AI is Compressing the OT Attack Cycle

On August 19, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), U.S. Department of Energy (DOE), and U.S. Environmental Protection Agency (EPA) warned that attackers are actively targeting Siemens S7 programmable logic controllers (PLCs) used across U.S. critical infrastructure.

The attackers are using AI-assisted Python scripts built around public industrial automation libraries. The tools can communicate directly with Siemens controllers, read and write PLC memory, access configuration data, and modify control logic.

The government says AI is “dramatically reducing the technical expertise and time required” to build working ICS exploitation tools. Experienced attackers can move faster. Less experienced attackers can get further.[1]

Some of the scripts are built to look like legitimate OT monitoring tools and communicate over S7comm, the same protocol used for normal Siemens engineering activity.[1]

A controller write from an approved engineering workstation at 2:13 p.m. during scheduled maintenance may be normal. The same write at 2:13 a.m. from a host that has never touched that PLC, with no scheduled work, deserves a closer look.

For teams running Siemens environments, the federal guidance is straightforward:

  1. Inventory S7 controllers and the systems that can reach them.

  2. Patch critical vulnerabilities after testing updates in the operational environment.

  3. Segment OT networks and keep PLCs off the public internet.

  4. Strengthen access controls and require MFA for remote OT access.

  5. Monitor for unexpected hosts, unusual reads or writes, off-hours activity, and configuration changes outside approved work.

  6. Hunt for unusual S7 activity and investigate what doesn't match normal operations.[1]

Once something fires, somebody has to work it.

Where did the activity come from? Was that host supposed to reach the PLC? Has it done this before? Did the controller change? What else happened around it?

Teams don't have enough time to do that work. A 2025 SANS survey of more than 180 professionals found that only 9% spend all of their time on ICS/OT security, while 41% said their organizations allocate no more than 25% of their cybersecurity budget to ICS/OT.[2]

AI gives attackers a faster way to build, test, and adapt tooling against industrial systems. More of that activity will have to be investigated, so the investigation needs to get faster.

CrunchAtlas automates that work.

It passively analyzes network and security telemetry, connects related activity, and builds the investigation around what happened: source, target, timing, affected systems, evidence, and surrounding activity.

If an S7 write fires at 2:13 a.m., the operator should be working from an investigated case, not starting a scavenger hunt across five tools.

The attackers are already using AI to move faster.

Defenders should be too.

 

References

[1] National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, U.S. Department of Energy, and U.S. Environmental Protection Agency. Defending Against an Active Threat to Siemens S7 Series PLCs. Joint Cybersecurity Advisory AA26-231A, August 19, 2026.

[2] Parsons, Dean. 2025 ICS/OT Cybersecurity Budget: Spending Trends, Challenges, and the Future. SANS Institute, March 3, 2025.

Previous
Previous

This Week in Cyber - August 13–19, 2026

Next
Next

This Week in Cyber - August 6–12, 2026