What Fire-Protection Impairment Management Can Teach Us About Defending OT/ICS at AI Speed

Fire codes have a well-established answer for a specific problem: what happens when permanent protection is not available right now. When a fire protection system is impaired, NFPA impairment procedures require the increased risk to be evaluated and compensating measures to be considered. Depending on the circumstances, an approved fire watch, a trained person who patrols the affected area and is prepared to act with whatever means are on hand, may be required until the system is restored. NFPA 25 sets out this process in detail for water-based fire protection systems specifically. A fire watch does not guarantee a fire will never start. Its purpose is narrower than that: keep the consequences small enough to survive until real protection comes back online.
OT/ICS (Operational Technology and Industrial Control Systems) security faces a version of the same problem, and the gap is widening. A permanent fix, a vendor-qualified patch deployed inside a planned maintenance window, still takes weeks to months to reach a running plant. What has changed is how quickly that gap can now be found and used against you, because artificial intelligence (AI) is measurably accelerating reconnaissance and exploit development. CS4, DTS Solution’s OT/ICS cybersecurity division, uses the fire watch model to think about what belongs inside that gap: a compensating control that is continuous, monitored, owned by a named person, and retired the moment the permanent fix arrives.
Three Cases, Three Stages
Three recent cases show different stages of AI-enabled activity around OT: research assistance, reconnaissance, and active tool development. None shows AI independently causing a successful physical-process compromise. Together, they show how much less expertise and time that now takes.
The earliest case runs from October 2023 through January 2024, when the Iran-linked group CyberAv3ngers compromised at least 75 internet-exposed Unitronics programmable logic controllers (PLCs) across the US, Israel, the UK, and Ireland by exploiting default passwords nobody had changed. The Municipal Water Authority of Aliquippa, Pennsylvania, switched a pumping station to manual control after its equipment was defaced with an anti-Israel message; a utility in County Mayo, Ireland, lost water service for two days. That compromise involved no AI. Separately, in October 2024, OpenAI disclosed that the group had used ChatGPT for reconnaissance, vulnerability research, and help debugging scripts, and assessed at the time that this gave the attackers no novel capability, only a limited boost on top of what was already achievable with public tools.
The second case is stronger evidence of a shift. Investigating an intrusion against Mexican government and municipal targets between December 2025 and February 2026, Dragos reported that the attacker had built the operation around Claude, describing the model as the campaign’s primary technical executor. During ordinary network reconnaissance, without being told to look for operational technology, the model identified a SCADA and Industrial Internet of Things (IIoT) management gateway on a municipal water utility’s network, flagged it as a high-value target on its own initiative, researched the vendor’s authentication scheme, and generated credentials the operator then used in password-spray attempts. Both attempts failed. Dragos found no evidence that the utility’s actual treatment or distribution controls were reached. This is evidence of AI-assisted OT reconnaissance and targeting, not a successful OT compromise, and that distinction matters.
The third case, ten weeks later, moved from reconnaissance to active tool development against real equipment in the field.
31 minto build a working proof of concept for a newly disclosed Windows or Firefox flaw, in controlled testing | 18 / 21tested Windows kernel vulnerabilities turned into working exploits within hours | ~$2,000estimated cost to weaponize one disclosed IT vulnerability this way | 263%growth in CVE submissions, 2020 to 2025 (NIST, via Nozomi Networks) |
Source: Nozomi Networks, “Zero-Days at AI Speed,” August 2026. These figures describe controlled testing of Windows and Firefox vulnerabilities. They are not evidence of a working exploit against a PLC.
The Zero-Hour Problem
These figures describe disclosed Windows and Firefox flaws, not industrial controllers. They establish the trend underneath all three cases: what once took an expert days of analysis can now take an automated pipeline minutes, and separate real-world cases show that same acceleration reaching toward OT reconnaissance and targeting.
The chart tracks two averages. Organizations’ mean time to remediate has climbed from around 60 days in 2020 toward roughly 95 days by 2026. Attacker time-to-exploit has moved the other way, from about 30 days down through zero and into negative territory in the more recent data. A negative value does not mean a vulnerability was exploited before it existed. It means that, on average in this dataset, exploitation was observed before the disclosure or patch that would normally start an organization’s clock: defenders were already behind before they knew there was a race.
For an IT estate that gap is painful but survivable: patch, roll back if something breaks, move on. OT runs into structure, not habit. Availability and safety outrank confidentiality, a continuous process cannot pause for a Common Vulnerabilities and Exposures (CVE) entry, and the next scheduled maintenance window may be a turnaround planned a year in advance. Industrial patches generally need vendor qualification against the specific product line before deployment, a process that starts once the manufacturer has processed the fix and can run weeks to months on its own. That is the gap a fire watch model is built for.
A fire watch cannot promise the fire never starts. What it can do is act, with whatever is on hand, to keep the damage survivable until the sprinkler system is restored. A compensating control is meant to do the same job for a PLC that cannot be pulled off the line mid shift |
A Fire-Watch Model for OT Compensating Controls
IEC 62443, the International Electrotechnical Commission’s cybersecurity standard for industrial automation and control systems, gives OT operators the broader framework for this: zones and conduits to define exposure, defense in depth, and compensating measures where patching is not feasible on the timeline the risk demands. ISA-TR62443-2-3 specifically addresses patch management in the IACS environment; it sits inside that framework rather than serving as a standalone virtual-patching manual. Read against fire-watch impairment logic, the sequence looks like this:
Permanent Control → Impairment / Exposure → Compensating Control → Continuous Monitoring → Named Accountability → Permanent Remediation |
1 · Permanent Control
A vendor-qualified patch deployed inside a planned maintenance window is the intended, permanent fix, the equivalent of a working sprinkler system. It is also structurally slow: risk and impact assessment, change request and approval, and a scheduled maintenance window that can together run weeks to months before the patch is applied.
2 · Impairment and Exposure
When a vulnerability is disclosed, or found through automated tooling, faster than the qualified patch is ready, the asset is impaired in the same sense NFPA uses the word: an abnormal condition leaving the protected asset without its intended safeguard. That calls for an evaluation of the increased risk and a decision on compensating measures, not silence.
3 · Compensating Control
The control has to be continuous, monitored, and ready to act, not just log an alert. Depending on the asset and the exposure, that can mean network segmentation, firewall restrictions, protocol-aware filtering or deep packet inspection (DPI), allow-listing, isolation, tightened access control, enhanced monitoring, a temporary operational restriction, or virtual patching at the network boundary where technically appropriate. Which specific control gets used matters less than whether it has a named owner and an expiry date tied to the permanent fix, so it never quietly becomes the permanent answer.
AI-Accelerated Resilience, Human-Supervised
Detection tells you an attack is underway. Resilience determines what it costs you. |
No IEC 62443 Security Level, SL 0 through SL 4, should be treated as a standalone defense against an AI-assisted adversary. Security Levels need to be supported by zones and conduits, defense in depth, access control, monitoring, and the operational process to act on what monitoring finds.
People, Process, Technology
PEOPLE | PROCESS | TECHNOLOGY |
|
|
|
The Takeaway
The tools on both sides changed over the past three years. The underlying logic did not. A gap between a hazard and its permanent fix has always needed a compensating control that is continuous, monitored, and ready to act, a question fire codes settled decades ago for physical protection systems. What changed is the size of the gap and how fast it can be found: the three cases above show AI lowering the research and reconnaissance cost of reaching OT, even where the evidence stops short of a successful physical-process compromise.
The objective was never to pretend every vulnerability can be patched immediately. It is to make sure the unavoidable window between disclosure and permanent remediation does not become an uncontrolled exposure window, and that someone is named as accountable for it the entire time it stays open.
How CS4 Works with Your Environment
CS4, DTS Solution’s OT/ICS cybersecurity division, helps asset owners build this kind of compensating-control program. It is not a promise to eliminate AI-assisted threats outright.
✓ Full asset visibility to Level 1: PLCs, DCS controllers, and SCADA RTUs inventoried against IEC 62443.
✓ Compensating-control design, including virtual patching where appropriate, plus digital-twin or representative test-environment validation before changes reach production
✓ Purdue-based architecture reviews and zone and conduit design for the OT DMZ and secure remote access
✓ AI-assisted OT SOC triage and threat hunting, with every finding reviewed and signed off by an analyst
✓ Consequence-based, crown-jewel risk prioritization for assets carrying safety, integrity, and production risk
✓ OT cybersecurity training and AI-assisted incident-response tabletop exercises
✓ CSMS development aligned to ISA/IEC 62443 across the asset lifecycle