How AI Has Elevated the Path to Compromise in Manufacturing
Al Imran Husain, CISO at MillerKnoll, discusses how AI is changing the path to compromise in manufacturing by increasing the speed and efficiency of attacks, while putting greater pressure on security teams to understand and protect critical IT and OT environments.
AI is not necessarily creating entirely new attack paths. It is making existing paths faster, easier, and more scalable, increasing the importance of segmentation, exposure management, and continuous validation across manufacturing environments.
Episode Chapters & Full Transcript
Select any chapter or transcript timestamp to begin watching from that exact point in the episode.
Full Transcript
Welcome to Conversations with CISOs, Security Leaders, and Technology Executives, where we sit down with the leaders shaping cybersecurity and enterprise technology. Today I'm joined by Al Imran Husain to discuss cybersecurity and manufacturing plants, how AI has elevated the path to compromise. Imran, thank you for taking the time to join me today to get us started. Could you tell us a little bit about your background and your current role?
Yeah, thanks for having us, Sullivan. So my name's Al Imran Husain. I've been in the IT cybersecurity space for the last twenty five years. Pretty much all in information security, compliance risk management, and other areas of that nature. I'm currently the Chief Information Security Officer for MillerKnoll.
Excellent. So you've spent years securing complex organizations and now you lead security in a global manufacturing environment. What makes a manufacturing plant fundamentally different to defend than a traditional corporate IT environment?
Well, I think before we get into that, it's important to recognize what manufacturing and cyber and how they necessarily weren't married from the start. So historically speaking, manufacturing very much like healthcare has been rather I wouldn't call the word lackadaisical, but is not necessarily thinking about security at the forefront.
Part of the reason why is because manufacturing has always been something of manual labor. Even the machineries were pulled with the levers that we see on site at the plants. But of course, as we moved and headed into the future, what you started to recognize was the fact that a lot of these automated pieces could be placed online. And so now the same levers that you see on the plants are being controlled remotely through the internet, through other facets of automation. But what happened as a result was security controls were never considered. And if they were considered, it was very minimal.
So the issue in terms of why manufacturing is so hard to defend is simply because of the fact that we haven't seen cybersecurity and technology catch up to the pieces which have now been placed online. So you need to have those appropriate controls. Ultimately it's all about availability and safety. And that has really been the key difference between why we haven't taken OT as seriously and more importantly as aware as we have with other attack areas or attack surfaces such as IT and cloud.
So before generative AI became widely available, what did the typical path to compromise look like in manufacturing and how has it changed that?
I think the attack path has fundamentally changed. I mean, it's always been there. You know, attackers will look for identities, vulnerabilities, any type of mi misconfigurations, including trusted access. I think what's changed is really the speed and efficiency. That has really been the central focus in terms of why attackers have been using AI. It's because the fact fact that they can create scripts, they can create certain types of attack functionality. That can get to their targets at a much quicker rate.
Now, what that does is that it minimizes the way that EDRs such as attached enhanced detection responses or MDR type of solutions, monitoring detection response solutions, have reacted. And that's a problem because it can certainly number one, the bigger issue is the fact that a lot of monitoring tools doesn't have OT and its landscape incorporated into the areas that it's covering. And as a result of that, it it's not necessarily getting the full scope in terms of what it does need to monitor. And because of that, hackers know it and they can go ahead and start creating much faster types of attacks against those attack pathways to go ahead and compromise their targeted assets.
So as a CISO over a manufacturing organization, what have you done to mitigate some of those risks coming from AI?
Yeah. The most important thing that all manufacturing plants and CISOs and and people who are responsible for their security should know is that basic cyber controls should not be understated. They're as important as any other attack landscape, right? So whether it's IT, the cloud, OT is just as important. And more importantly, your basic cyber controls can do a lot.
So what that basically means is that placing monitoring tools within your OT landscape, within that environment is extremely important. Understanding what your critical assets are. And then also understanding that if those critical assets were impacted, what are the dollars to disruption? And what that basically means is that if that asset was to be compromised, how does that impact your plant? And then more importantly, how does that impact the business?
So you have to understand exactly what you need to protect. OT is very complex, much more complex, I believe, than IT. And because of that, you have to be very, very selective in terms of what where you want to approach your your controls and how to apply it. Given the fact that all of us are concerned about budgeting and what we can do. Utilizing your IT tools within OT is certainly an advantage for those people who have those types of tools. But more importantly, being selective in terms of where you put those controls.
and when we talk about those controls, it's like what I said, monitoring detection, very important. Having proper identity access management. So people don't have keys to the kingdom, segregation of duties within critical assets. making sure that your perimeter or your edges are protected through firewalls or some other type of some other type of external control so that when you allow for remote access to be coming in, it's being very, very guarded, it's being very, very discreet. So all of those things are extremely important in terms of protecting your your OT landscape.
Are there any controls that are something you would recommend very specifically for manufacturing, or is it more that general best practices across cybersecurity?
It's interesting because as the cyber manufacturing the awareness has grown, so too have those tools. So there are now specific type of modules specifically geared towards OT. They understand the assets. So when we talk about assets within OT, we're talking about things such as industrial control systems, SCADA data, shop floor devices, PLC controllers. Those are all important critical tools within OT to find certain types of solutions and tools that are much more intimate with those types of controls are extremely important.
So there are solutions out there which can certainly go ahead and apply themselves much more seamlessly within that area. But if you can't do that because obviously there's a cost associated to
Mm-hmm.
it, then IT tools are certainly a good way of utilizing those tools which exist within your IT environment and then expanding that with an OT. The other thing which is extremely important and people don't talk about it as much is network segmentation. So segmentation is providing guarded perimeters around your OT environment, both externally and internally. If you can separate your IT from your OT, then even if your attack even if your IT was compromised, for them to get into your OT system is much harder. And that limits the blast radius in terms of what that attacker could do.
Okay. So when it comes to AI you know accelerating the attack path becoming widely available, what are some areas that you've seen or are expecting the biggest acceleration to occur?
Well, it's interesting because I think really the the the biggest areas I would say are those connection points between OT and IT. that's probably the place where we would want to first and foremost focus on because the fact that there is there is such a discretionary line between the two that it's very easy for threats to occur right there on the border and then allow for those attacks to happen. In both IT and OT area, right?
Poorly segmented networks are really vulnerable towards those types of attacks. Anything which allows third-party vendor access to come in are also very, very weak when it comes to patrolling and monitoring who has access, remote access provisioning into those respective areas, what someone can do. So, and then finally the machinery itself, right? So when we're talking about some of the assets that I'd mentioned with an OT, making sure that those respective tools have the proper version upgrades, if they are externally facing, what kind of controls do they have around it? So that certainly has a significant impact in terms of how you protect your OT environment.
So on the flip side of those technical areas, how has AI changed the human side of the attack path?
Well, it's made it much more the the AI makes the impersonation much more con convincing, right? So AI has, especially generative AI, has gone from zero to sixty within just a matter of a few years. So when we talk about that, we're talking about how phishing messages are much better written. We're talking about deep fake videos, which are much more realistic. We're talking about any type of social engineering with that infusion of AI, making it much more making it much harder to go ahead and distinguish b between fake and reality.
And I think that's the issue because we don't know how far this is going to go. And we're only talking about a few years time in terms of the advancement of social engineering and the creativity of it. I am very apprehensive to see how things are going to be in the next three or four years. only because the fact that the iterative process of AI is only going to make things much more sophisticated, much more realistic, and harder to distinguish. So it certainly has changed the way attacks are looked at and how we on the security side have to defend that.
So as you alluded to earlier, manufacturing systems, they can't maybe they can't patch or take the systems offline as quickly as maybe another organization could. So how should security teams manage vulnerabilities when it comes to these AI accelerated attack paths?
Yeah. So you have to so like when when we talk about vulnerabilities, you know, we we think about patching. That seems to be the go-to traditional route in terms of how we patch IT assets. Harder to do when it comes to manufacturing and especially with AI into that. You can't just think of patching as the only way of handling or remediating. Or even protecting your respective environment.
It now comes down to, and I know I'm repeating it, but I think it's very important for for me to do that. Segmentation. Obviously that's very important. But access controls, monitoring, application restrictions, any type of vendor controls and other compensating controls. These are words that I echo within IT. They are also considered fundamental, basic hygiene type of controls.
But it's so important to go ahead and start with that basic foundation. And the reason why is because 80% of what we see in terms of attacks normally come from those respective areas. Lack of segmentation can lead to different multiple types of attacks. Lack of access controls allow masquerading impersonation. Lack of application restrictions allow your applications to be compromised very quickly, especially from the outside. So you have to understand exactly why those are so important and why they complement in a significant way much more than patching.
So when manufacturing organizations are dealing with potentially thousands of different vulnerabilities and exposures, how do you determine which ones create a credible path to something that could disrupt production?
Yeah. So I think the most important thing, and hackers normally look at it from the same perspective, is that they look at the attackability based on business impact, right? So when we talk about that, it's very under important to understand they're looking at severity, right? They're looking at the ranking of severity and what is the most damage I can do to that specific business. And so if the vulnerability is reachable and it's accessible and it's exploitable and it has the biggest impact to the business, that's what they're looking for.
What I would do then is you need to start figuring out exactly what are the those most critical attack pathways. And this is very important. When we talk about critical pathways compared to vulnerabilities, those are two separate things. The traditional route of doing things was we look at vulnerabilities, we go ahead and remediate our most critical remediate our most critical vulnerabilities in a timely manner. That only works halfway up to this point.
Now, what we have to look at is realistic attack pathways. Like what can a a hacker expose and what kind of vulnerabilities out there that can actually in reality do some type of significant damage. So vulnerabilities in some way are theoretical and other vulnerabilities are actually realistic. Focus on the realistic because that is what's going to impact your business.
So if AI has allowed attackers to move from discovery to exploitation faster, how does that change how many manufacturers should think about things like penetration testing, vulnerability scanning, and continuous security validation?
Yeah. So all of those things periodic penetration testing is is certainly valuable. I would not go ahead and undermine that. And it's important to do it regularly. I know it can get expensive, but if you have the means, quarterly vulnerability pen testing is very, very important. The reason why is because you're constantly wanting to monitor how your attack pathways may be changing.
Every so often. And I think that's very important to recognize. So as attackers, obviously utilizing AI become faster, we need to continuously improve our exposure management and validate our security controls. And that has to happen frequently. So continuous monitoring against that is extremely important.
It gives you an understanding of where your vulnerabilities are, how they change on a month to month, week to week, even day to day basis. And getting that real type of information, the that data to collect and then crunch that down and understand exactly where those flaws are, where the exposures are on your respective environment with an intimate type of optical lens, that's where you're going to be successful. So periodical security testing, I would highly encourage continuous monitoring. Obviously those are tools. I would highly encourage that as well.
So AI is not only something that attackers use. Obviously defenders n are have access to these capabilities as well. Where do you think AI can give defenders a meaningful advantage?
I really think it's the forensics and audit trails. It's really about connecting the dots. Because when you utilize AI as a service for yourself within information security, you've got the capability of utilizing it in such a way that it can give you information about your respective environment at a much more detailed level. And I think that's really important to recognize because before it was all about utilizing certain types of tools to give you certain information which may have a lot of false positives.
Vulnerability management is only going to give you so much. Exposure management to say we have exploits here and there, it'll only give you so much. What AI is giving you from the defender's perspective is really that intimate look in terms of saying, here are the attack pathways that are certainly going to be able to get into your network. This has a very high probable reach within your network and it can do some certain damage. So I would say utilizing AI, combining the vulnerabilities, the identities, the configuration, kind of bringing all of that together, that gives you the best threat intelligence in terms of how you want to lay out your map, in terms of what you want to go ahead and then apply controls to and restrict and minimize the risk wherever possible.
Excellent. So as we wrap up, looking ahead to the next three to five years, what concerns you more when it comes to AI? Entirely new AI-enabled attacks, or AI making the attack techniques we already know dramatically faster, cheaper, and more scalable?
Well, I think what I'm less concerned about is, you know, new AI attacks than I am about AI making is existing attacks faster and easier to get to. And that's the difference. Those those attack pathways, those exposures that you have within your environment are always going to be there. And sure, new AI attacks can certainly come up whenever they need to.
But what I'm more concerned about is I can only I can only experience and understand what is already out there and there's plenty of AI attacks out there. I need to understand exactly how they are making those things faster. How are they making it more scalable? I think those are the areas that in the next three to five years is what we really need to focus on. What are those attacks which are recurring because we know that they have success, two of them?
And then understand how to go ahead and build up techniques that we need to utilize from a tactical perspective in terms of how to thwart those types of respective compromises. That's going to be really be the key in terms of us building up knowledge on those existing AI attacks, understanding that, and then coming back with strategy in terms of how to minimize the type of attack disruptions they can have. So I would be very concerned about what we have in front of us rather than five years down the road. Because I'm sure there'll be plenty down there, down that path, but we can only go ahead and attack what we know or defend what we know at this time because we know it exists.
All right, excellent. Well, thank you very much. thank you everybody for watching. If you enjoyed this conversation, be sure to like, subscribe, and leave a comment with your thoughts or suggestions for future guests and topics. And thank you again to Al Imran Husain for joining us today.
Thank you, Sullivan.
Conversations With CISOs, Security Leaders & Technology Executives
Hear practical conversations with the executives responsible for protecting complex organizations. Each episode explores leadership, risk management, infrastructure, incident response, governance, and the decisions security leaders make every day.