AI In Production in OT, Today, Right Now, Not In The Future
Clint Bodungen
S4x24 - ICS Security Conference · Day 1 · Main Stage
Overview
Clint Bodungen's presentation at S4 challenges the industrial community's traditional reluctance to adopt new technologies, particularly in the realm of software. The talk, titled "AI In Production in OT, Today, Right Now, Not In The Future," serves as a practical guide for operational technology (OT) environments looking to leverage the transformative power of generative AI, specifically Large Language Models (LLMs). Bodungen argues that while the industrial sector is often slow to embrace change due to critical safety and operational concerns, generative AI presents an opportunity too significant to ignore, akin to historical breakthroughs like the printing press or the internet.

Key moments
- 0:00 Introduction: Generative AI in OT, safety, and value
- 2:00 Overview of practical AI use cases in OT
- 3:19 Demo: AI for asset and network risk analysis
- 4:00 Demo: Automating incident response tabletop exercises
- 5:01 Key to safety: Using private open-source models
- 6:01 Finding and utilizing open-source models via Hugging Face
AI In Production in OT, Today, Right Now, Not In The Future
Speakers: Clint Bodungen
Conference: S4
YouTube: https://www.youtube.com/watch?v=VFS37IZzFXg
Overview
Clint Bodungen's presentation at S4 challenges the industrial community's traditional reluctance to adopt new technologies, particularly in the realm of software. The talk, titled "AI In Production in OT, Today, Right Now, Not In The Future," serves as a practical guide for operational technology (OT) environments looking to leverage the transformative power of generative AI, specifically Large Language Models (LLMs). Bodungen argues that while the industrial sector is often slow to embrace change due to critical safety and operational concerns, generative AI presents an opportunity too significant to ignore, akin to historical breakthroughs like the printing press or the internet.
The core of Bodungen's message is not whether OT organizations should use generative AI, but how they can do so safely and effectively in production environments today. He highlights several real-world use cases where AI is currently augmenting human capabilities and delivering tangible value, focusing heavily on the critical aspect of data privacy and security. By demonstrating practical applications and outlining a secure architectural approach, the talk aims to demystify generative AI for OT professionals and empower them to explore its potential without compromising the integrity or safety of their systems.
Background
▶ Watch: Introduction: Generative AI in OT, safety, and value (0:00)
The operational technology (OT) sector has historically approached new software technologies with caution, a stance driven by the inherent risks associated with industrial control systems (ICS) and critical infrastructure. Unlike IT environments, disruptions in OT can lead to physical damage, environmental incidents, production outages, and even loss of life. This high-stakes environment necessitates rigorous testing, lengthy validation cycles, and a strong preference for proven, stable solutions, often leading to a slower adoption rate for emerging technologies.
However, the rapid advancements in artificial intelligence (AI), particularly generative AI and Large Language Models (LLMs), have created a paradigm shift that the OT community can no longer afford to ignore. These technologies, capable of understanding, generating, and manipulating human-like text, images, audio, and other data, hold immense potential for efficiency gains, enhanced decision-making, and improved security posture. The challenge for OT lies in reconciling this potential with the paramount need for safety and security. Concerns about data exposure, model reliability, and the potential for AI-induced errors are significant hurdles.
Bodungen explicitly differentiates generative AI from "classical AI and machine learning," emphasizing that his discussion focuses on the former. He acknowledges the natural questions arising in the OT space: Is this technology inevitable? Can it provide value? And most critically, is it safe and can it be implemented securely? The talk is framed as an answer to the "how," providing practical examples and a secure framework for current, in-production applications, rather than a debate on the "should." This pragmatic approach underscores the urgency and relevance of integrating cutting-edge AI into an often conservative industrial landscape.
Key Findings
▶ Watch: Demo: AI for asset and network risk analysis (3:19)
Clint Bodungen's presentation reveals several key findings demonstrating the immediate and safe applicability of generative AI in OT environments. The overarching discovery is that generative AI, specifically Large Language Models (LLMs), can be deployed today to significantly augment human capabilities across various critical security and operational functions, provided specific architectural and data privacy considerations are met.
The primary findings revolve around practical, real-world use cases that Bodungen and his customers are actively implementing:
- Enhanced Risk and Attack Surface Analysis: Generative AI can aggregate vast quantities of data from asset management systems and Security Information and Event Management (SIEM) platforms. It then rapidly performs detailed risk analyses, identifies attack surfaces, and even maps out MITRE ATT&CK TTP chains (Tactics, Techniques, and Procedures). This drastically reduces the time and effort traditionally required for such complex analyses.
- Automated Network Diagram Analysis: The technology can ingest and analyze images of network diagrams, extrapolating system details, identifying potential risks, and uncovering threats that might be missed in manual reviews. This capability is particularly valuable in OT, where network topologies can be complex and documentation may be outdated.
- Streamlined Vulnerability Management: By aggregating and processing data related to vulnerabilities, generative AI assists in the decision-making and process of vulnerability management, moving beyond mere assessment to active, informed management.
- Revolutionized Incident Response Preparedness: A significant finding is the ability of AI to automate and facilitate tabletop exercise planning. It can generate dynamic scenarios, create realistic injects, produce detailed logs, and even provide voice narration, transforming a process that traditionally takes weeks into a matter of seconds. This allows for more frequent, varied, and realistic training scenarios.
- The Imperative of Private, Open-Source Models: The most critical finding for secure OT integration is the necessity of using local, private, open-source models. This architecture ensures that sensitive operational data remains on-site and does not leave the organization's control, mitigating the significant privacy and security risks associated with sending data to public cloud-based services like ChatGPT or proprietary APIs. This approach is fundamental to achieving safe and secure AI adoption in OT.
In essence, Bodungen demonstrates that generative AI is not merely a future prospect but a current reality for OT, capable of delivering immediate value by augmenting human expertise and accelerating critical security processes, all while adhering to stringent data privacy requirements through the strategic use of open-source technologies.
Technical Deep Dive
▶ Watch: Demo: Automating incident response tabletop exercises (4:00)
The technical foundation for securely deploying generative AI in OT environments, as presented by Clint Bodungen, hinges on a crucial architectural principle: the exclusive use of private, open-source models. This approach directly addresses the primary security concern in OT—data exfiltration and privacy—by ensuring that all sensitive operational data remains on-site and within the organization's control.
Bodungen explicitly differentiates this methodology from interacting with public services like ChatGPT or proprietary cloud-based APIs (e.g., the OpenAI API). When data is sent to these public endpoints, it travels into "the cloud, into the ether," exposing potentially sensitive industrial information. In contrast, the recommended strategy involves "writing code, writing apps on top of or in using APIs" that interface with locally hosted models.
The core components of this technical strategy include:
- Open-Source Model Selection: The bedrock of the secure architecture is the utilization of open-source models. These models are publicly available and can be downloaded, hosted, and run entirely within an organization's private infrastructure. This ensures that no data leaves the controlled environment. Bodungen highlights Hugging Face as a prominent platform where a vast array of such models can be found. Hugging Face hosts models for diverse purposes, including multimodal models capable of processing and generating various data types such as voice, audio, image creation, and image recognition, which are critical for the demonstrated OT use cases.
- Local API Integration: Instead of calling external cloud APIs, applications are developed to interact with local APIs that expose the functionality of the on-site open-source models. This allows developers to build custom applications that leverage the power of generative AI while maintaining full control over the data flow. The "five steps, five categories" mentioned by Bodungen, though not explicitly detailed in the transcript, are implied to represent the structured process for selecting, deploying, integrating, and operationalizing these models within a secure OT context. The foundation of these steps is undeniably the open-source model choice.
- Data Processing and Analysis:
- Asset Management and SIEM Data: For risk and attack surface analysis, the system ingests large volumes of structured and unstructured data from existing asset management systems and SIEMs. The locally hosted LLM then processes this data to identify vulnerabilities, analyze potential threats, and generate insights such as MITRE ATT&CK TTP chains. This involves natural language understanding (NLU) to interpret textual descriptions and potentially graph analysis capabilities to map relationships between assets and threats.
- Network Diagram Analysis: For network diagrams, multimodal models with image recognition capabilities are employed. These models can take an image (e.g., a scanned drawing or digital diagram) of an OT network, parse its components (PLCs, HMIs, switches, firewalls), identify connections, and extrapolate system details. The extracted data can then be analyzed by the LLM for security risks and potential attack vectors.
- Vulnerability Management: The AI assists by correlating vulnerability data from various sources, providing context, suggesting prioritization based on risk, and aiding in the generation of mitigation strategies. This leverages the LLM's ability to synthesize information and provide actionable recommendations.
- Dynamic Content Generation for Tabletop Exercises:
- This is a sophisticated application of generative AI, utilizing multimodal models extensively.
- Scenario Generation: Based on initial settings provided by a user, the LLM dynamically generates an entire incident response scenario tailored for a critical infrastructure setting.
- Dynamic Injects: The AI creates "injects"—additional pieces of information or events that unfold during the exercise—in real-time, responding to participants' actions and decisions.
- Detailed Log Generation: To enhance realism, the AI dynamically generates detailed, context-specific logs (e.g., SIEM alerts, network traffic logs, process control system events) that support the evolving narrative and injects. This ensures that the exercise feels authentic and provides relevant data for participants to analyze.
- Voice Narration: Leveraging text-to-speech capabilities within the multimodal model, the AI can even provide dynamic voice narration, making the exercise more immersive and human-like in its facilitation.
By exclusively using private, open-source models, OT organizations can harness the power of generative AI for these complex tasks, ensuring that their critical operational data remains secure and compliant with industrial security mandates. This approach offers a powerful pathway for accelerating security operations and enhancing resilience without introducing unacceptable risks.
Demo / Proof of Concept
▶ Watch: Key to safety: Using private open-source models (5:01)
Clint Bodungen presented a video demonstration showcasing several in-production applications of generative AI within OT environments, emphasizing that these solutions are not theoretical but actively delivering value today. The demonstrations highlighted the speed, efficiency, and security benefits derived from using local, private, open-source models.
The demo covered three primary use cases:
- Asset Management and Risk Analysis:
The first part of the demonstration illustrated the aggregation of extensive data from an asset management system and various vulnerability sources. The AI system rapidly analyzed this aggregated data to provide a comprehensive risk analysis and attack surface analysis. Crucially, it was shown identifying specific MITRE ATT&CK TTP chains, offering a detailed understanding of potential adversary behaviors and pathways within the OT environment. This process, traditionally labor-intensive and time-consuming, was executed with remarkable speed, demonstrating how AI can quickly distill complex data into actionable security intelligence.
- Network Diagram Analysis:
The second segment focused on the AI's ability to process and understand visual information. A drawing or image of a network diagram was fed into the system. The generative AI then extrapolated all relevant data from the diagram, identifying systems, connections, and potential configurations. This extracted information could then be used for various purposes, including populating asset inventories, assessing network segmentation, and informing planning and preparation for incident response scenarios. The ability to derive structured data from unstructured visual input is a powerful application, especially in OT where legacy systems and documentation often rely on diagrams.
- Automated Tabletop Exercise Planning and Facilitation:
This was perhaps the most compelling part of the demonstration, showcasing the AI's advanced capabilities in incident response preparedness. The demo highlighted how users could input "a few settings" to initiate the creation of a complete tabletop exercise scenario. The AI then took over, dynamically configuring the exercise, setting up the narrative, and generating dynamic injects—events or information presented to participants during the exercise.
A key feature demonstrated was the dynamic voice narration, making the exercise feel more interactive and human-like. For instance, the AI's voice introduced the scenario: "Welcome to today's incident response tabletop exercise. I'm here to facilitate this scenario, guiding you through various challenges and decision points... Throughout this exercise, you will confront a series of events designed to test your team's ability to respond effectively to an incident within a critical infrastructure setting."
Furthermore, the AI dynamically generated detailed logs specific to the evolving scenario, providing realistic data for participants to analyze, such as SIEM or network logs. This capability eliminates the traditional limitations of pre-scripted exercises, allowing for curveballs and dynamic responses to participant decisions. Bodungen emphasized that this process, which typically takes "weeks" to plan and prepare, could be accomplished "in seconds" with the AI, dramatically increasing the frequency and realism of training.
Throughout the demonstration, Bodungen reiterated that "this is all local," and uses a "local private open source model," ensuring "no data leaves the site." This constant reinforcement underscored the talk's central tenet: generative AI can be deployed effectively and securely in OT by keeping sensitive data strictly within the organizational perimeter.
Defensive Implications
▶ Watch: Finding and utilizing open-source models via Hugging Face (6:01)
The secure and practical applications of generative AI in OT, as demonstrated by Clint Bodungen, carry significant defensive implications for organizations operating critical infrastructure. The primary message for defenders is that generative AI, when implemented correctly, can become a powerful force multiplier, enhancing an organization's security posture and operational resilience.
- Enhanced Situational Awareness and Risk Prioritization:
Defenders can leverage generative AI to move beyond reactive security. By aggregating and analyzing vast datasets from asset management systems and SIEMs in near real-time, AI can provide a rapid, holistic view of the OT environment's security posture. This includes identifying critical vulnerabilities, mapping MITRE ATT&CK TTP chains, and performing detailed attack surface analyses much faster than manual processes. This capability allows security teams to prioritize threats based on actual risk to OT assets, enabling more effective resource allocation and proactive mitigation strategies.
- Streamlined Vulnerability Management:
The AI's ability to assist in vulnerability management means that defenders can accelerate the identification, assessment, and remediation planning for vulnerabilities. Instead of merely listing vulnerabilities, the AI can help contextualize them within the OT environment, suggest potential impacts, and even recommend appropriate countermeasures, thereby improving the efficiency and efficacy of patch management and configuration hardening efforts.
- Improved Incident Response Readiness and Training:
The automation of tabletop exercises is a game-changer for incident response (IR) teams. Defenders can now conduct more frequent, diverse, and realistic training scenarios without the weeks of preparation typically required. The AI's ability to generate dynamic injects, detailed logs, and voice narration creates highly immersive and challenging exercises. This leads to better-trained IR teams, improved communication protocols, and a deeper understanding of how to respond to complex cyber incidents in critical infrastructure settings, ultimately reducing mean time to detect (MTTD) and mean time to respond (MTTR).
- Secure Data Handling and Privacy:
Perhaps the most critical defensive implication is the insistence on local, private, open-source models. This architectural choice directly addresses the paramount concern of data privacy in OT. Defenders must ensure that any AI implementation processes sensitive OT data entirely within their controlled environment, preventing accidental or malicious exfiltration to public cloud services. This requires a robust understanding of model deployment, data governance, and the secure configuration of local AI infrastructure. Organizations should actively seek out open-source alternatives and prioritize solutions that guarantee data residency.
- Augmentation, Not Replacement, of Human Expertise:
Bodungen emphasizes that AI should augment human processes and capabilities, not replace them. Defenders should view AI tools as assistants that handle the heavy lifting of data analysis and content generation, freeing up human experts to focus on higher-level strategic decision-making, critical thinking, and complex problem-solving. This collaboration leverages the strengths of both AI (speed, data processing) and human intelligence (intuition, experience, ethical judgment).
In summary, generative AI offers OT defenders the tools to significantly enhance their proactive security measures, streamline operational processes, and dramatically improve their incident response capabilities. However, realizing these benefits is contingent upon a strategic and secure implementation that prioritizes data privacy through the use of private, open-source models.
Key Takeaways
- Generative AI is Here for OT Today: Contrary to common perceptions, generative AI is not a future technology for OT; it's being successfully implemented in production environments right now to deliver tangible value.
- Augment, Don't Replace: Generative AI should be used to augment human capabilities and processes, enhancing efficiency and decision-making rather than replacing human roles, which is particularly crucial in safety-critical OT.
- Data Privacy is Paramount: For secure OT adoption, it is essential to use local, private, open-source models to ensure sensitive operational data remains on-site and does not leave the controlled environment. Avoid public APIs like ChatGPT for sensitive data.
- Practical Use Cases Deliver Immediate Value: Key applications include rapid risk and attack surface analysis, network diagram analysis, vulnerability management assistance, and significantly, the automation of incident response tabletop exercise planning and facilitation.
- Open-Source Models are Key to Security: Platforms like Hugging Face offer a wide array of open-source, multimodal models that can be hosted locally, providing the necessary foundation for secure and private AI deployments in OT.
- Accelerate Critical Security Processes: AI can dramatically reduce the time required for labor-intensive security tasks, such as generating detailed tabletop exercise scenarios and logs in seconds, compared to weeks of manual effort.
About the Speaker(s)
Clint Bodungen is a speaker at the S4 conference, where he presented on the practical applications of AI in operational technology. From the context of his talk, he is involved with organizations or clients who are actively implementing generative AI solutions in production OT environments. His expertise lies in navigating the challenges of new technology adoption within industrial sectors, particularly focusing on how to integrate advanced AI securely and effectively to augment human capabilities and improve cybersecurity posture.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This talk provides a brutally honest and technically sound blueprint for integrating generative AI into operational technology (OT) environments today, not in some distant future. Bodungen cuts through the hype by focusing on a secure, practical architecture utilizing local, private, open-source models. The demonstrated use cases, particularly the automated, dynamic tabletop exercises, offer immediate and significant value for OT defenders, proving that AI can be a powerful force multiplier when implemented with zero tolerance for data exfiltration.
Heather Calloway (CISO) — STRONG ACCEPT
This presentation by Clint Bodungen offers a critically important and timely message for OT leaders: generative AI is not a future concern but a present opportunity, provided it is implemented with rigorous security and data governance. By advocating for local, private, open-source models, Bodungen directly addresses the paramount risk of data exposure, offering a clear and actionable framework for leveraging AI to enhance risk analysis, vulnerability management, and incident response preparedness in high-stakes industrial environments. This approach offers a powerful path to augmenting human capabilities and improving resilience without compromising core operational integrity.