blog hero

Cybersecurity Blog

Stay updated on the latest trends and insights in cybersecurity.

Date: 8/8/2026

OT Security

AI Is Changing the Attacker. Why IEC 62443 Matters More Than Ever

AI lowers the expertise, time and cost needed to attack an industrial environment. Why ISA/IEC 62443 architecture, zones and Security Levels matter more than ever in OT.

AI Is Changing the Attacker. Why IEC 62443 Matters More Than Ever

TL;DR

AI is lowering the expertise, time and cost an attacker needs to understand an industrial environment. That does not make ISA/IEC 62443 obsolete. It makes weak architecture more dangerous, and it makes delay more expensive.

Industrial cybersecurity has always been different.

In IT, a security incident can compromise systems, identities and data. In operational technology, a security incident can stop production, affect availability and, in the wrong circumstances, have physical or safety consequences.

That is why ISA/IEC 62443 matters. For more than two decades, the standard has provided a structured way to secure Industrial Automation and Control Systems.

But the environment around the standard is changing. Artificial intelligence is increasing the speed at which attackers can analyse systems, process technical information, discover weaknesses and build attack capability.

At the same time, AI is entering industrial operations through predictive maintenance, anomaly detection, machine vision, engineering support and optimisation. The industrial environment is becoming smarter. It also needs to become more resilient.

The attacker does not need to become an OT expert

Industrial environments have traditionally benefited from complexity.

  • Understanding an unfamiliar plant takes time.
  • Finding the right systems takes time.
  • Understanding industrial protocols takes time.
  • Interpreting engineering documentation takes time.
  • Recognising which systems actually matter to the physical process requires specialist knowledge.

That friction has always helped defenders. AI is beginning to reduce it.

An attacker can use AI to analyse documentation, interpret network information, generate code and make sense of technologies they do not fully understand.

This does not mean that autonomous AI is suddenly taking control of factories. That would be an unnecessary exaggeration.

The more immediate problem is simpler. AI reduces the amount of expertise, time and effort required to attack a complex environment. That matters enormously in OT.

Security Levels deserve renewed attention

IEC 62443 Security Levels distinguish between different levels of attacker capability, resources, skills and motivation. That model remains useful.

But one assumption deserves renewed attention: specialist capability is becoming cheaper. An attacker who previously lacked industrial knowledge can increasingly augment that capability using AI, readily available tooling and public technical information.

That does not mean every industrial system suddenly requires the highest Security Level. IEC 62443 should remain risk based. But organisations should challenge older assumptions.

If a Target Security Level was established because a certain attack required scarce specialist knowledge, is that assumption still valid today? That is the question that matters.

When attacks accelerate, architecture becomes more important

The answer is not to abandon IEC 62443. The answer is almost the opposite. Some of its strongest principles become even more important when attackers become faster.

  • Zones.
  • Conduits.
  • Restricted data flow.
  • Identity and access control.
  • Least privilege.
  • System integrity.
  • Monitoring.
  • Secure remote access.
  • Defence in depth.

A vulnerable engineering workstation should not automatically provide access to every PLC. A compromised enterprise identity should not automatically open a path into production. A supplier connection should not automatically become a trusted route through the industrial environment.

Good architecture limits what an attacker can reach before an incident even starts. That matters because organisations cannot assume their defenders will always react faster than automated attack tooling.

When the attacker operates at machine speed, architecture must create boundaries before humans need to intervene.

AI is also entering OT from the inside

There is another reason IEC 62443 is becoming more important. AI is not only changing the threat. AI is becoming part of the industrial environment itself.

Consider predictive maintenance. Sensor data is used to estimate whether equipment can continue operating safely and reliably. That can reduce downtime and improve maintenance planning. But it also creates new dependencies.

  • What happens if the underlying data is manipulated?
  • Who can access the system?
  • Can an attacker influence the data flow?
  • Where does the model run?
  • What happens when its recommendation is wrong?
  • And how much authority should an organisation give that recommendation?

Some of these are cybersecurity questions. Others are questions about AI governance, assurance and safety. That distinction will become increasingly important.

IEC 62443 helps protect the industrial environment in which these technologies operate. Frameworks such as ISO/IEC 42001 address a different question: how organisations govern the AI systems they develop and use. Industrial organisations increasingly need to understand both.

Compliance is not the objective

IEC 62443 should never become a documentation exercise. The real questions are operational.

  • Can an attacker move from IT into OT?
  • Which assets can communicate?
  • Who can modify PLC logic?
  • How is remote access controlled?
  • What happens when an engineering workstation is compromised?
  • Can abnormal industrial communication be detected?
  • How quickly can part of the environment be contained?
  • And what happens when cybersecurity, availability and safety requirements conflict?

The answers determine industrial resilience. IEC 62443 gives organisations a structured way to find those answers.

AI does not make IEC 62443 obsolete

AI changes the speed and economics of cyber attacks. It does not make industrial security architecture irrelevant. It makes weak architecture more dangerous.

The fundamentals remain remarkably consistent.

  • Know your assets.
  • Understand your risks.
  • Define your zones.
  • Control your conduits.
  • Protect identities.
  • Secure remote access.
  • Monitor industrial communication.
  • Prepare for incidents.
  • Build cybersecurity into the industrial lifecycle.

Those principles were important before generative AI. They are more urgent now. AI is not replacing IEC 62443. It is increasing the cost of delaying its implementation.

From understanding IEC 62443 to implementing it

Understanding the standard is one thing. Implementing it inside a real industrial environment is another.

From 2 to 6 November 2026, CyberBusters is delivering the official PECB ISA/IEC 62443 Lead Implementer training in person in Lelystad, the Netherlands. The programme focuses on translating the ISA/IEC 62443 series into an operational IACS cybersecurity programme, including industrial risk, Security Levels, security controls, governance, supply chain security, patching, monitoring and incident response.

PECB ISA/IEC 62443 Lead Implementer

Five days in Lelystad, 2–6 November 2026. From the standard to a working IACS cybersecurity programme.

View the training

What happens when AI becomes part of the process itself?

Securing the environment is only one side of the equation. As AI enters industrial operations through predictive maintenance, engineering support, anomaly detection and optimisation, organisations also need to determine how that AI should be governed, validated and audited. That is where ISO/IEC 42001 becomes increasingly relevant.

PECB ISO/IEC 42001 Lead Auditor

Audit the management system behind the AI your organisation develops and uses.

Explore the training

Related articles