ics-ottrade-pressNewsThe Broadside2 min read

IST sprints to build AI-OT cyber framework for cash-strapped operators

The 100-day multistakeholder push targets critical-services operators who lack cyber talent, budget, and tools, the tier below existing CISA and NIST guidance.


TL;DR

The Institute for Security and Technology launched a 100-day initiative on August 27 to produce policy guidance for OT/ICS operators who are "target rich, cyber poor", lacking dedicated cybersecurity talent, budget, or tools. Five working groups will address consequence analysis, sector engagement, pragmatic guidance for those operators, novel mitigations, and policy-incentive design, with a report due December 10. IST's framing acknowledges a gap between existing CISA and NIST AI-security guidance and the operational reality of cash-constrained critical-services providers facing AI-enabled threats.

The Institute for Security and Technology is betting that a 100-day sprint can bridge the gap between high-level government guidance and the reality facing operators who run critical services without dedicated cybersecurity resources.

IST announced the "Fragile Foundations Sprint" on August 27 and held an onboarding webinar September 3. The initiative convenes five working groups, each co-chaired by figures from industry and the nonprofit security community: consequence analysis, OT/ICS sector engagement, pragmatic guidance for cyber-poor operators, novel mitigation analysis, and policy and incentive design. A report is targeted for December 10.

The sprint's premise is that existing frameworks from CISA and NIST (including the December 2025 joint guidance on secure AI integration in OT and the forthcoming NIST AI RMF Critical Infrastructure Profile) were built for organizations that have governance machinery. Many critical-services operators, particularly in water and other life-safety functions, don't.

Joshua Corman, IST's executive in residence for public safety, described the target audience as "target rich, cyber poor", operators of OT and ICS systems "where they may not have cyber talent or cyber budget or cyber tools." Corman pointed to recent attacks against vulnerable programmable logic controllers in water systems as evidence that adversaries are exploiting the gap, and flagged that AI-enabled capabilities are accelerating the threat.

IST's August 2025 report on AI "world models" argued that the hard part of attacking industrial control systems has historically been understanding the target well enough to cause specific physical effects, a barrier that AI models with physical-reasoning capabilities are now lowering.

The policy and incentive design working group, co-chaired by Matt Hayden of General Dynamics Information Technology and Megan Samford of Schneider Electric, will have to answer the question that makes this effort distinctive: what makes a cash-constrained water district spend on cybersecurity?

"They want to bring absolute pragmatism to everything they do," IST advisor Jen Ellis said on the webinar, emphasizing near-term tools operators can use now. That framing (and the December deadline) suggests IST sees the window for action narrowing as AI-augmented attacks on under-resourced OT environments become more feasible.


Published ·Deep Fathom