AI Attacks on OT & Critical Infrastructure by Kai London
A short, direct briefing on what AI actually changes for industrial defenders — which parts of the threat model need rewriting, which controls hold regardless, and where the honest uncertainty lies. Written to be read before the next planning cycle, not after the next incident.
Available on Amazon.
What is inside
What AI actually changes
Speed, scale and accessibility of attack capability — separated clearly from what is still marketing.
Reconnaissance and social engineering
Targeting engineers, contractors and operators with material that no longer reads as a phishing email.
Protocol and process abuse
Where machine assistance lowers the expertise barrier for manipulating industrial protocols and logic.
Rewriting the threat model
Updating assumptions about attacker skill, dwell time and the credibility of what an operator sees.
Controls that still hold
Segmentation, safety systems, physical interlocks and manual operation — the defences indifferent to attacker sophistication.
What to brief upward
A concise, non-alarmist account for executives and regulators asking what your AI exposure really is.
Who it is for: OT security leaders and ICS engineers, plant and operations managers, CISOs in critical national infrastructure, and boards who need the AI question answered without theatre.
The attack got cheaper. The consequence did not change. Defend the consequence.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.