Faster Than You Can Watch: Why Agentic AI Breaks the OT Visibility Model
About This Session
Most OT security programs have spent the last several years chasing one goal. Visibility. ICS asset inventories, passive taps at the Purdue Level 2/3 boundary, IPS/IDS tuned to known-bad Modbus, DNP3, or OPC traffic patterns. The assumption has always been that if you can see it, you can stop it.
Agentic AI breaks that premise. In our threat research we have identified AI-driven reconnaissance and attack tooling that can chain together legitimate-looking engineering workstation commands, pivot from IT to OT, and probe PLCs, RTUs, and HMIs for weaknesses faster than any analyst watching a SIEM dashboard.
Faster detection won’t fix this. That’s a race defenders keep losing. What has to change is what the architecture assumes in the first place, containment that doesn’t depend on catching someone in time, a definition of “normal” that doesn’t rely on pattern-matching bad behavior fast enough, and incident response model that doesn’t compromise human safety or plant shutdown.
This session breaks down what’s actually changing in OT attacker tradecraft, and what that means for how teams need to architect detection and response on the plant floor going forward.
Agentic AI breaks that premise. In our threat research we have identified AI-driven reconnaissance and attack tooling that can chain together legitimate-looking engineering workstation commands, pivot from IT to OT, and probe PLCs, RTUs, and HMIs for weaknesses faster than any analyst watching a SIEM dashboard.
Faster detection won’t fix this. That’s a race defenders keep losing. What has to change is what the architecture assumes in the first place, containment that doesn’t depend on catching someone in time, a definition of “normal” that doesn’t rely on pattern-matching bad behavior fast enough, and incident response model that doesn’t compromise human safety or plant shutdown.
This session breaks down what’s actually changing in OT attacker tradecraft, and what that means for how teams need to architect detection and response on the plant floor going forward.
Speaker
Umang Barman
OT specialist - Zscaler
Umang Barman focuses on OT and industrial cybersecurity, working closely with manufacturing and critical infrastructure organizations. His work centers on reducing operational risk in complex factory and plant environments. With experience across network, identity, data, and SecOps, he brings a unique perspective that helps align network, security, and OT teams.
