Deployed defensively, however, AI can do the opposite: show unmanaged OT assets, monitor vendors for leaked credentials in real time and reduce the gap between detection and response. As he puts it, AI is best understood as“ a force multiplier for conventional controls”, not a replacement for segmentation, patching and multifactor authentication.
Regulation is catching up Governments are starting to formalise what Sheetal describes as a shared obligation. In the European Union( EU), the NIS2 Directive extends cybersecurity accountability beyond criticalinfrastructure operators to mid-sized manufacturers and their suppliers, with supply chain risk assessment written into its minimum security measures.
The Cyber Resilience Act adds obligations on the product side, requiring manufacturers to build cybersecurity into connected products before sale and support them for years afterwards.
The EU Machinery Regulation goes further, embedding resistance to unauthorised access and tampering into the essential safety requirements
102 October 2026