Disclaimer: All views presented here, in this newsletter, are my own, or are either researched using internet and AI (using LLMs) search and referenced accordingly.
Author or the newsletter are not liable for any actions taken by any individual or any organization / business / entity. The information provided is for information, education and awareness purposes only and is not specific to any business and or situation.
This publication does not constitute legal, regulatory, or professional advice.
Hi Securing Things family,
Hope you are doing well and had a great weekend.
Let me start with one question.
Who approved the AI that's running in your plant today?
If your honest answer is "IT," "the vendor," or "I'm not sure", this edition is for you.
βͺοΈ In this newsletter edition βοΈ we cut through the hype on AI in OT / Industry 4.0 / industrial manufacturing. No jargon walls.
Whether you're new to OT or you've been in control rooms for 20 years, you'll leave with a clear picture and a plan.
π§ What "AI in the plant" actually means (3 kinds, 3 analogies)
πͺ The three doors AI uses to enter your OT
𧨠Five myths that could cost you a shutdown
π¦ A walk up the Purdue model: green, amber & red zones for AI
β οΈ Six new failure modes, with plant-floor examples
π What US, EMEA and APAC regulators are saying right now
β A 7 Step plan for CISOs + 7 questions for your vendors.
Companion resources: this edition comes with basic list of action items below and an upcoming live webinar. Think of it this way:
the newsletter is the map.
the webinar/podcast is the walk.
Same topic, different depth, no repeats (well some recap). registration link below.
But before we begin, do me a favor and make sure you βSubscribeβ to let me know that you care and keep me motivated to publish more. Thanks!
Ready? letβs dig in.
Yours truly.
β Yousuf.
β»οΈif you know someone in your professional circle who will benefit from these resources and interested in learning. Thanks π
Note; in the previous two editions weβve covered awareness across:
βͺοΈProve it - ISA Secure ACSSA (Automation Control System Security Assurance) certification for Asset Owner β Iβd like to thank you those you joined our webinar live and those that register to view recordings. In case you missed, go to above link to watch the recording.
βͺοΈEU AI Act is about Trust, Not AI - 31 days of EU AI Act Awareness series.
Covered below - once you register with your e-mail, you can access for free:
π― The 60-Second Version
(For the CISO who has a board meeting in ten minutes.)
AI is already inside most industrial environments. It mostly arrived through vendors, not projects.
The value is real: fewer breakdowns, better quality, lower energy use, captured expertise.
But AI adds new ways to fail that classic OT controls don't cover: drift, poisoned data, prompt injection and over-trust.
One rule keeps you safe: AI advises. Deterministic controls and humans decide. Read-only by default.
Regulators are converging on the same message. The EU delayed some AI Act deadlines, but delayed is not cancelled.
Your first move is not a new tool. It's finding the AI you already have.
π§ First, What Do We Mean by "AI"?
"AI" is a word doing too much work. In a plant, it means three very different things. Here they are as three people you might already know.
1. Classic machine learning: the experienced night-shift technician.
They've seen a thousand pump failures. They walk past and say, "That vibration doesn't sound right." Machine learning learns patterns from history and spots what's unusual.
Where you'll see it: predictive maintenance, camera-based quality inspection, energy optimization.
2. Generative AI (LLMs): the brilliant intern.
They've read every manual ever written. They answer instantly. And they will confidently answer even when they're wrong.
Where you'll see it: searching SOPs, summarizing shift logs, drafting work orders, explaining alarms in plain language.
3. Agentic AI: the intern, now with a badge and a laptop.
Same intern, but now they can do things: open tickets, call other systems, change settings. Highest value. Highest risk.
Here's the pattern to remember:
The closer AI moves from advice to action, the more your risk grows. Most of what follows in this newsletter is just that idea, applied.
SPONSOR
Analytics on Live Data Without Leaving Postgres
When analytics on Postgres slows down, most teams add a second database. Then come the pipelines, the sync jobs, and a copy of your data that's always a little behind.
TimescaleDB takes a different approach: extend Postgres instead of splitting away from it. Hypertables partition your data automatically as volume grows. Hypercore compression cuts storage up to 95%. Continuous aggregates keep dashboards live without re-querying everything.
CERN runs Postgres this way for sensor data from the Large Hadron Collider.
No split architecture, no pipeline lag, no new query language to learn. Same SQL, same drivers, same tools.
Start on Tiger Cloud and get $1000 in credits.
SPONSOR
For Deel's "Feeling of Deeling" campaign, agency SuperBloom used Branded AI Voice for one consistent brand voice across markets, without sacrificing quality or consent. Watch the Recording.
πͺ The Three Doors AI Uses to Enter Your OT
Most CISOs I speak with know about one door. There are three.
Door 1πͺ: The front door (vendors ship it)
Your SCADA, historian, MES, or OT monitoring vendor adds an "AI assistant" in the next release. You didn't buy AI. You upgraded. And nobody in security was in the room.
Door 2πͺ: The side door (your teams build it)
A data science pilot pulls years of historian data into a cloud platform to predict failures. Good project. Sensible goal. But now your process data lives somewhere new, on a pipeline nobody threat-modeled.
Door 3πͺ: The back door (shadow AI)
A well-meaning engineer pastes an alarm log, a P&ID description, or a chunk of ladder logic into a public chatbot to "save an hour." Your process IP just left the building.
"But how many plants are actually using AI?"
Depending on who you ask, the answer swings wildly. A 2026 Fluke survey found predictive maintenance adoption doubled to 18%. An RSM survey of 129 middle-market manufacturers found 88% had AI at least partially integrated. MaintainX reports roughly a third of maintenance teams have implemented AI, with about two-thirds planning to.
These numbers aren't contradicting each other. They're measuring different things. Your exposure isn't defined by any survey. It's defined by what's actually running in your plant.
(Note: these are vendor and consultancy surveys, so read them as directional, not gospel.)
𧨠Five Myths That Could Cost You a Shutdown
Myth 1: "AI is going to run our plant."
Reality: Today, most AI in OT is decision support. It recommends, flags and summarizes. That's a feature, not a flaw. The joint international guidance we'll look at below is clear that humans must stay in the loop, and that LLMs shouldn't be making safety decisions in OT.
Myth 2: "We're air-gapped, so AI can't touch our OT."
Reality: Very few modern plants are truly air-gapped. Historians feed cloud analytics. Vendors connect remotely. Data flows outward to power AI. Assume you're converged, and design as if you are.
Myth 3: "AI security is just IT security with a new logo."
Reality: Partly true, and that's the trap. The fundamentals (segmentation, access control, change management) still apply. But AI adds failure modes that don't exist in a PLC: a model can quietly get worse over time, be fed poisoned data, or be tricked by hidden instructions in text.
Myth 4: "The vendor has it covered."
Reality: Your vendor secures their product. You own the consequences in your plant. AI security is a shared responsibility, and the contract needs to say who does what. (See the 7 vendor questions below.)
Myth 5: "AI will fix our OT security gaps."
Reality: AI-powered detection is genuinely useful. But an anomaly detector on a network you can't see just produces confident noise.
Asset visibility and segmentation come first. AI multiplies the quality of your fundamentals, good or bad.
Webinar: βAI-in-OT Readiness Assessmentβ Prove IT!
AI-in-OT Readiness Assessment - AI Is Already on Your Plant Floor. Who Approved It? Securing Things Webinar covering:
Welcome + Poll 1
The Helpful Suggestion - Illustrative Scenario!
Segment 1: Ground rules (3 kinds of AI, 3 doors)
Segment 2: Green / Amber / Red Sort Interactive, audience polls
Segment 3: Tabletop: "The Helpful Copilot" Interactive, chat votes
Segment 4: Regional radar + 30-60-90 plan
Live Q&A
Close + call to action.
Designed to help you as asset owners get aware on the AI-in-OT risks. Plus, how to go about identifying, classifying and treating them across the Purdue stack. An interactive workshop!
Learn what it means for you as an asset owner and how this'll help your business.Β
Schedule: October 10, 2026, 7:00 PM - 8:00 PM (UTC+08:00) Hong Kong.
We look forward for you attending the webinar:
π Register here today. π
π€ How We Help
I've spent few years working across IT and OT security with global asset owners / manufacturers, and the pattern is consistent:
fundamentals decide whether AI becomes an advantage or a liability.
"I enjoyed working with Yousuf with his extensive IT and OT cybersecurity knowledge."
An βAI-in-OT Readiness Assessmentβ from Securing Things gives you what this newsletter can only describe:
A complete inventory of AI across your three doors
Zone and conduit mapping for every AI system
Risk-tiering by consequence and autonomy (green, amber, red)
A gap analysis against the CISA-led principles, IEC 62443, NIST AI RMF and ISO/IEC 42001, mapped to your regional obligations
A prioritized roadmap your board can approve.
Companion resources (if you'd rather watch or listen): Join us on
π₯ Live webinar: π§WEBINAR REGISTRATION + 13 October 7-8 pm (GMT +8).
π [Book your AI-in-OT Strategy Call β
(Reply to this e-mail, Or write to [email protected], or reach me via Linkedin).
To continue reading rest of the sections - subscribe below to get free access.




