Cybersecurity AI for OT and robotics — securing the converged attack surface
IT and OT networks are converging. Robotics is adding new classes of endpoints that no traditional IT security tool was designed to protect. The result is an attack surface that spans enterprise IT, industrial control systems and autonomous machines — and the security tooling needs to span it too.
The convergence problem
For decades, IT and OT operated as separate domains with separate security models. IT security focused on confidentiality — protecting data. OT security focused on availability — keeping processes running. The two rarely intersected.
That separation is collapsing. Modern manufacturing, energy, logistics and defence environments connect OT systems to IT networks for monitoring, analytics and remote management. Robotics adds another layer: autonomous machines with sensors, actuators and network connectivity that create entirely new attack surfaces.
The result: an attacker who compromises an IT endpoint can pivot to an OT controller. A vulnerability in a robot's ROS middleware can provide a foothold into the factory network. Traditional IT security tools — designed for Windows endpoints, HTTP traffic and cloud APIs — cannot see, classify or respond to threats that traverse this converged environment.
Why OT is different from IT — and why it matters for AI security
OT environments have fundamentally different security priorities, protocols and constraints. AI security tools that don't account for these differences create more risk than they mitigate.
- •Availability over confidentiality: in OT, an unplanned shutdown can be more costly than a data breach. A security tool that quarantines an OT device the way it would an IT endpoint can cause physical damage, production loss or safety incidents.
- •Legacy protocols: Modbus, OPC UA, DNP3, BACnet — industrial protocols that predate modern security assumptions. They lack authentication, encryption and integrity checking by design. Security monitoring must understand these protocols natively.
- •Air-gapped segments: many OT environments are partially or fully air-gapped. Any security AI deployed here must operate entirely offline — the same air-gapped requirements that apply to defence and critical infrastructure.
- •Safety-critical systems: OT includes systems where incorrect automated action can cause physical harm — process control, robotic actuators, safety instrumented systems. Automated response must be governance-constrained, not unbounded.
What cybersecurity AI brings to OT
AI-driven security for OT is not about applying IT security tools to OT networks. It is about building detection and response that understands the OT context — availability priorities, protocol semantics, and the consequences of automated action.
- •Continuous monitoring without disruption: passive analysis of OT traffic patterns, anomaly detection against learned baselines, no active probing that could disrupt operations.
- •ML detection trained on OT-specific patterns: classification models that understand what normal looks like in industrial environments — process variable ranges, command sequences, communication patterns between PLCs and HMIs.
- •Automated response scoped to not disrupt operations: response actions governed by policy that accounts for OT priorities — alerting and isolating at the network level rather than shutting down control processes.
- •Cross-domain correlation: connecting indicators across IT and OT boundaries — an anomalous login on the IT side correlated with unusual commands on the OT side reveals lateral movement that neither domain sees alone.
The robotics angle — where the attack surface is newest
Robotics introduces attack surfaces that neither IT nor traditional OT security has encountered: sensor manipulation, control injection, middleware vulnerabilities and autonomous decision interference. Monarch's foundation model comes from Alias Robotics — a European robotics-security research lab with peer-reviewed publications in adversarial AI and robot vulnerability assessment.
- •ROS security: the Robot Operating System is widely deployed in research and industrial robotics. Its original architecture assumed trusted networks. Securing ROS deployments requires understanding the middleware's trust model and communication patterns.
- •Sensor manipulation: adversarial inputs to cameras, lidar or force sensors can cause a robot to misperceive its environment — a safety-critical attack class unique to autonomous machines.
- •Control injection: direct manipulation of control commands — joint trajectories, velocity limits, safety boundaries — can turn a collaborative robot into a physical hazard.
- •Supply chain firmware: robot components from multiple vendors with multiple firmware versions create a supply chain attack surface that conventional vulnerability scanners don't cover.
Research: Alias Robotics publications on robot security (arXiv:2504.06017; arXiv:2512.02654).
How Monarch fits the converged environment
Monarch was built at the IT/OT/robotics convergence point — it is the origin, not an extension:
- •Sovereign deployment matches OT's air-gapped requirements: the entire platform — model, orchestration, memory, governance, identity — runs on a single VM with zero egress. No data leaves the network. This is the same deployment model OT environments already demand.
- •Governance prevents disruptive automated response: policy enforcement under 2ms on every action. In OT and robotics environments, governance rules scope automated response to non-disruptive actions — network isolation, alerting, evidence capture — rather than device shutdown or process termination.
- •Robotics-origin AI: the sovereign model was trained on robot vulnerability assessment and adversarial AI. It understands the attack classes unique to autonomous machines — not as a bolt-on, but as foundational training data.
- •Memory across the converged surface: findings from IT, OT and robotics assessments persist in the same memory layer. Cross-domain correlation is not a separate integration — it is the platform remembering what it found across all domains.
Frequently asked questions
Can AI cybersecurity work on OT networks?
Yes, if the platform is designed for it. Traditional IT security tools generate noise on OT networks because they don't understand OT protocols or the availability-first priority. AI trained on OT-specific traffic patterns can monitor without disruption — passive analysis, not active probing.
Is cybersecurity AI safe for safety-critical systems?
Only if governance constrains automated response. An AI that can auto-quarantine an IT endpoint must not do the same to a robotic actuator or an industrial control loop. Monarch's governance runtime scopes every automated action by policy — safety-critical systems require explicit human authorisation for disruptive response.
Does Monarch support OT protocols?
Monarch's detection layer ingests telemetry from existing OT sensors and SIEM integrations (Splunk, Wazuh, Suricata, Zeek). OT protocol parsing depends on the sensor layer; Monarch classifies and correlates the telemetry those sensors produce.
Why was Monarch built for robotics?
Monarch's intelligence layer is built in partnership with Alias Robotics, a European robotics-security research lab. The foundation model was trained on robot vulnerability assessment, adversarial AI and autonomous offensive security — robotics and OT security are the origin, not an extension.
IT, OT, robotics — one sovereign platform for the converged attack surface.
Request a briefing