← Back to Articles
22 August 2026 · Critical Infrastructure · Security Architecture · 7 min read

Written by

Critical Infrastructure Was Designed To Be Reliable. Now It Must Be Designed To Survive AI-Assisted Attacks.

Power, water, transport, manufacturing and telecommunications were designed to keep running. As AI reduces the time and expertise required to attack industrial environments, their architecture must also be designed to contain compromise and recover safely.

Power, water, rail, telecommunications and industrial systems continue operating behind layered blue security boundaries while an amber AI-assisted threat is contained at the perimeter.

Critical infrastructure was built around a simple expectation.

It must keep running.

Power must remain available.

Water must continue flowing.

Transportation systems must remain operational.

Factories must continue producing.

Telecommunications must stay connected.

For decades, reliability was the dominant design objective.

Cybersecurity was important, but often secondary to availability, safety and operational continuity.

That balance is now changing.

Recent warnings around Siemens S7 programmable logic controllers show why.

In August 2026, U.S. agencies warned that Siemens S7 Series PLCs used across water, energy, manufacturing and other critical sectors were being actively targeted. The advisory highlighted concern that attackers were using AI to reduce the technical expertise and time required to develop working exploits against industrial environments. Reuters reported the warning here.

The lesson is bigger than Siemens.

The systems that were designed to be reliable must now also be designed to survive increasingly automated attacks.

Critical Infrastructure Was Built For A Different Threat Model

Operational Technology and Industrial Control Systems were historically designed for controlled environments.

Many systems assumed:

That world no longer exists.

Industrial environments are increasingly connected to enterprise IT.

Cloud platforms collect operational data.

Remote maintenance is common.

Vendors require external connectivity.

APIs integrate industrial systems with business processes.

AI is beginning to optimise industrial operations.

Connectivity creates efficiency.

But every new connection also creates another possible attack path.

The architecture has changed.

The threat model must change with it.

AI Does Not Need To Invent A New Attack

The immediate concern is not that AI will suddenly invent completely new cyber techniques.

The existing ones are already enough.

Reconnaissance.

Credential theft.

Vulnerability discovery.

Privilege escalation.

Lateral movement.

Configuration manipulation.

The difference is that AI can help attackers perform these activities faster and at greater scale.

The Siemens S7 warning is important precisely because the concern is not a completely new class of attack.

It is the reduction of time and expertise required to attack an environment that was traditionally difficult to understand.

That changes the economics of attacking industrial systems.

A technique that once required deep specialised knowledge can gradually become more accessible.

And when the target controls a physical process, that matters.

Lower Skill Does Not Mean Lower Impact

Historically, attacking industrial systems required specialised knowledge.

An attacker needed to understand protocols.

Controllers.

Industrial processes.

Engineering environments.

Safety implications.

That expertise created a natural barrier.

AI may gradually reduce it.

A less experienced attacker can ask an AI system to explain unfamiliar protocols.

Analyse configurations.

Interpret technical manuals.

Generate scripts.

Identify likely vulnerabilities.

Suggest the next step.

This does not suddenly make every attacker an industrial-control expert.

But it reduces the distance between curiosity and capability.

And critical infrastructure has something ordinary IT systems do not.

Cyber actions can create physical consequences.

A compromised email account is serious.

A compromised industrial process may affect production, safety or essential services.

Availability Alone Is No Longer Enough

Traditional industrial architecture places enormous emphasis on availability.

Understandably so.

A security control that interrupts production can itself create operational risk.

This has sometimes produced a dangerous assumption:

If the system is stable, leave it alone.

Legacy operating systems remain.

Old protocols remain.

Unsupported components remain.

Network architectures remain unchanged for years.

Reliability becomes confused with security.

But a system can be extremely reliable and still be insecure.

The fact that something has operated successfully for ten years does not mean it can survive tomorrow's attacker.

Segmentation Must Become Real

Network segmentation has been discussed in industrial security for years.

But diagrams sometimes show segmentation more strongly than reality does.

A firewall exists between IT and OT.

Yet numerous exceptions are allowed.

Vendor connections bypass normal paths.

Shared identities exist across environments.

Administrative workstations connect to multiple zones.

Monitoring is inconsistent.

A determined attacker does not care what the architecture diagram says.

They care about the path that actually works.

Critical infrastructure therefore needs segmentation that is enforceable, monitored and regularly tested.

Not merely documented.

The objective should be simple:

A compromise in corporate IT should not automatically become a compromise of operational technology.

Identity Is Becoming An OT Security Problem Too

Industrial security has traditionally been highly network-centric.

That is understandable because industrial environments were built around devices and network zones.

But modern OT increasingly depends on identity.

Engineers authenticate remotely.

Vendors connect for maintenance.

Service accounts operate industrial applications.

Cloud services consume operational information.

Privileged administrators cross IT and OT environments.

Once identities cross these boundaries, identity becomes part of the industrial attack surface.

This is the same broader shift discussed in The New Security Perimeter Is No Longer The Network. It Is Identity.. Modern trust increasingly depends on who or what is requesting access, not simply where that request originates.

Strong authentication, Privileged Access Management, time-limited access and session monitoring therefore become just as important as firewalls.

A compromised identity should not become a passport across the entire environment.

Critical Systems Need Their Own Security Architecture

Not every system should be protected equally.

For truly critical operational environments, additional architecture should exist around the crown jewels.

Dedicated administrative workstations.

Separate privileged identities.

Restricted management paths.

Independent monitoring.

Controlled remote access.

Strong network boundaries.

Offline recovery capability.

Manual fallback procedures.

The assumption should be that another part of the enterprise may eventually be compromised.

Critical infrastructure must still survive.

That is resilience.

Design For The Failure Of Individual Controls

The Siemens S7 situation also reinforces another important principle.

No individual technology should be treated as infallible.

The PLC may be vulnerable.

The firewall may be misconfigured.

The identity may be compromised.

The remote-access platform may be abused.

The monitoring system may fail to detect the activity.

Good security architecture therefore assumes that individual controls can fail.

The architecture should prevent one control failure from becoming a complete operational failure.

That means independent layers.

Different trust boundaries.

Segregated administrative paths.

Multiple verification points.

And tested recovery.

This is the same principle behind Good Security Architecture Assumes Every Control Will Eventually Fail.

The objective is not to build perfect controls.

It is to build an environment that remains defensible when one of them is no longer perfect.

AI Can Help Defenders Too

AI is not exclusively an offensive advantage.

The same technology can help defenders identify vulnerabilities, analyse unusual behaviour and accelerate investigations.

AI-assisted threat modelling.

Automated configuration analysis.

Continuous exposure assessment.

Behavioural monitoring.

Faster incident investigation.

These capabilities may become particularly valuable in industrial environments where systems are complex, long-lived and difficult to change.

But defensive AI still needs governance.

Automation without boundaries can introduce another operational risk.

Recovery Must Be Designed Before The Incident

One principle becomes increasingly important.

Assume something will eventually fail.

A controller.

An identity.

A firewall.

An engineering workstation.

A vendor connection.

An AI-assisted attack may simply discover the weakness faster.

The organisation must therefore know how operations continue when that failure occurs.

Can critical systems operate manually?

Can configurations be restored?

Are backups isolated?

Are recovery procedures tested?

Can compromised identities be revoked quickly?

Are operators trained to run without normal digital services?

Cyber resilience is not simply having backups.

It is knowing how the organisation continues operating while technology is under attack.

Final Thoughts

Critical infrastructure was designed around reliability.

That principle remains essential.

But reliability alone is no longer enough.

The Siemens S7 warnings demonstrate how the attack landscape is changing.

AI does not need to create completely new attack techniques to become dangerous.

It only needs to reduce the skill, effort and time required to use the techniques that already exist.

Future critical infrastructure architecture must therefore combine reliability with resilience.

Connectivity must be controlled.

Identities must be governed.

Segmentation must be enforceable.

Critical assets must have stronger boundaries.

Recovery must be tested.

And organisations must assume that sophisticated cyber capabilities will gradually become accessible to more attackers.

The objective is not to predict every AI-assisted attack.

It is to design environments where one successful attack does not become a catastrophic operational failure.

Because the systems that keep society running cannot depend on attackers remaining slow, inexperienced or predictable.

Critical infrastructure must continue to be reliable.

But now it must also be designed to survive.

Question assumptions. Share knowledge. Build trust.

Share this article

If this perspective was useful, share it with your network.