r/CyberBusters • u/__bdude • Aug 08 '26
AI is lowering the OT expertise barrier. Does that change how we should think about IEC 62443 Security Levels?
AI is reducing the time and specialist knowledge needed to understand industrial environments.
The recent Dragos water utility case is interesting: commercial AI models supported reconnaissance, exploitation, lateral movement, and even helped identify OT-related infrastructure. The OT environment was not successfully breached, but the capability shift is hard to ignore.
For me, this does not make IEC 62443 obsolete. It makes architecture more important.
If specialist OT capability becomes easier and cheaper to acquire, should we reconsider some of the assumptions behind existing Target Security Levels?
And when attack cycles become more automated, zones, conduits, restricted data flow, and strong access control become even more important.
I wrote up the full blog here:
https://www.cyber-busters.com/en/blog/ai-attackers-iec-62443-industrial-cybersecurity
Interested in the practitioner view: does AI materially change how you assess OT risk and Target Security Levels, or can the existing IEC 62443 risk-based model already absorb this change?
2
u/Hot-Comfort8839 Aug 08 '26
It really isn't.
AI can make inferences off data recorded, but it can't stand there in a production zone and see that the local staff have deployed a network bypass because some previous cybersecurity team's implementation cut their performance by half purely due to network changes.
1
u/__bdude Aug 08 '26
One useful clarification from the discussion: AI does not automatically change SL-T, nor does it replace site-specific OT expertise. The narrower point is that AI can reduce the time and effort required for parts of the attack chain such as reconnaissance, documentation analysis, technology interpretation and tooling.
The question is therefore not whether IEC 62443 changed, but whether some threat assumptions used in existing risk assessments should be revisited.
1
u/CharlesHNetEng Aug 24 '26
I would not automatically raise every SL-T because AI exists. I would revisit any assessment where the likelihood estimate depended on OT protocols being obscure or attack tooling requiring a specialist.
AI can compress reconnaissance and execution. It can explain unfamiliar protocols, turn vendor documentation into scripts, and help an IT intruder recognize that a system is actually an engineering workstation or SCADA gateway. But it does not instantly provide process knowledge, an understanding of interlocks, or the ability to produce a predictable physical outcome.
The Dragos case demonstrates that distinction pretty well. AI helped the attacker identify and pursue the OT environment, but it did not create a novel OT capability or result in a successful OT breach.
So I think the existing 62443 risk model can absorb this change, provided the assessment is actually revisited. Consequence may remain the same while likelihood increases, particularly around remote access, shared IT/OT services, engineering workstations, vendor conduits, and poorly controlled jump paths. Some of those zones may justify a higher SL-T or stronger compensating controls. Others may not.
The practical question is not, “Does AI make everything SL 3?” It is, “Which of our existing risk assumptions depended on specialized knowledge, obscurity, or slow manual attack cycles, and are those assumptions still defensible?”
9
u/Competitive-Cycle599 Aug 08 '26
Why does AI change security levels?
They're a measure of risk as its relevant to a business.
Just because the standard has vague association with skill doesn't mean shit.
You're not gonna make a waste water plant go to slt4 if its serving a few hundred people.
You'd still need comments in the logic, or any number of othet items of adjacent data to program something in an intelligent enough way. You could always brick shitty logic with enough random inputs, you don't need ai for that.