Pre-DEFCON Session: Hacking & Defending OT with AI

Pre-DEFCON Session: Hacking & Defending OT with AI

🎙 Mike Holcomb 👥 27K 📅 August 2, 2026 ⏱ 56 min 👁 379 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OTICSAIcybersecuritydefense

Summary

In this pre-DEFCON session, Mike Holcomb discusses the dual use of AI in OT/ICS environments, emphasizing that attackers are leveraging AI to accelerate reconnaissance and attack development, while defenders can use the same technology to analyze and protect industrial systems. He demonstrates using AI tools like Claude to interpret an HMI screenshot from a simulated water treatment facility (LabShark), showing how AI can quickly provide an overview of the environment and suggest attack vectors. Holcomb argues that AI lowers the barrier for attackers, who no longer need deep engineering knowledge, and that defenders must adopt AI to keep pace. He highlights the importance of fundamental security measures, such as network segmentation and asset management, and mentions resources like his OT Threat Feed for tracking incidents. The session includes practical advice on using AI for defensive purposes, such as generating checklists to mitigate attacks, while cautioning against uploading confidential data to AI platforms. Holcomb also touches on broader topics like the use of SBOMs and the potential for AI to eventually take humans out of the loop in OT operations, referencing the movie WarGames. The talk is interactive, with Q&A addressing concerns about latency in network monitoring and the import of foreign OT equipment.

203 words

Critical Evaluation

Value of the Information & Strength of the Argument

The session provides valuable insights into the practical application of AI in OT security, demonstrating real-world use cases with tools like Claude and LabShark. The argumentation is solid, grounded in the speaker’s experience and current threat landscape. Holcomb effectively argues that AI is a double-edged sword, and his demonstration of using AI to analyze an HMI and generate attack scenarios is compelling. He also emphasizes the importance of fundamental security practices, which is a pragmatic approach. However, some claims, such as the speed of AI-driven attacks, are presented without detailed evidence, and the session is more of an expert opinion than a rigorous study.

Scientific Rigor, Source Quality, Title Accuracy

The speaker references known incidents like Colonial Pipeline and mentions tools like LabShark and OT Threat Feed, but does not provide formal citations. The title accurately reflects the content. The session is based on the speaker’s expertise and practical demonstrations, which adds credibility, but the lack of formal references and the anecdotal nature of some claims limit the scientific rigor. The audience interaction shows engagement, but no specific comments are provided for analysis.

192 words

Title / Content Match

The title accurately reflects the content, which focuses on using AI for both attacking and defending OT systems.

Quality & Reliability

7/10

The speaker demonstrates practical expertise in OT security, using real tools and examples. Claims are generally supported by references to known incidents and tools, but some assertions lack detailed evidence and rely on anecdotal experience.

Key Moments

Cited Sources

  • LabShark — Mentioned as a free platform for simulating OT environments
  • OT Threat Feed — Created by the speaker to track OT security incidents

Concurring Sources

  • Dragos — Referenced in the context of the Frosty malware research

Contribution & Novelties

The session provides a practical, hands-on demonstration of using AI to analyze and attack OT environments, which is valuable for defenders. It emphasizes that AI lowers the barrier for attackers and that defenders must adopt similar tools. The speaker’s approach of using AI to generate attack scenarios and then defensive checklists is a novel method for improving OT security posture.

Pour aller plus loin :

98 words

Radar Profile

The radar profile shows a balanced score across all dimensions, with slightly higher scores in information quantity and reliability, indicating a well-rounded presentation. The technical level is moderate, making it accessible to a broad audience.

Reliability 7/10