AI-assisted exploit development is changing the economics of operational technology risk. The uncomfortable part is not that factories suddenly became vulnerable. It is that one of the quiet defenses many plants relied on — attacker specialization — is getting weaker.
In a new Zscaler analysis, Bryan Ashley argues that exploiting industrial controllers used to require narrow domain knowledge: protocols, firmware behavior, product-family quirks, and plant-floor realities most attackers did not understand. That scarcity helped keep many intrusions on the business side of manufacturing networks. Now, AI-assisted tooling is lowering the bar for turning public information, patches, and device knowledge into usable attack capability.
For small manufacturers, utilities, food producers, logistics firms, and government contractors with plant-floor equipment, the takeaway is blunt: the defender cannot count on attackers being slowed down by unfamiliar OT anymore. The defensive model has to shift from “patch before the exploit arrives” to “make sure the exploit has fewer places it can reach.”
What was reported
Zscaler’s post connects several developments into one larger trend. AI systems have demonstrated the ability to assist with vulnerability discovery and exploit construction. Research has shown that patches can be analyzed and converted into working exploit paths quickly. More importantly for OT defenders, federal agencies recently warned that AI-generated exploitation scripts were being used against Siemens S7-series programmable logic controllers, disguised as legitimate monitoring tools.
The article also highlights a second pressure point: industrial environments cannot patch at normal IT speed. A plant floor may run equipment that has operated reliably for ten or twenty years. Changes are tested carefully, coordinated with production, and often limited to planned maintenance windows. That is not laziness; it is the operating reality of systems that move physical processes, safety constraints, product quality, and uptime.
The result is an asymmetric race. AI can help attackers move faster. It does not magically give defenders more safe maintenance windows.
Why this matters for SMBs and government contractors
Many smaller organizations do not think of themselves as OT targets. They should. If the business supports manufacturing, water, food and agriculture, energy, facilities, maritime, transportation, or physical production, there may be controllers, HMIs, vendor laptops, cellular modems, remote-support tools, or unmanaged industrial network paths in scope.
The risk is rarely a clean “internet-connected factory” problem. It is usually messier: a vendor remote-access path left in place, a cellular modem shipped with a machine, an integrator account that was never retired, a flat plant network, or an IT workstation that can still reach engineering systems. A controller does not need to be directly exposed to the internet to be reachable. It only needs a path from something that is.
That is especially relevant for contractors and suppliers. A shop that provides parts, logistics, facilities support, or specialized manufacturing for government customers may have a small IT team and a mixed environment of office systems, cloud apps, vendor portals, and industrial equipment. If compromise affects production, safety, customer delivery, or controlled data handling, the incident becomes a business continuity and reporting problem fast.
The defensive lesson: shrink reachability
The strongest idea in the Zscaler piece is simple: an exploit is worthless against a controller it cannot reach. That is the control that scales as attacker speed increases.
Patching still matters. Asset owners should apply vendor updates inside safe windows and prioritize known-exploited issues. But for OT, patching cannot be the only line of defense. The more durable control is reducing which users, devices, vendors, subnets, services, and remote sessions can talk to controllers in the first place.
Practical controls to implement now
- Map every path to controllers. Include engineering workstations, HMIs, vendor laptops, jump boxes, cellular routers, VPNs, remote monitoring tools, cloud dashboards, and maintenance accounts.
- Remove direct exposure. Industrial controllers and management services should not be internet-reachable. If remote access is required, broker it through controlled, logged, time-bound access.
- Segment by function, not convenience. Separate office IT, vendor access, engineering workstations, HMIs, safety systems, and controllers. Flat networks turn one foothold into plant-wide reachability.
- Use allowlists for OT communication. Define which systems are allowed to talk to which controllers, over which protocols, and for what operational purpose. Deny the rest.
- Control vendor access tightly. Replace standing vendor tunnels with approved sessions, MFA, named accounts, session logging, and expiration. Review old integrator and OEM access paths quarterly.
- Monitor for “normal-looking” tools in abnormal places. If malicious scripts are disguised as monitoring utilities, defenders need baselines for who runs engineering tools, from where, and when.
- Plan compensating controls before the patch window. When a controller cannot be patched immediately, document the temporary exposure reduction: blocked routes, disabled services, ACL changes, monitoring rules, and vendor restrictions.
Bulwark Black assessment
AI does not make OT defense hopeless. It makes architecture matter more. The organizations that depend only on secrecy, obscurity, tribal knowledge, or slow attacker specialization are losing ground. The organizations that know their controller paths, restrict them aggressively, and log every remote-support session are in a much better position.
For SMBs and government contractors, this does not have to start as a massive plant redesign. Start with the map. Identify what can reach the controllers today. Remove what has no business being there. Put vendor access behind a controlled choke point. Then use the next maintenance window for the fixes that truly require touching production.
The hard part of attacking factories is getting easier. The answer is not panic. The answer is reachability discipline.
Source: Zscaler — It No Longer Takes an Expert to Attack a Factory

