AI is transforming operational technology cybersecurity by enabling threat actors to conduct reconnaissance, generate malware variants, and execute convincing social engineering attacks through deepfakes, while defenders must rely on fundamental security practices including strong identity management, network segmentation, and frameworks like IEC 62443, as human vulnerability remains the primary attack vector.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
AI vs OT: Let's Talk Cyber with Ian Gemski
Added:Welcome back everybody. I'm Tommy McCarthy and this is Let's Talk Cyber.
Yes, he's no stranger to Let's Talk Cyber, the one and only Ian Jemski, the CEO and founder of Tech Gem. Welcome back Ian.
>> Hi, morning Tommy. How are you keeping?
>> Yeah, not too bad at all Ian. It's a strange old world we're living in right now, especially with what you know, the implementation of AI across all industries and sectors. I have been inundated with AI podcasts. Is AI taking over the world? You multitude of thing.
Interestingly Ian, the Scottish OT Cyber Summit's on its way and you've agreed to support us in a number of different capacities. So, we thought we'd talk a little bit now about AI versus OT. Does it exist Ian? What's your opinion before we get into the questions? Is there such a thing AI versus OT?
>> Yeah, absolutely. You know, you kind of touched on it right at the beginning there that AI is in use all over the place. We're using it on a day-to-day basis within our business for all sorts of different business processes and that's no different on the plant floors, on the the storage terminals, these OT environments. AI tools are being used day in and day out to help productivity, um to solve problems.
So, absolutely AI is here and it ain't going anywhere.
>> No, yeah, well, there's one common theme there Ian, you're absolutely right.
Everyone says the same thing, AI is around for good, certainly in our lifetime. So, I guess the first question Ian is is AI change changing the threat landscape in industrial control systems and operational technology? Because if AI is being used, surely there must be a change in the threat landscape. What's your view on that Ian?
>> Yeah, absolutely. So, for years industrial cybersecurity has been a skills problem and in terms of the threat landscape, to compromise an OT environment, you would typically need specialist knowledge of industrial protocols, engineering processes, and control systems. Now, AI is beginning to erode that barrier because AI can actually provide that specialist knowledge that threat actors without them needing to know in depth the specifics on how a control system is programmed, how it operates, and how it functions. So, because of that, we're now starting to see the industrialization of cyberattacks. Uh AI allows threat actors to conduct reconnaissance quicker, to generate malware variants at scale, and create highly convincing social engineering campaigns. I don't know if you've seen examples online, Tommy, but now these deep fakes aren't just audio deep fakes, they're video deep fakes. You can fake uh conversations over a video call with people.
>> You know, the deep fake especially is just astounding what the deep fakes uh how seriously real the deep fakes are coming across now. So, it's interesting you say that about the attacker AI because it leads me right into my next question. What's the most realistic way that an attack attacker would use AI to compromise, not just an OT environment, but an ICS environment? What do you think's the probably the most realistic way they'd do that?
>> Yeah, so the most likely target isn't the PLC or or or your safety instrument system. It's the engineer. And I've said this many, many times, and I always say it, the biggest vulnerability is the human vulnerability. Um AI's making phishing, impersonation, and social engineering incredibly convincing. Um you know, attackers can analyze publicly available information, understand an organization's structure, and generate messages so that they look like they come from a trusted colleague, a supplier, or a manager. And so, my view is that the future battleground isn't machine versus machine per se, it's trust versus versus deception, and AI is making deception far more effective.
>> Yeah, interesting trust versus versus deception. That's That's a good analogy, that Ian. Might have to steal that one myself.
So, then I guess what we should you know, what should industrial organizations be doing now then, Ian, to defend against AI-enabled cyber threats because it's all right saying, "Yeah, we've identified them." Well, what should they be doing about it?
>> Yeah, I I guess uh there's a there's a couple of points here, you know, whilst attackers are using AI um as part of their toolkit, also you know, cybersecurity platforms are integrating AI uh for defensive mechanisms. So, so looking into and utilizing those those those technologies that you may already have um and where AI is available, you know, building them into your defensive capabilities is absolutely key. But, I think you know, the answer isn't some miracle technology. I think organizations need to double down on on cybersecurity fundamentals, Tommy.
>> Yeah.
>> Strong identity management, network segmentation, secure remote access, rigorous change control, um and continuous security monitoring. They're as relevant as they've ever been. Um and frameworks such as IEC 62443 provide a solid foundation because they're designed around resilience rather than to specific threats. Uh and I think that's key is business resilience uh uh and um AI is going to continue to evolve um and the organizations that uh will succeed will be the ones that are chasing it won't be chasing down every new trend, but they'll be the ones that are operating disciplined and well-governed security programs. Uh and that's absolutely key.
Fundamentals. Get your fundamentals right uh and uh and you'll be well placed to protect uh your critical infrastructure.
>> It's It's interesting that you touched on govern as in governance, Ian, because that certainly seems to be one of the things that's being driven now around the implementation of AI is the you know, ensuring that organizations understand the governance and the control. Are you seeing yourself in your now across industry the encouragement of AI being used in your space, the industrial control system space, or is there is there a resistance to to say, "Whoa, don't be bringing AI to us."
What's the general gut feeling right now?
>> Everybody's using it in every aspect of everybody's job. You know, if you look at control system engineers or your process control engineers, they typically have very stressful and complicated jobs to carry out. Um and a lot of those activities that they they need to carry out involve troubleshooting, plant upsets, and and you know, people are using AI to understand issues and help them to solve those technical challenges, engineering challenges. And I think as part of that, people are using AI, but that potentially it is share they they are potentially sharing what could be sensitive information was publicly accessible models. Uh and you know, having the right and necessary governance in place within an organization to protect that is absolutely key. I was actually and this is on a separate topic. I was actually having a discussion with our marketing agency a week or two ago around search engine optimization. Well, actually, they're not they're they're not Well, they're still talking about search engine optimization, but now the discussion is around large language model search optimization because people are interacting with models to get information. Um now, you can do that for good, i.e. trying to fix an issue, but if the model has that information, is it available to a potentially bad threat actor who can use that information as part of an attack. So, those are absolutely key things that that organizations need to take into account.
>> Yeah, there's no question here in the whole landscape of how we communicate now online is definitely changing as a result of AI. Well, Ian, we could go on forever as you well know. Four weeks today you'll be here in Aberdeen supporting the Scottish OT Cyber Summit.
Machine versus machine, Ian. You've got something unusual in store for the audience, so we're looking forward to that.
>> [music] >> Ian Jemske, CTO of Tech Germ, for now thanks so much for joining me on Let's Talk Cyber.
>> Thanks, Tommy. Take care.
Related Videos

Expanding Stikbot thumbnails
leopoldshorts
2K views•2023-09-24

Digital Discrimination: Cognitive Bias in Machine Learning
redmonktechevents2974
4K views•2019-12-18

Evolutionary Approach to Clustering by Ujjwal Maulik
ICTStalks
279 views•2019-06-26

Rose Yu "Learning from Large-Scale Spatiotemporal Data"
networkscienceinstitute
2K views•2019-03-04

Stanford Seminar - Generalization through Task Representations with Foundation Models
stanfordonline
4K views•2025-07-14

Satellite-Based Wheat Yield Forecasting using GEE & Transformer Neural Network
gisrsinstitute
634 views•2025-06-15

Paradigm Shifts in Data Processing for the Generative AI Era: Robert Nishihara of Anyscale & Ray.io
GradientFlow
2K views•2025-01-02

How to Build Your Own GenAI-Based Knowledge Management System
2150GmbH
360 views•2025-06-03
Trending

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23

SuperBike Factory Has Gone... What's Next for the Motorcycle Industry?
thatbikersimon
11K views•2026-07-22