audiences, this directly impacts mission assurance, continuity of operations, and national critical infrastructure protection
[00:02:36] Cam Cullen: You know, OT operators are today not ready at all to allow automated responses.
So it doesn’t know if I change the settings of the PLC or I turn it off, it’s gonna make a, a reactor blow or a water pipe open and, and flood the dam es- essentially. But the gap between that 200 millisecond ma- machine speed attack and 20 minutes for the system to detect a problem, alert the human, the human to try and [00:03:00] process if it’s a problem, ask about the settings, figure out what they’re doing, in 20 minutes all your data’s gone.
It could have turned off all the systems. So basically that is no longer acceptable to expect a human to be the one to, to fix this. So
[00:03:14] Host: So what makes AI so different this time? Most security leaders focus on phishing, deepfakes, and malware generation. Those are real, but not the most dangerous part. The real risk is indirect AI exposure, which includes accidental AI misuse.
That’s the uploading of network diagrams into AI tools, asking AI to generate automation scripts or PLC configs, and using AI-powered browsers or agents to elevate permissions. What that means for you now is that your asset inventories, network topology, and operating procedures exist outside of your control.
[00:03:48] Cam Cullen: Anyone that has used AI even a little bit has seen a hallucination in terms of, okay, the answer to this question is X, and you know that no, the Earth is not [00:04:00] flat. But the AI, for whatever reason, either it doesn’t know the answer, it looked to the wrong site and gave it authority for the wrong reason and someone tweaked it, uh, and caused an issue, or it doesn’t know the answer and just doesn’t wanna let you down, which is what they found some of these AIs will do.
Ask it, for example, “What’s the safe procedure for updating a PLC?” And it says, um, five. And you, you put five in and suddenly it turns off the safety system or exceeds the safety parameters. So hallucination is something that we should be aware of.
[00:04:32] Host: Additionally, AI hallucination and automation, as we know, confidently provides wrong answers and automates actions without understanding physical consequences.
But in OT terms, that means the wrong PLC settings, incorrect safety thresholds, and automated click-on-shutdown procedures. That’s not a cyber incident, that’s a real-world impact event So let’s address why OT and AI is the perfect storm. OT environments already struggle with legacy [00:05:00] systems, flat networks, and long human response times.
Now combine that with AI-driven attacks that perform reconnaissance in milliseconds, move laterally without credentials, and mutate to evade signature-based detections means that alerting that once relied on humans is exponentially slower and the fight is already lost. Because detection takes minutes, triage takes even longer, and response intervals involve manual validation.
[00:05:23] Cam Cullen: Real examples of what I’m talking about have already hit the wor- real world, and the cloud-powered attack that came out a while back. Essentially, a human operator provided a target to the, to the cloud system and pointed a target. It gathered the data with reconnaissance, conducted vulnerability scan of the systems, went out and harvested credentials, exploited these vulnerabilities, laterally moved within the network, exfiltrated data, and essentially presented to the human operator, “Here you go.
Here’s all the information, all the data. Here’s the vulnerabilities. Tell me what you want me to do, and set the ransom.” And so essentially, the human [00:06:00] didn’t have to get involved until the attack was essentially done.
[00:06:03] Host: So when you look back at an incident, AI-powered attackers have already finished the job before you realize it.
But there’s a bigger misconception that defensive AI will save us in the future. Yes, defensive AI will matter eventually, but today it’s incomplete, it’s immature for operational technology, and it still relies on detection and response. Detection-only models fail because AI attacks adapt faster than signatures do, malware rewrites itself, and behavior shifts to bypass controls.
So the real question becomes, how do you make attacks harder to start in the first place? Blastwave’s webinar returned us to fundamentals that do scale against AI. The first being assume that there’s a breach. This isn’t pessimism, it’s realism. You have to plan as if credentials will be stolen, a user will click the wrong thing, and an AI agent will behave unexpectedly.
But we do have to eliminate the ability for [00:07:00] discovery. If attackers, human or AI, can’t find the network, that means reconnaissance fails, automation breaks, and drive-by attacks just move on. We also have to kill lateral movement. Most real-world OT incidents start in IT and move laterally into OT networks, and if that path doesn’t exist, then the attack completely collapses.
And remember, we need to include human-in-the-loop authentication. AI can steal credentials, but it cannot physically authenticate complete out-of-band validation or pass device-bound access checks. And for federal and military environments, this isn’t just about cybersecurity. This is about mission readiness, critical infrastructure resilience, operational safety, and zero trust applied to real systems Because the gap exists in the execution of these systems, and standards and frameworks already exist to help us get there.
And that’s where Blastwave comes into the conversation, not as a vendor pitch, but as a force multiplier. Blastwave’s [00:08:00] products translate zero trust from policy to the plant floor. They integrate modern access, segmentation, and visibility without disrupting operations. Blastwave also helps agencies and commands reduce attack surfaces, close IT to OT fast lanes, and implement human-centric controls that AI can’t bypass.
We’ve seen Blastwave help organizations move from, “We know what the problem is,” to, “This is how we operationalize the fix.” And that distinction matters. Because AI isn’t coming, it’s already here. It’s already automated, and it’s already being used against operational environments. So what’s the bottom line up front?
The organizations that win won’t try to out-AI the attacker. They’ll design systems that don’t give them room to operate. Because AI isn’t just an external attacker, it’s already inside your workflows. OT security models that rely on detection and response alone cannot keep up with AI-enabled threats.
And using tools like Blastwave that make networks hard to find, hard to access, and hard to move [00:09:00] laterally between breaks AI automation completely, while human-in-the-loop zero trust controls remain one of the few things AI cannot bypass. And finally, integration matters more than the products, and that’s where Blastwave adds strategic value.
So if you wanna dig deeper into this topic or understand how the partnership between Blastwave and ATPGov helps agencies operationalize zero trust for OT and mission systems, reach out or check the follow-on article on our website for more details. Be sure to reach out to ATPGov today at www.atpgov.com or email info@atpgov.com or check us out on social media on LinkedIn.
Thanks for listening, and be sure to subscribe to The Bottom Line Up Front wherever you get your podcasts. And stay tuned for more distilled insights from the front lines of tech and national security. So until next time, stay secure, stay mission
ready.
About this Podcast
The Bottom Line Up Front, is ATP Gov’s podcast that cuts through the noise to deliver distilled insights from today’s most important technical webinars, presentations and demonstrations designed for federal and military IT leaders. Each episode breaks down complex technologies into mission ready takeaways, so you get the key points.
Fast.
Whether it’s cybersecurity, cloud, architecture, or emerging defense technologies, we highlight what matters most and how trusted integrators like ATP Gov can help implement and operationalize these solutions across your agency or command.
No fluff. No filler, just the bottom line up front.