> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# OT Security May Hold the Blueprint for Securing IT and AI
- URL: https://www.cybrsecmedia.com/ot-security-may-hold-the-blueprint-for-securing-it-and-ai/
- Published: 2026-08-19T12:30:10.000Z
- Updated: 2026-08-19T20:02:40.000Z
- Description: Xage Security’s Roman Arutyunov argues that OT’s toughest constraints forced it to solve security problems the rest of the enterprise is only now confronting. (Sponsored by Xage)
- Author: Bill Brenner
- Tags: AI and OT Security, IT-OT convergence, AI Governance, Article

For years, the cybersecurity industry has talked about bringing IT security into operational technology.

Firewalls moved toward the factory floor. Identity controls expanded into industrial environments. Zero Trust, segmentation, vulnerability management and other practices developed largely around enterprise IT were adapted — sometimes awkwardly — for manufacturing plants, power systems, transportation networks and other critical infrastructure.

But what if that flow is starting to reverse?

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

What if some of the security architecture developed to protect OT is exactly what enterprise IT, cloud infrastructure and now artificial intelligence need?

Roman Arutyunov, co-founder and chief product officer at Xage Security, made that case during the latest episode of CYBR.SEC.CAST. And his argument starts with something OT security practitioners have understood for years: Industrial environments are brutally unforgiving places to build cybersecurity.

**Full episode and related article:**

[Pulling Pranks with Roman ArutyunovExplore how Zero Trust must evolve for agentic AI as Xage’s Roman Arutyunov shares practical ways to secure critical systems, data and AI access![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-66dcc005-884d-4fda-93d3-3809bf595022.jpg)CYBR.SEC.Media, and CYBR.SEC.Media![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/Roman-Arutyunov_Ghost-b6d7cefe-6131-4dcd-9e9e-3415f825a6c1.png)](https://www.cybrsecmedia.com/pulling-pranks-with-roman-arutyunov/)

[AI Agents Are Already Inside. Zero Trust Has to Catch UpAs autonomous AI agents gain privileged access to enterprise systems, Xage Security’s Roman Arutyunov explains why Zero Trust, least privilege and continuous authentication are becoming critical controls for securing agentic AI. (Sponsored by Xage)![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-ee969275-26c7-4c3b-8c9c-295a0ab98624.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/1b15da2e-423f-4321-9b14-f288db4e4994-08529d62-ad2c-4e3f-a2f9-e66adc0d6e75.png)](https://www.cybrsecmedia.com/ai-agents-are-already-inside-zero-trust-has-to-catch-up/)

## OT couldn't assume the easy stuff

Enterprise security architecture has historically benefited from assumptions that don't necessarily survive contact with operational technology.

A device probably has an identity. Software can probably be updated. A protocol probably supports modern security controls. A network connection can probably be interrupted without something physically dangerous happening.

OT practitioners don't get to make those assumptions.

Industrial environments can contain decades-old equipment, vulnerable protocols, assets without credentials, systems that cannot easily be patched and devices that have to remain available continuously.

Security also has to operate across enormously diverse environments.

Arutyunov argues that those constraints forced companies working deeply in OT to develop controls capable of protecting systems under conditions that enterprise IT security products weren't originally designed to handle.

“You think about the variety of type of situations you have in OT,” he said.

That includes a deceptively difficult question: How do you protect an asset that doesn't even have credentials?

Then there are vulnerable protocols, highly distributed infrastructure and the simple reality that many OT environments don't have large security teams available to babysit complicated technology.

“There’s not many resources,” Arutyunov said. “So it has to be really simple to deploy. It just has to work.”

Those limitations weren't edge cases.

They shaped the architecture.

**Related:**

[Agentic AI Is Pushing Zero Trust Into Its Next PhaseZero Trust was designed to control people and machines. The rise of autonomous AI agents is forcing security teams to extend those same principles to software capable of making decisions and taking action on its own. (Includes infographic)![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-46e3d862-a699-400c-b2a1-2c435e8ab138.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/2c81ae53-6288-4ad4-b3ae-bd2926aec100-ffef011e-0d30-4444-bd3e-c3c045b20cd2.png)](https://www.cybrsecmedia.com/agentic-ai-is-pushing-zero-trust-into-its-next-phase/)

[The Purdue Model Is Aging: Here’s Why Operators Are Looking Toward 2.0The Purdue Model has long been the GuideStar for securing factories, power plants, and water systems: layer your sensors at the bottom, controllers above, and tie it all to enterprise IT at the top with firewalls segmenting between. Simple. Effective. Or so the industry told itself.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-c771a21e-48d0-4e8d-af56-bfecfa23b4c6.jpg)CYBR.SEC.MediaGeorge V. Hulme![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/d70e902e-aece-4204-a77d-e514d45594db-b393d6cb-c5c0-49c3-960a-9d1d7cf6fa96.png)](https://www.cybrsecmedia.com/the-purdue-model-is-aging-heres-why-operators-are-looking-toward-2-0/)

## Billions of connected devices changed the equation

Arutyunov's own career followed the convergence between connectivity and physical infrastructure.

He started working in cybersecurity while still in college, joining a startup that eventually became Blue Coat Systems and helped pioneer enterprise proxy technology.

He later moved into large-scale networking, automation and IoT, helping grow another startup whose technology connected billions of IoT assets before eventually becoming part of ABB.

That brought him into manufacturing, transportation and energy just as those industries were rapidly connecting sensors, meters, controllers and other equipment.

The productivity upside was obvious. So was the security problem.

“My cybersecurity brain kicked in,” Arutyunov recalled. “It’s like, wait a minute, this is great. It’s leading to a lot of productivity improvements, but cyber attacks are just around the corner.”

He ultimately left to start Xage around protecting those environments using a Zero Trust architecture.

The problem wasn't simply that more devices were being connected. The devices themselves were becoming more powerful.

During the CYBR.SEC.CAST discussion, host Michael Farnum pointed to Mirai as an important turning point. Connected devices increasingly combined meaningful computing power with default credentials, poor update mechanisms and ubiquitous internet connectivity.

That created the ingredients for devices themselves to become infrastructure for attacks. Arutyunov sees the same trend accelerating today as autonomous vehicles, robotics and other edge environments gain increasingly powerful computing platforms.

## Solve for OT and everything else starts looking easier

That history produced an interesting outcome. Xage initially concentrated on cyber-physical and OT environments where security had to work across highly distributed systems without introducing single points of failure.

But customers eventually started applying the same architecture elsewhere.

“If you can figure out how to protect that kind of stuff that's sitting at the edge that has all these limitations,” Arutyunov said, organizations can begin applying those techniques to environments that don't necessarily have the same constraints.

Data centers came next. Then cloud infrastructure. Now AI agents are entering the picture. Arutyunov said the architecture Xage originally developed around cyber-physical environments has expanded over the years into enterprise and cloud systems and is now being used to protect agentic AI systems as well.

Instead of taking an enterprise security architecture and figuring out how to make it survive OT, start with an architecture designed for some of the most difficult environments in computing and move it in the opposite direction.

## OT learned to distrust the network a long time ago

There is another reason that approach suddenly looks relevant. Modern enterprise infrastructure increasingly resembles the distributed environments OT security teams have been wrestling with for years.

Applications span data centers and multiple clouds. Workloads appear and disappear. APIs connect services across organizational boundaries. Machines communicate directly with other machines. AI agents add yet another layer.

Agents can operate on endpoints, in cloud environments, inside data centers and potentially at the industrial edge. They can interact with resources distributed across all of them.

That makes security dependent less on where something resides and more on whether every interaction can be identified, authenticated and authorized.

Arutyunov argues that effective Zero Trust therefore has to extend through multiple layers of the technology stack.

An identity should be validated before a network path is provisioned. That path should connect only to resources the identity is authorized to use. Access to applications and credentials should be brokered rather than handed directly to the requesting system.

The objective is to prevent implicit connectivity from becoming implicit trust. Those requirements sound increasingly relevant to enterprise AI. They also sound remarkably familiar to OT.

## Don't rebuild the complexity problem

None of this means enterprises should throw away their existing security stack and replace it with something labeled “OT security.”

The more important lesson is architectural. As organizations attempt to secure increasingly distributed infrastructure, Arutyunov warns against solving each new problem by adding another isolated control.

Organizations can deploy more firewalls. More segmentation products. More privileged access management. More API gateways. More infrastructure around emerging technologies such as MCP.

Eventually, however, they risk assembling a “hodgepodge of tools” that must be stitched together to enforce what should be a consistent security policy.

That complexity doesn't merely increase operational costs. It can create security gaps and fatigue among the people expected to operate it. OT security has historically had less tolerance for that kind of complexity because the environments themselves impose harder constraints.

Systems have to stay available. Security teams can be small. Equipment can remain deployed for decades. Some assets cannot support the security software an enterprise team might normally install.

And failure can have consequences considerably more serious than an employee losing access to email.

That forced OT security architects to think differently.

## Maybe IT has been looking in the wrong direction

Near the end of the CYBR.SEC.CAST conversation, co-host Sam Van Ryder pointed out how unusual the direction of travel has become.

Usually, he noted, IT security companies try to move into OT. Now we're seeing some movement in the other direction. Arutyunov believes there's a reason.

Companies that “cut their teeth” protecting operational technology have had to build deeper security technologies because of the sheer variety of conditions they encounter.

Assets without credentials. Vulnerable protocols. Limited resources. Distributed infrastructure. Systems that can't simply be shut down when security becomes inconvenient.

For decades, cybersecurity's assumption was that OT needed to catch up with IT.

The explosion of cloud infrastructure, connected devices and autonomous AI may be exposing the flaw in that thinking.

Enterprise technology is becoming more distributed, autonomous and difficult to control.

Those problems aren't entirely new.

OT has been living with them for years.

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)