Skip to content

Agentic AI Is Coming to Critical Infrastructure Security — But Autonomy Must Have Its Limits

Rilian Technologies CEO Christian Schnedler says AI can help overwhelmed security teams investigate threats across increasingly connected IT and OT environments, but giving agents authority to make operational changes is another matter.

Agentic AI may be making its way into security operations centers, but applying the technology to critical infrastructure requires a very different approach to automation.

That was one of the central themes of a recent CYBR.HAK.CAST conversation with Christian Schnedler, CEO and co-founder of Rilian Technologies, who joined hosts Phillip Wylie and Michael Farnum to discuss the growing intersection of artificial intelligence, security operations and operational technology.

Full episode:

AI, OT Security and Critical Infrastructure With Schnedler
Christian Schnedler explores AI, OT security, air gaps and human oversight as critical infrastructure becomes more connected and automated.

Schnedler’s interest in critical infrastructure security stretches back well before the current AI boom.

Early in his career, he worked on large-scale data fusion and “safe city” projects before becoming involved with the New York Police Department’s Lower Manhattan Security Initiative. The public-private initiative brought law enforcement and financial institutions together to share physical security and threat information in the years after 9/11.

During the Occupy Wall Street protests, Schnedler said he was tasked with leading a red-team effort examining whether hacktivists could compromise infrastructure accessible from around Zuccotti Park and what the potential impact of such an intrusion might be.

That experience helped shape a career that would later include public safety work in the Middle East and Africa, a return to the NYPD as a civil servant, and eventually a role as a group CISO at a private equity firm where he also worked with investments in cybersecurity and defense companies.

Critical infrastructure isn't as isolated as organizations think

The conversation eventually turned to one of OT security’s longest-running assumptions: the air gap.

Industrial environments have traditionally relied heavily on isolation to protect operational systems. But Schnedler argued that economic and operational pressures are steadily eroding those boundaries.

Critical infrastructure operators increasingly need centralized monitoring, automation and access to operational data. Those requirements mean more assets are being connected, even in organizations that continue to think of their environments as largely isolated.

“In practice, we have yet to come across a critical infrastructure organization of any real size that is actually honoring the Purdue all the way they think they are,” Schnedler said.

Competitive pressures, he added, are pushing organizations to connect more systems so they can centrally monitor and automate operations.

Farnum noted that many of those connections are driven by business rather than security requirements. Organizations need operational data for auditing, accounting and other functions, making complete isolation increasingly impractical.

Even environments designed to remain air-gapped aren't immune to another familiar cybersecurity problem: people.

Schnedler recounted an incident involving a sensitive law-enforcement system that was supposed to be isolated. A maintenance worker, tired of manually transferring updates and working inside a cold data center, connected a phone to create a hotspot. The systems subsequently became infected with ransomware.

The lesson, Schnedler said, is that organizations should treat supposedly isolated environments as though they could eventually become connected or otherwise exposed.

Using agents to cut through SOC complexity

That changing environment is part of the problem Rilian is attempting to address with agentic AI.

Schnedler described a security operations environment overwhelmed by tools, data feeds and interfaces. Rather than expecting analysts to become experts in every product, Rilian's approach uses layers of specialized agents to interact with those underlying technologies.

At one level, agents can become specialized in particular security products. Another layer understands broader technology categories such as endpoint detection and response or cyber threat intelligence. Primary agents can then orchestrate work across those specialized agents to accomplish a larger task.

For vulnerability management, for example, one agent might collect asset information from a configuration management database while another queries vulnerability scanning systems and another examines threat intelligence for exploits or newly discovered vulnerabilities.

A higher-level agent can correlate that information and present a conclusion to the analyst, with traceability back to the sources used to reach it.

The objective isn't simply to put a chatbot in front of existing security tools. It is to automate much of the investigative work analysts currently perform manually across multiple systems.

Schnedler also emphasized the importance of containing those agents. Rilian runs agents inside a controlled environment defining which tools, data feeds and network resources they can access. Additional controls inspect responses from the underlying large language models and allow organizations to establish guardrails around what individual agents can do.

The system is also designed to learn from experienced practitioners. A senior analyst can correct a conclusion — for example, explaining that a particular network path makes a vulnerability more severe than the system initially determined — and that knowledge can be incorporated into subsequent investigations.

That allows practitioners rather than AI engineers to gradually tailor the system around an organization's environment and operating practices.

In OT, autonomous doesn't mean unrestricted

The biggest question is what happens when agentic AI moves beyond investigation and starts taking action.

That's where Schnedler draws a significant distinction between traditional enterprise environments and OT.

Plant operators have good reasons to be cautious about autonomous security systems. An automated response that takes a server offline in an enterprise environment may be inconvenient. Taking the wrong industrial asset offline can create operational and potentially safety consequences.

Schnedler said Rilian isn't trying to convince OT operators that those concerns are misplaced.

“We do not dissuade that fear. It's a healthy fear,” he said.

Instead, the goal is to build systems technically capable of autonomous operation while allowing organizations to decide where that autonomy should end.

In an OT environment, that can mean automating everything from the initial alert through investigation and triage, then stopping before an operational action is taken.

An analyst could receive a package showing what happened, how the agents investigated it, what conclusions they reached, alternative explanations and recommended next steps. The human operator remains responsible for deciding what actually happens to the industrial environment.

Even relatively simple actions such as taking an asset offline generally remain subject to multiple approval layers, Schnedler said.

Financial services organizations, by comparison, are showing greater appetite for true end-to-end automation because of the sheer volume and variety of attacks they face and expectations that adversarial AI will increase both.

AI defense without handing over the plant

The distinction may become increasingly important as AI enters critical infrastructure environments.

Attackers are already experimenting with AI, while defenders face expanding attack surfaces, growing numbers of security tools and persistent shortages of experienced practitioners. At the same time, the IT and OT boundaries that once provided at least some isolation continue to weaken.

That creates a strong case for using AI to accelerate investigation, correlate information and reduce the amount of repetitive work analysts must perform.

It does not necessarily create a case for letting an AI agent shut down a pump, turbine or other operational asset on its own.

For critical infrastructure defenders, the near-term opportunity may therefore be less about creating a fully autonomous SOC than using agentic AI to get humans to better decisions faster.

As Schnedler's comments throughout the conversation made clear, the technology can be built for autonomy without requiring organizations to surrender control.

HOU.SEC.CON CTA

Latest

Microsoft RemoteApp Breakout and Bypasses

Microsoft RemoteApp Breakout and Bypasses

This talk by Jon Rhodes explores security vulnerabilities and evasion techniques targeting Microsoft RemoteApp, focusing on breakout methods that escape the isolated RemoteApp container to access the underlying host system, as well as bypasses for common detection and restriction mechanisms.