blog hero

Cybersecurity Blog

Stay updated on the latest trends and insights in cybersecurity.

Date: 8/8/2026

OT Security

AI Is Changing the Attacker. Why IEC 62443 Matters More Than Ever

AI lowers the expertise, time and cost needed to attack an industrial environment. Why ISA/IEC 62443 architecture, zones and Security Levels matter more than ever in OT.

AI Is Changing the Attacker. Why IEC 62443 Matters More Than Ever

TL;DR

AI is reducing the expertise, time and cost required to understand and target an industrial environment. That does not make ISA/IEC 62443 obsolete. It makes weak architecture more dangerous, and it makes delay more expensive.

Industrial cybersecurity has always been different.

In IT, a security incident can compromise systems, identities and data. In operational technology, a security incident can stop production, affect availability and, in the wrong circumstances, have physical or safety consequences.

That is why ISA/IEC 62443 matters. For more than two decades, the ISA/IEC 62443 series has provided a structured way to secure Industrial Automation and Control Systems.

But the environment around the standard is changing. Artificial intelligence is increasing the speed at which attackers can analyse systems, process technical information, discover weaknesses and build attack capability.

At the same time, AI is entering industrial operations through predictive maintenance, anomaly detection, machine vision, engineering support and optimization. The industrial environment is becoming smarter. It also needs to become more resilient.

The attacker does not need to become an OT expert

Industrial environments have traditionally benefited from complexity.

  • Understanding an unfamiliar plant takes time.
  • Finding the right systems takes time.
  • Understanding industrial protocols takes time.
  • Interpreting engineering documentation takes time.
  • Recognising which systems actually matter to the physical process requires specialist knowledge.

That friction has always helped defenders. AI is beginning to reduce it.

This is already visible in practice. In 2026, Dragos documented an intrusion against a municipal water utility in which commercial AI models supported reconnaissance, enumeration, exploitation, lateral movement and tooling development. The AI also identified OT-adjacent infrastructure and investigated possible paths towards the operational environment. The OT environment was not successfully breached, but the case demonstrated something important: AI can reduce the expertise and time required to identify and target industrial infrastructure.
Source: https://www.dragos.com/blog/ai-assisted-ics-attack-water-utility

An attacker can use AI to analyse documentation, interpret network information, generate code and make sense of technologies they do not fully understand.

This does not mean that autonomous AI is suddenly taking control of factories. That would be an unnecessary exaggeration.

The more immediate problem is simpler. AI reduces the amount of expertise, time and effort required to attack a complex environment. That matters enormously in OT.

Security Levels deserve renewed attention

IEC 62443 Security Levels describe increasing resistance against adversaries with greater capability, resources, skills, and motivation. The model remains useful, but AI is changing some of the assumptions behind attacker capability.

Specialist capability is becoming easier and cheaper to acquire. An attacker who previously lacked industrial knowledge can increasingly augment that capability using AI, readily available tooling and public technical information.

This does not mean every industrial system suddenly requires the highest Security Level. The application of IEC 62443 should remain risk-based. But organizations should challenge assumptions made when Target Security Levels were originally established.

If a Target Security Level was based partly on the assumption that a particular attack required scarce specialist knowledge, is that assumption still valid today? That is the question that matters.

When attacks accelerate, architecture becomes more important

The answer is not to abandon IEC 62443. The answer is almost the opposite. Some of its strongest principles become even more important when attackers become faster.

  • Zones.
  • Conduits.
  • Restricted data flow.
  • Identity and access control.
  • Least privilege.
  • System integrity.
  • Monitoring.
  • Secure remote access.
  • Defence in depth.

A vulnerable engineering workstation should not automatically provide access to every PLC. A compromised enterprise identity should not automatically open a path into production. A supplier connection should not automatically become a trusted route through the industrial environment.

Good architecture limits how far an attacker can move before defenders even know an intrusion is underway. As attack cycles become increasingly automated and compressed, architecture must create boundaries before humans need to intervene.

As attack cycles become increasingly automated and compressed, architecture must create boundaries before humans need to intervene.

AI is also entering OT from the inside

There is another reason IEC 62443 is becoming more important. AI is not only changing the threat. AI is becoming part of the industrial environment itself.

Consider predictive maintenance. Sensor data is used to estimate whether equipment can continue operating safely and reliably. That can reduce downtime and improve maintenance planning. But it also creates new dependencies.

  • What happens if the underlying data is manipulated?
  • Who can access the system?
  • Can an attacker influence the data flow?
  • Where does the model run?
  • What happens if the underlying data is manipulated?
  • And how much authority should an organization give that recommendation?

Some of these are cybersecurity questions. Others are questions about AI governance, assurance and safety. That distinction will become increasingly important.

IEC 62443 helps protect the industrial environment in which these technologies operate. Frameworks such as ISO/IEC 42001 address a different question: how organizations govern the AI systems they develop and use. Industrial organizations increasingly need to understand both.

Compliance is not the objective

IEC 62443 should never become a documentation exercise. The real questions are operational.

  • Can an attacker move from IT into OT?
  • Which assets can communicate?
  • Who can modify PLC logic?
  • How is remote access controlled?
  • What happens when an engineering workstation is compromised?
  • Can abnormal industrial communication be detected?
  • How quickly can part of the environment be contained?
  • And what happens when cybersecurity, availability and safety requirements conflict?

The answers determine industrial resilience. IEC 62443 gives organizations a structured way to find those answers.

AI does not make IEC 62443 obsolete

AI changes the speed and economics of cyber attacks. It does not make industrial security architecture irrelevant. It makes weak architecture more dangerous.

The fundamentals remain remarkably consistent.

  • Know your assets.
  • Understand your risks.
  • Define your zones.
  • Control your conduits.
  • Protect identities.
  • Secure remote access.
  • Monitor industrial communication.
  • Prepare for incidents.
  • Build cybersecurity into the industrial lifecycle.

Those principles were important before generative AI. They are more urgent now. AI is not replacing IEC 62443. It is increasing the cost of delaying its implementation.

From understanding IEC 62443 to implementing it

Understanding the standard is one thing. Implementing it inside a real industrial environment is another.

From 2 to 6 November 2026, CyberBusters is delivering the official PECB ISA/IEC 62443 Lead Implementer training in person in Lelystad, the Netherlands. The programme focuses on translating the ISA/IEC 62443 series into an operational IACS cybersecurity programme, including industrial risk, Security Levels, security controls, governance, supply chain security, patching, monitoring and incident response.

PECB ISA/IEC 62443 Lead Implementer

Five days in Lelystad, 2–6 November 2026. From the standard to a working IACS cybersecurity programme.

View the training

What happens when AI becomes part of the process itself?

Securing the environment is only one side of the equation. As AI enters industrial operations through predictive maintenance, engineering support, anomaly detection and optimization, organizations also need to determine how that AI should be governed, validated and audited. That is where ISO/IEC 42001 becomes increasingly relevant.

PECB ISO/IEC 42001 Lead Auditor

Audit the management system behind the AI your organization develops and uses.

Explore the training