Practical applications of agentic AI in OT security
In the second part of our Frontier AI for OT mini-series, we explore how you can use agentic AI to interrogate data, identify cyber threats, and streamline security operations. We provide a practical demonstration of integrating local large language models (LLMs) with Tenable OT to enhance your network defenses.
[00:02:47] Defending OT networks at machine speed
As cyber attacks driven by AI accelerate, you must rely on strong foundational security practices to defend your network.
- Asset discovery: Understand your assets, identify choke points, and map out your network architecture.
- Attack path analysis: Find viable attack paths and implement compensating controls to break them.
- Configuration tracking: Validate core OT configurations in real time to ensure unauthorized changes do not occur.
[00:05:27] Core capabilities of Tenable OT and Tenable One
We designed Tenable OT and Tenable One to give you complete visibility and control over your environment.
- Hybrid discovery: Discover assets deeply and quickly, including running configurations and controller run states.
- Comprehensive management: Centralize your asset inventory, vulnerability management, compliance mapping, and anomaly detection.
- Data analytics: Feed Tenable OT data into Tenable One to map relationships, enrich analytics, and enable AI-driven investigations.
[00:07:31] AI architecture and local large language models
You have flexibility when configuring AI models, from cloud-based systems to entirely on-prem local LLMs.
- Model flexibility: Connect Tenable Enterprise Manager to local models like Embra AI and Mistral, or cloud solutions like AWS Bedrock.
- Cost control: Open-weight LLMs help you avoid unpredictable token maxing and token costing.
- Data privacy: Running local models ensures your data stays entirely on-prem, giving you control over hardware and technical debt.
[00:11:44] Setting up your on-prem AI architecture
Connecting your AI models to native APIs requires a specialized translation layer.
- Model Context Protocol (MCP): Use an MCP layer to give your AI the routing capability to understand dictionaries and make intelligent API queries.
- Harness options: Implement server-based harnesses like LibreChat or Goose to handle tool calling securely.
- Customization: Build or modify your own MCPs using stable GraphQL APIs to pull data effectively.
[00:13:59] Best practices for prompt engineering
Because LLMs are stateless, you must craft well-structured prompts to guide the AI and manage context windows.
- System prompts: Embed repetitive instructions in the system prompt to reduce hallucination and set the role, audience, and objective.
- Context management: Monitor token consumption in local models, as large system prompts take up valuable context memory.
- Skills routing: Use targeted prompts, or skills, for specific operations to reduce data loads and improve system scalability.
[00:18:46] Practical demonstration of agentic AI
We demonstrate how a local LLM can interact directly with Tenable OT to identify active issues in your environment.
- Hardware setup: You can achieve strong multi-user capacity with a well-funded enterprise server running modern GPUs.
- Secure environments: Server-based agents prevent exposure to local file systems while enabling secure logging and reporting.
- Live querying: Use natural language to list sensors, identify offline devices, and rank vulnerabilities by VPR scores.
[00:27:40] Addressing hardware diagnostics and security controls
AI models offer unique ways to diagnose hardware and interact with complex security systems.
- Physical diagnostics: You can grant your MCP shell access to diagnose network interfaces directly on physical hardware.
- Write safeguards: You can configure default safeguards to prevent unauthorized AI actions, like initiating active scans.
- Tenable AI integration: Use Tenable AI within Tenable One to enforce guardrail checking and ensure safe AI execution.
[00:29:16] Investigating incidents and assessing risk profiles
Interactive chat sessions allow you to uncover hidden network insights faster than reviewing standard dashboards.
- Asset investigation: Query specific subnets to find unresolved events, major faults, and high-risk assets.
- Event correlation: Identify recurring failure patterns across maintenance windows to isolate intrusion attacks.
- Risk profiling: Ask the AI to evaluate asset groups and pinpoint machines that represent severe physical safety or fatality risks.
[00:38:56] Future Tenable OT initiatives and use cases
We are actively building new capabilities to help you classify devices and streamline policy management.
- Asset classification: Soon, you can package unidentified device data for AI analysis to generate prospective decoders on the fly.
- Prompt enhancements: We are refining prompts specifically for OT data to improve active operations and asset enrichment.
- Active operations: Use AI to automate complex processes, identify unpatchable devices, and recommend missing security policies.
[00:45:36] Automating reports and managing AI hallucinations
AI significantly reduces the manual effort required to generate actionable intelligence for your stakeholders.
- Custom reporting: Use AI tools to instantly generate risk reports detailing critical vulnerabilities and immediate recommendations.
- Hallucination management: Write precise prompts to prevent the AI from fabricating data or entering conversational loops.
- Operational efficiency: Let the AI handle the heavy lifting of parsing data, allowing your team to focus on strategic security decisions.
Tenable One
Demander une démo
La plateforme de gestion de l'exposition alimentée par l'IA leader du secteur
Merci
Nous vous remercions de votre intérêt pour Tenable One.
Un représentant vous contactera prochainement.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success