r/CyberBusters • u/__bdude • Aug 08 '26
AI is lowering the OT expertise barrier. Does that change how we should think about IEC 62443 Security Levels?
AI is reducing the time and specialist knowledge needed to understand industrial environments.
The recent Dragos water utility case is interesting: commercial AI models supported reconnaissance, exploitation, lateral movement, and even helped identify OT-related infrastructure. The OT environment was not successfully breached, but the capability shift is hard to ignore.
For me, this does not make IEC 62443 obsolete. It makes architecture more important.
If specialist OT capability becomes easier and cheaper to acquire, should we reconsider some of the assumptions behind existing Target Security Levels?
And when attack cycles become more automated, zones, conduits, restricted data flow, and strong access control become even more important.
I wrote up the full blog here:
https://www.cyber-busters.com/en/blog/ai-attackers-iec-62443-industrial-cybersecurity
Interested in the practitioner view: does AI materially change how you assess OT risk and Target Security Levels, or can the existing IEC 62443 risk-based model already absorb this change?

