This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

❝

Disclaimer: All views presented here, in this newsletter, are my own, or are either researched using internet and AI (using LLMs) search and referenced accordingly.

Author or the newsletter are not liable for any actions taken by any individual or any organization / business / entity. The information provided is for information, education and awareness purposes only and is not specific to any business and or situation.

This publication does not constitute legal, regulatory, or professional advice.

M. Yousuf Faisal

Hi Securing Things family,

Hope you are doing well and had a great weekend.

Let me start with one question.

Who approved the AI that's running in your plant today?

If your honest answer is "IT," "the vendor," or "I'm not sure", this edition is for you.

β†ͺ️ In this newsletter edition ✍️ we cut through the hype on AI in OT / Industry 4.0 / industrial manufacturing. No jargon walls.

Whether you're new to OT or you've been in control rooms for 20 years, you'll leave with a clear picture and a plan.

  • 🧠 What "AI in the plant" actually means (3 kinds, 3 analogies)

  • πŸšͺ The three doors AI uses to enter your OT

  • 🧨 Five myths that could cost you a shutdown

  • 🚦 A walk up the Purdue model: green, amber & red zones for AI

  • ⚠️ Six new failure modes, with plant-floor examples

  • 🌍 What US, EMEA and APAC regulators are saying right now

  • βœ… A 7 Step plan for CISOs + 7 questions for your vendors.

Companion resources: this edition comes with basic list of action items below and an upcoming live webinar. Think of it this way:

  • the newsletter is the map.

  • the webinar/podcast is the walk.

Same topic, different depth, no repeats (well some recap). registration link below.

But before we begin, do me a favor and make sure you β€œSubscribe” to let me know that you care and keep me motivated to publish more. Thanks!

Ready? let’s dig in.

Yours truly.

β€” Yousuf.

♻️if you know someone in your professional circle who will benefit from these resources and interested in learning. Thanks 🌟

Note; in the previous two editions we’ve covered awareness across:

β†ͺ️Prove it - ISA Secure ACSSA (Automation Control System Security Assurance) certification for Asset Owner – I’d like to thank you those you joined our webinar live and those that register to view recordings. In case you missed, go to above link to watch the recording.

β†ͺ️EU AI Act is about Trust, Not AI - 31 days of EU AI Act Awareness series.

Covered below - once you register with your e-mail, you can access for free:

🎯 The 60-Second Version

(For the CISO who has a board meeting in ten minutes.)

  • AI is already inside most industrial environments. It mostly arrived through vendors, not projects.

  • The value is real: fewer breakdowns, better quality, lower energy use, captured expertise.

  • But AI adds new ways to fail that classic OT controls don't cover: drift, poisoned data, prompt injection and over-trust.

  • One rule keeps you safe: AI advises. Deterministic controls and humans decide. Read-only by default.

  • Regulators are converging on the same message. The EU delayed some AI Act deadlines, but delayed is not cancelled.

  • Your first move is not a new tool. It's finding the AI you already have.

🧠 First, What Do We Mean by "AI"?

"AI" is a word doing too much work. In a plant, it means three very different things. Here they are as three people you might already know.

1. Classic machine learning: the experienced night-shift technician.

They've seen a thousand pump failures. They walk past and say, "That vibration doesn't sound right." Machine learning learns patterns from history and spots what's unusual.

Where you'll see it: predictive maintenance, camera-based quality inspection, energy optimization.

2. Generative AI (LLMs): the brilliant intern.

They've read every manual ever written. They answer instantly. And they will confidently answer even when they're wrong.

Where you'll see it: searching SOPs, summarizing shift logs, drafting work orders, explaining alarms in plain language.

3. Agentic AI: the intern, now with a badge and a laptop.

Same intern, but now they can do things: open tickets, call other systems, change settings. Highest value. Highest risk.

Here's the pattern to remember:

The closer AI moves from advice to action, the more your risk grows. Most of what follows in this newsletter is just that idea, applied.

SPONSOR

Analytics on Live Data Without Leaving Postgres

When analytics on Postgres slows down, most teams add a second database. Then come the pipelines, the sync jobs, and a copy of your data that's always a little behind.

TimescaleDB takes a different approach: extend Postgres instead of splitting away from it. Hypertables partition your data automatically as volume grows. Hypercore compression cuts storage up to 95%. Continuous aggregates keep dashboards live without re-querying everything.

CERN runs Postgres this way for sensor data from the Large Hadron Collider.

No split architecture, no pipeline lag, no new query language to learn. Same SQL, same drivers, same tools.

Start on Tiger Cloud and get $1000 in credits.

SPONSOR

For Deel's "Feeling of Deeling" campaign, agency SuperBloom used Branded AI Voice for one consistent brand voice across markets, without sacrificing quality or consent. Watch the Recording.

πŸšͺ The Three Doors AI Uses to Enter Your OT

Most CISOs I speak with know about one door. There are three.

Door 1πŸšͺ: The front door (vendors ship it)

Your SCADA, historian, MES, or OT monitoring vendor adds an "AI assistant" in the next release. You didn't buy AI. You upgraded. And nobody in security was in the room.

Door 2πŸšͺ: The side door (your teams build it)

A data science pilot pulls years of historian data into a cloud platform to predict failures. Good project. Sensible goal. But now your process data lives somewhere new, on a pipeline nobody threat-modeled.

Door 3πŸšͺ: The back door (shadow AI)

A well-meaning engineer pastes an alarm log, a P&ID description, or a chunk of ladder logic into a public chatbot to "save an hour." Your process IP just left the building.

"But how many plants are actually using AI?"

Depending on who you ask, the answer swings wildly. A 2026 Fluke survey found predictive maintenance adoption doubled to 18%. An RSM survey of 129 middle-market manufacturers found 88% had AI at least partially integrated. MaintainX reports roughly a third of maintenance teams have implemented AI, with about two-thirds planning to.

These numbers aren't contradicting each other. They're measuring different things. Your exposure isn't defined by any survey. It's defined by what's actually running in your plant.

(Note: these are vendor and consultancy surveys, so read them as directional, not gospel.)

🧨 Five Myths That Could Cost You a Shutdown

Myth 1: "AI is going to run our plant."

Reality: Today, most AI in OT is decision support. It recommends, flags and summarizes. That's a feature, not a flaw. The joint international guidance we'll look at below is clear that humans must stay in the loop, and that LLMs shouldn't be making safety decisions in OT.

Myth 2: "We're air-gapped, so AI can't touch our OT."

Reality: Very few modern plants are truly air-gapped. Historians feed cloud analytics. Vendors connect remotely. Data flows outward to power AI. Assume you're converged, and design as if you are.

Myth 3: "AI security is just IT security with a new logo."

Reality: Partly true, and that's the trap. The fundamentals (segmentation, access control, change management) still apply. But AI adds failure modes that don't exist in a PLC: a model can quietly get worse over time, be fed poisoned data, or be tricked by hidden instructions in text.

Myth 4: "The vendor has it covered."

Reality: Your vendor secures their product. You own the consequences in your plant. AI security is a shared responsibility, and the contract needs to say who does what. (See the 7 vendor questions below.)

Myth 5: "AI will fix our OT security gaps."

Reality: AI-powered detection is genuinely useful. But an anomaly detector on a network you can't see just produces confident noise.

Asset visibility and segmentation come first. AI multiplies the quality of your fundamentals, good or bad.

Webinar: β€œAI-in-OT Readiness Assessment” Prove IT!

  • Welcome + Poll 1

  • The Helpful Suggestion - Illustrative Scenario!

  • Segment 1: Ground rules (3 kinds of AI, 3 doors)

  • Segment 2: Green / Amber / Red Sort Interactive, audience polls

  • Segment 3: Tabletop: "The Helpful Copilot" Interactive, chat votes

  • Segment 4: Regional radar + 30-60-90 plan

  • Live Q&A

  • Close + call to action.

Designed to help you as asset owners get aware on the AI-in-OT risks. Plus, how to go about identifying, classifying and treating them across the Purdue stack. An interactive workshop!

Learn what it means for you as an asset owner and how this'll help your business.Β 

Schedule: October 10, 2026, 7:00 PM - 8:00 PM (UTC+08:00) Hong Kong.

We look forward for you attending the webinar:

πŸ“– Register here today. πŸ“Œ

🀝 How We Help

I've spent few years working across IT and OT security with global asset owners / manufacturers, and the pattern is consistent:

fundamentals decide whether AI becomes an advantage or a liability.

❝

"I enjoyed working with Yousuf with his extensive IT and OT cybersecurity knowledge."

Global CISO, Global Manufacturer (F&B sector)

An β€œAI-in-OT Readiness Assessment” from Securing Things gives you what this newsletter can only describe:

  • A complete inventory of AI across your three doors

  • Zone and conduit mapping for every AI system

  • Risk-tiering by consequence and autonomy (green, amber, red)

  • A gap analysis against the CISA-led principles, IEC 62443, NIST AI RMF and ISO/IEC 42001, mapped to your regional obligations

  • A prioritized roadmap your board can approve.

Companion resources (if you'd rather watch or listen): Join us on

πŸŽ₯ Live webinar: 🎧WEBINAR REGISTRATION + 13 October 7-8 pm (GMT +8).

πŸ‘‰ [Book your AI-in-OT Strategy Call β†’

(Reply to this e-mail, Or write to [email protected], or reach me via Linkedin).

To continue reading rest of the sections - subscribe below to get free access.

Subscribe to keep reading

This content is free, but you must be subscribed to Securing Things Newsletter to continue reading.

I consent to receive newsletters via email. Terms of use and Privacy policy.

Already a subscriber?Sign in.Not now

Reply

Avatar

or to participate