The McCrary Institute for Cyber & Critical Infrastructure Security warned that artificial intelligence is accelerating cyber threats against operational technology (OT) systems supporting critical infrastructure, including power, water and manufacturing. In a Sept. 28 article, Frank Cilluffo and Brad Medairy said AI-enabled threats can help attackers identify vulnerabilities and potential disruption paths faster and with less specialized expertise. Drawing on controlled testing of frontier AI models in OT environments and a September tabletop exercise convened by Booz Allen and Auburn University’s McCrary Institute, the authors highlighted the need for critical infrastructure organizations to reassess security readiness, identify mission-critical assets and dependencies, and test defenses against AI-enabled attacks.
The authors outlined three priorities for strengthening resilience, including assessing readiness, accelerating remediation and response, and preparing to maintain operations during an active compromise.
When it comes to assessing readiness and resilience, the article called upon leaders at critical infrastructure organizations to proactively build a shared understanding of the AI-enabled threat environment and raise awareness beyond cyber teams to include OT operators, the C-suite, boardrooms, and public-affairs teams. They must also identify vital assets and data (crown jewels) and mission-critical dependencies for IT and OT, build a common operating picture, and test cascading consequences of disruptive cyberattacks in the context of critical missions and business operations.
They must also safely pressure-test security controls with realistic, emulated AI threats, and prioritize fixes for foundational controls based on an understanding of the most likely and consequential attack paths. Such exercises must be refreshed continuously as AI capabilities and their related security implications evolve. Additionally, asset owners and operators must look outward to build stronger supply chain risk management as well as actionable information sharing with government and industry stakeholders.
On remediating and responding at machine speed, Cilluffo and Medairy identified that many security processes still depend on people to investigate an alert, make a decision, and take action, which is no longer sufficient because cyber defense now needs to operate at machine speed. They advised fixing priority gaps and controls based on assessments, setting the right foundations using zero trust (ZT) principles, and using AI to emulate advanced threats, pressure test defenses, identify gaps, and build compensating controls.
They also recommended enabling human defenders to use agentic systems to detect, investigate, and contain attacks faster. This involves defining playbooks with a human in the loop and clear baselines on what actions can occur, who can issue them, from where, and under what conditions. Defenders should also monitor for changes in what a system does and prioritize remediation of the attack paths that matter most across systems and supply chains. Finally, they urged enhancing cyber defense with counter AI tradecraft that uses deception to disrupt or misdirect automated attacks.
When it comes to preparing to operate under compromise, Cilluffo and Medairy explained that operating under compromise means maintaining vital business functions and operations amid an active breach, a challenge that security leaders at critical infrastructure organizations need to prepare for as it becomes increasingly likely.
They advised briefing the C-suite and the board on the changing threat environment, underscoring the need to reinforce fundamental controls such as identity and to drive investments aligned to a ZT cybersecurity strategy. Such a strategy is designed to reduce the blast radius, isolate segments, enable AI-driven defensive cyber operations, protect crown jewels and critical functions, and support incident response and resilience planning.
They also urged organizations to seize opportunities to use AI to both pressure test security controls and uncover and manage risks tied to the use of AI within the enterprise. Organizations should understand internal and external dependencies, establish manual or alternate operating paths, and regularly test and update incident response, enterprise risk management, and resilience plans under degraded conditions. Finally, they stressed the need to clarify decision rights across organizational boundaries.
“The need to strengthen the security and resilience of OT is top of mind at the Department of War and the Cybersecurity and Infrastructure Security Agency,” Cilluffo and Medairy wrote. “Critical infrastructure companies that seize the opportunity to take action can maximize uptime and their ability to sustain critical operations under pressure. Organizations that don’t take the initiative, however, run the risk of falling further behind.”


