On-Demand Webinar / Exposure Management

Frontier AI for OT: Part 2

On-Demand

Watch the second part of our exclusive double header, Frontier AI for OT, where we explore the evolving landscape of industrial cybersecurity.

As Frontier AI lowers the barrier for sophisticated attacks against organisations with OT environments. Organisations in Critical National Infrastructure, manufacturing and so on have to balance availability and safety, supply chain security in a world now where machine speed threats are targeting these verticals. Organisations must move beyond reactive monitoring to continuous, risk-reducing strategies that focus on truly what is exploitable within their environments.

In this mini-series, Chris and Dominic will guide you through:

Beyond the Checkbox: Mastering OT Exposure Management in the Era of Frontier AI

Watch now

Learn how to shift from reactive monitoring to proactive OT exposure management. We’ll cover how to operationalise security by turning vulnerability and misconfiguration data into actionable insights. By contextualising asset events and analysing potential attack paths before AI-driven threats can exploit them, we will show you how to stop chasing every alert, fulfil regulatory mandates and confidently defend your operational uptime.

Deep Dive Demo: Putting OT Exposure Management and Frontier AI into Action

Watch now by submitting the form!

See these concepts brought to life in a technical demonstration inside the Tenable platform. We will show you how to investigate complex attack paths, apply business context to filter out noise, and isolate the exact exposures threatening your operations.

Click here to review the webinar summary

Practical applications of agentic AI in OT security

In the second part of our Frontier AI for OT mini-series, we explore how you can use agentic AI to interrogate data, identify cyber threats, and streamline security operations. We provide a practical demonstration of integrating local large language models (LLMs) with Tenable OT to enhance your network defenses.

[00:02:47] Defending OT networks at machine speed

As cyber attacks driven by AI accelerate, you must rely on strong foundational security practices to defend your network.

  • Asset discovery: Understand your assets, identify choke points, and map out your network architecture.
  • Attack path analysis: Find viable attack paths and implement compensating controls to break them.
  • Configuration tracking: Validate core OT configurations in real time to ensure unauthorized changes do not occur.

[00:05:27] Core capabilities of Tenable OT and Tenable One

We designed Tenable OT and Tenable One to give you complete visibility and control over your environment.

  • Hybrid discovery: Discover assets deeply and quickly, including running configurations and controller run states.
  • Comprehensive management: Centralize your asset inventory, vulnerability management, compliance mapping, and anomaly detection.
  • Data analytics: Feed Tenable OT data into Tenable One to map relationships, enrich analytics, and enable AI-driven investigations.

[00:07:31] AI architecture and local large language models

You have flexibility when configuring AI models, from cloud-based systems to entirely on-prem local LLMs.

  • Model flexibility: Connect Tenable Enterprise Manager to local models like Embra AI and Mistral, or cloud solutions like AWS Bedrock.
  • Cost control: Open-weight LLMs help you avoid unpredictable token maxing and token costing.
  • Data privacy: Running local models ensures your data stays entirely on-prem, giving you control over hardware and technical debt.

[00:11:44] Setting up your on-prem AI architecture

Connecting your AI models to native APIs requires a specialized translation layer.

  • Model Context Protocol (MCP): Use an MCP layer to give your AI the routing capability to understand dictionaries and make intelligent API queries.
  • Harness options: Implement server-based harnesses like LibreChat or Goose to handle tool calling securely.
  • Customization: Build or modify your own MCPs using stable GraphQL APIs to pull data effectively.

[00:13:59] Best practices for prompt engineering

Because LLMs are stateless, you must craft well-structured prompts to guide the AI and manage context windows.

  • System prompts: Embed repetitive instructions in the system prompt to reduce hallucination and set the role, audience, and objective.
  • Context management: Monitor token consumption in local models, as large system prompts take up valuable context memory.
  • Skills routing: Use targeted prompts, or skills, for specific operations to reduce data loads and improve system scalability.

[00:18:46] Practical demonstration of agentic AI

We demonstrate how a local LLM can interact directly with Tenable OT to identify active issues in your environment.

  • Hardware setup: You can achieve strong multi-user capacity with a well-funded enterprise server running modern GPUs.
  • Secure environments: Server-based agents prevent exposure to local file systems while enabling secure logging and reporting.
  • Live querying: Use natural language to list sensors, identify offline devices, and rank vulnerabilities by VPR scores.

[00:27:40] Addressing hardware diagnostics and security controls

AI models offer unique ways to diagnose hardware and interact with complex security systems.

  • Physical diagnostics: You can grant your MCP shell access to diagnose network interfaces directly on physical hardware.
  • Write safeguards: You can configure default safeguards to prevent unauthorized AI actions, like initiating active scans.
  • Tenable AI integration: Use Tenable AI within Tenable One to enforce guardrail checking and ensure safe AI execution.

[00:29:16] Investigating incidents and assessing risk profiles

Interactive chat sessions allow you to uncover hidden network insights faster than reviewing standard dashboards.

  • Asset investigation: Query specific subnets to find unresolved events, major faults, and high-risk assets.
  • Event correlation: Identify recurring failure patterns across maintenance windows to isolate intrusion attacks.
  • Risk profiling: Ask the AI to evaluate asset groups and pinpoint machines that represent severe physical safety or fatality risks.

[00:38:56] Future Tenable OT initiatives and use cases

We are actively building new capabilities to help you classify devices and streamline policy management.

  • Asset classification: Soon, you can package unidentified device data for AI analysis to generate prospective decoders on the fly.
  • Prompt enhancements: We are refining prompts specifically for OT data to improve active operations and asset enrichment.
  • Active operations: Use AI to automate complex processes, identify unpatchable devices, and recommend missing security policies.

[00:45:36] Automating reports and managing AI hallucinations

AI significantly reduces the manual effort required to generate actionable intelligence for your stakeholders.

  • Custom reporting: Use AI tools to instantly generate risk reports detailing critical vulnerabilities and immediate recommendations.
  • Hallucination management: Write precise prompts to prevent the AI from fabricating data or entering conversational loops.
  • Operational efficiency: Let the AI handle the heavy lifting of parsing data, allowing your team to focus on strategic security decisions.

Watch the Full Webinar


Referenten

Chris Baker
Chris Baker

OT Security Sales Manager, Tenable

Photo of Dominic Storey, OT Architect / Principal Security Engineer, Tenable
Dominic Storey

OT Architect / Principal Security Engineer, Tenable

Ressourcen

Lösung

Achieve Canada CCSPA (Bill C-8) compliance with Tenable One OT Exposure

Lösung

Tenable for DoD: Cybersecurity beyond ACAS

Whitepaper

Ein strategisches Briefing zu Frontier-KI und Exposure Management