Practical applications of agentic AI in OT security
In the second part of our Frontier AI for OT mini-series, we explore how you can use agentic AI to interrogate data, identify cyber threats, and streamline security operations. We provide a practical demonstration of integrating local large language models (LLMs) with Tenable OT to enhance your network defenses.
[00:02:47] Defending OT networks at machine speed
As cyber attacks driven by AI accelerate, you must rely on strong foundational security practices to defend your network.
- Asset discovery: Understand your assets, identify choke points, and map out your network architecture.
- Attack path analysis: Find viable attack paths and implement compensating controls to break them.
- Configuration tracking: Validate core OT configurations in real time to ensure unauthorized changes do not occur.
[00:05:27] Core capabilities of Tenable OT and Tenable One
We designed Tenable OT and Tenable One to give you complete visibility and control over your environment.
- Hybrid discovery: Discover assets deeply and quickly, including running configurations and controller run states.
- Comprehensive management: Centralize your asset inventory, vulnerability management, compliance mapping, and anomaly detection.
- Data analytics: Feed Tenable OT data into Tenable One to map relationships, enrich analytics, and enable AI-driven investigations.
[00:07:31] AI architecture and local large language models
You have flexibility when configuring AI models, from cloud-based systems to entirely on-prem local LLMs.
- Model flexibility: Connect Tenable Enterprise Manager to local models like Embra AI and Mistral, or cloud solutions like AWS Bedrock.
- Cost control: Open-weight LLMs help you avoid unpredictable token maxing and token costing.
- Data privacy: Running local models ensures your data stays entirely on-prem, giving you control over hardware and technical debt.
[00:11:44] Setting up your on-prem AI architecture
Connecting your AI models to native APIs requires a specialized translation layer.
- Model Context Protocol (MCP): Use an MCP layer to give your AI the routing capability to understand dictionaries and make intelligent API queries.
- Harness options: Implement server-based harnesses like LibreChat or Goose to handle tool calling securely.
- Customization: Build or modify your own MCPs using stable GraphQL APIs to pull data effectively.
[00:13:59] Best practices for prompt engineering
Because LLMs are stateless, you must craft well-structured prompts to guide the AI and manage context windows.
- System prompts: Embed repetitive instructions in the system prompt to reduce hallucination and set the role, audience, and objective.
- Context management: Monitor token consumption in local models, as large system prompts take up valuable context memory.
- Skills routing: Use targeted prompts, or skills, for specific operations to reduce data loads and improve system scalability.
[00:18:46] Practical demonstration of agentic AI
We demonstrate how a local LLM can interact directly with Tenable OT to identify active issues in your environment.
- Hardware setup: You can achieve strong multi-user capacity with a well-funded enterprise server running modern GPUs.
- Secure environments: Server-based agents prevent exposure to local file systems while enabling secure logging and reporting.
- Live querying: Use natural language to list sensors, identify offline devices, and rank vulnerabilities by VPR scores.
[00:27:40] Addressing hardware diagnostics and security controls
AI models offer unique ways to diagnose hardware and interact with complex security systems.
- Physical diagnostics: You can grant your MCP shell access to diagnose network interfaces directly on physical hardware.
- Write safeguards: You can configure default safeguards to prevent unauthorized AI actions, like initiating active scans.
- Tenable AI integration: Use Tenable AI within Tenable One to enforce guardrail checking and ensure safe AI execution.
[00:29:16] Investigating incidents and assessing risk profiles
Interactive chat sessions allow you to uncover hidden network insights faster than reviewing standard dashboards.
- Asset investigation: Query specific subnets to find unresolved events, major faults, and high-risk assets.
- Event correlation: Identify recurring failure patterns across maintenance windows to isolate intrusion attacks.
- Risk profiling: Ask the AI to evaluate asset groups and pinpoint machines that represent severe physical safety or fatality risks.
[00:38:56] Future Tenable OT initiatives and use cases
We are actively building new capabilities to help you classify devices and streamline policy management.
- Asset classification: Soon, you can package unidentified device data for AI analysis to generate prospective decoders on the fly.
- Prompt enhancements: We are refining prompts specifically for OT data to improve active operations and asset enrichment.
- Active operations: Use AI to automate complex processes, identify unpatchable devices, and recommend missing security policies.
[00:45:36] Automating reports and managing AI hallucinations
AI significantly reduces the manual effort required to generate actionable intelligence for your stakeholders.
- Custom reporting: Use AI tools to instantly generate risk reports detailing critical vulnerabilities and immediate recommendations.
- Hallucination management: Write precise prompts to prevent the AI from fabricating data or entering conversational loops.
- Operational efficiency: Let the AI handle the heavy lifting of parsing data, allowing your team to focus on strategic security decisions.
Tenable One
Demo anfordern
Die weltweit führende KI-gestützte Plattform für Exposure Management
Vielen Dank
Vielen Dank für Ihr Interesse an Tenable One.
Ein Vertriebsmitarbeiter wird sich in Kürze mit Ihnen in Verbindung setzen.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success