AI is superpowering cyberattacks, but manufacturers can cut their exposure
What you’ll learn:
- In April, the Cybersecurity and Infrastructure Security Agency issued a warning that cyber actors were specifically targeting OT devices, including PLCs.
- AI is changing how easy it is to execute cyberattacks—and not just for new vulnerabilities.
- As AI and autonomous agent technologies continue to evolve, organizations must prepare for threats that are increasingly automated, adaptive and capable of moving faster.
Cyberattacks against industrial operations aren't new, but AI is rapidly changing how quickly attackers can identify targets, find vulnerabilities, and exploit them.
At the same time, manufacturers are taking advantage of connectivity between IT and OT systems, adopting cloud-based tools, and enabling remote access to plant-floor assets.
This level of connectivity is creating new pathways for hackers, providing access points to critical systems such as PLCs, HMIs, drives and other industrial controls.
See also: Ransomware increasing across all metrics in 2026
In April, the Cybersecurity and Infrastructure Security Agency issued a warning that cyber actors were specifically targeting OT devices, including PLCs. Hackers are looking to quickly exploit exposed controllers, poorly segmented networks, or unsecured remote access tools.
As AI-powered threats become more automated and adaptive, manufacturers need to rethink how they secure systems—especially controllers and drives—and keep production running. Understanding how AI elements are supercharging cybersecurity attacks and the necessary steps manufacturers can take to reduce their risk is critical as today’s threat landscape evolves.
AI is making cyberattacks faster, cheaper and more accessible
AI is changing how easy it is to execute cyberattacks—and not just for new vulnerabilities. Elements such as Internet-exposed PLCs, HMI, and remote access gateways; flat OT networks with little segmentation; always-on vendor registration access; and a lack of visibility into who’s talking to controllers all pose significant risks.
For example, attackers are now leveraging AI throughout all phases of the MITRE ATT&CK lifecycle. The MITRE ATT&CK framework is essentially a hacker cheat code for executing an attack throughout various stages.
See also: Has physical AI has gone ‘mainstream’? One new survey says yes
Traditionally, malicious actors spend significant time and resources researching and exploiting vulnerabilities. Today, AI and AI agents have streamlined that entire process by executing tasks automatically with minimal human involvement, achieving in mere hours what it would have taken a team of attackers to do in weeks.
As AI and autonomous agent technologies continue to evolve, organizations must prepare for threats that are increasingly automated, adaptive and capable of moving faster than traditional defenses.
Here are six steps manufacturers can take to reduce their risk as the OT threat landscape changes rapidly:
Align with the right cybersecurity framework
Organizations should start with a recognized cybersecurity framework that provides a structured, risk-based approach to protecting industrial operations.
See also: Growth in IoT sensor market points toward strong momentum for DX
Two of the most widely recognized frameworks are the NIST Cybersecurity Framework (CSF) 2.0 and ISA/IEC 62443. These frameworks complement each other rather than compete. NIST CSF provides executives with guidance for establishing cybersecurity governance, while ISA/IEC 62443 focuses specifically on securing ICS and OT.
This framework provides the roadmap that guides every future cybersecurity decision.
Gain visibility into your assets
Performing an inventory of your assets is a critical part of strong cybersecurity strategy. At a minimum, your organization needs to be able to answer these questions:
- What devices do you have on your network, and where are they located
- Which devices are critical to your operations?
- Is your device firmware up to date?
- Do you have strong passwords for your devices, or are they still set to default?
- If new devices or machines are added to your network, do you get notified
- Can you monitor and identify who’s logging into your network or assets?
- Do you understand the communication flow on your network, and what—or whom—your devices are talking to?
Perform an OT cybersecurity assessment
Once you have a solid understanding of your assets and how they communicate across the plant floor, the next step is assessing your overall cybersecurity posture.
Review your network architecture and document what safeguards you have in place, as well as what communication protocols and ports your devices are using. To underscore how important this is, the recent CISA advisory highlighted specific ports on devices that organizations should look out for.
As AI and autonomous agent technologies continue to evolve, organizations must prepare for threats that are increasingly automated, adaptive and capable of moving faster than traditional defenses.
From there, evaluate any potential risks or vulnerabilities are present and which need to be prioritized and addressed first. If your organization doesn’t have the in-house expertise to perform this step, a trusted partner can help.
Design and establish a DMZ
No single solution or product can protect every asset from cyber incidents. Instead, manufacturers need to take a “defense-in-depth” approach incorporating layers of controls and safeguards.
This includes everything from physical security and access control solutions to firewalls, network segmentation, and endpoint protection. Designing and establishing a “DMZ,” or buffer zone between your IT and OT networks, is critical.
See also: New Darktrace report spotlights growing cybersecurity risks manufacturers face from AI
Where possible, manufacturers should also utilize secure remote access and multifactor authentication to control, manage and verify who’s accessing their network. Although many older machines may not have MFA capability, there are solutions organizations can use to add another layer of security onto these devices.
These tools can allow manufacturers to log who’s accessing or remoting into their machines, monitor what those users are doing, time-limit access and disable it if needed.
Utilize micro segmentation on the plant floor
Once an effective DMZ is established, manufacturers should further strengthen their cybersecurity posture via micro segmentation on the plant floor.
Micro segmentation utilizes virtual local area network to establish logical cell/area zones within the plant floor network. This architecture reduces the attack surface by limiting lateral communication and containing potential cyber threats within a defined cell/zone.
Additionally, make sure that your network switches are both configured and managed. This makes it harder for bad actors to access your network, and makes it more difficult to access devices if your network is compromised.
Conduct regular training for staff
Proper training is vital to preventing cyberattacks—and mitigating the consequences in the event one occurs. Workers should be aware of potential threat vectors, like “phishing,” “vishing” and “smishing,” as well as how to recognize them.
They should also know what to do and who to alert if they receive suspicious emails, links, calls or texts. Many of these trainings may already be implemented on the IT side of the organization.
E-handbook: Cybersecurity
While the goal is always to prevent an attack in the first place, workers should know what to do if a cyber incident occurs. At a minimum, clear backup and disaster recovery policies and processes should be in place. Any cyber assessment and plant health check should ensure that the proper training is in place.
Ensuring a strong cybersecurity posture
Remote locations, varying degrees of readiness and diverse maturity needs require a multi-pronged approach to secure OT networks.
The goal is to reduce exposure, control access, improve visibility into potential vulnerabilities and be able to recover quickly if and when an incident occurs.
While no cybersecurity plan is perfect, a partner can help you fill in any gaps, perform the steps listed above and provide critical expertise if needed.
About the Author

Dan Furrow
Dan Furrow is senior VP and general manager, U.S. industrial, for Wesco, a a global provider of business-to-business distribution, logistics, and supply chain solutions, specializing in electrical, industrial, and communications maintenance products.
