Two Years On: What My 2024 OT Predictions Got Right, Got Wrong, and Missed Entirely

Most prediction lists in this industry are written to be forgotten.

The ones worth writing are the ones you have to live with.

In April 2024, I published My Top 10 OT Cybersecurity Predictions to Watch. Two years on, I have lived with that list through incidents, regulations, a blackout, two waves of AI hype, and a vantage point that has shifted in ways I did not expect. These two years took me into plants and programs I had never secured before, and into close work with IT/OT startups building the next layer of this stack from the inside out. Different plants. Different problems. Different blind spots.

That combined view has sharpened what I now believe I got right, what I got wrong, and what I should have called and didn't.

This is not a victory lap. It is a field report.

🛰️ The Ten, Scored

1. OT Cloud and IIoT Security — Half right.

The attack surface expanded as predicted. The Purdue model strained, also as predicted. But the "new OT-specific cloud protocols" I anticipated never arrived in the elegant form I imagined. The industry settled into something messier: extending IT-native controls into OT, accepting the architectural tension, and bolting on visibility tools to compensate. Pragmatic. Not pretty.

2. Autonomous AI at OT Levels 1 and 2 — Wrong on the level. Right on the trend. Autonomy surged. AI in OT exploded. But not at Level 1 or Level 2, the safety boundary held, and I am grateful it did. What I underestimated: how aggressively AI moved into Levels 3 and 4 monitoring, optimization, decision support, energy dispatch, and how fast that became the new risk surface. The plant did not lose deterministic control. It lost the boundary between operational decision-making and AI suggestion. I unpacked the architectural reasons in Beyond the Hype: AI, Autonomy, and the Architecture of Reality in OT. Short version: Autonomy without verifiability is negligence.

3. Remote Access and Zero Trust — Right on direction. Slow on adoption.

Zero trust permeated the discourse. Adoption did not. Persistent vendor VPNs, shared jump-host credentials, and remote access architectures no architect would design today from a clean sheet, all still common, all still in production, all still routing through "temporary" exceptions documented years ago. The conversation moved. Reality crawled.

4. Cyber-Physical Convergence — The vision was right. The timeline was naïve.

Some sectors got it: data centers, semiconductors, pharmaceuticals, and frontier manufacturing. Most others still run cyber and physical security through separate budgets, separate teams, and separate incident response playbooks. The convergence we called for is happening at the speed of organizational politics, not at the speed of threat reality.

5. Protection Over Detection — Right. And it is happening now.

This is the one I am most willing to defend. The "we will detect everything" gospel weakened. Compensating controls, protection-first thinking, and architectural hardening all gained ground. Asset owners are increasingly recognizing what I have written elsewhere: no algorithm can compensate for a flat network or a missing safety interlock. Protection must precede prediction. The caveat: many programs now claim to be protection-first while still budgeting like detection-first. The slogans moved before the architecture did.

6. Regulatory and Compliance Pressure — Underestimated.

I called the direction. I undershot the magnitude. NIS2 in Europe came into force, SEC disclosure rules tightened, and sectoral regulations across MENA and APAC kept multiplying. The unintended consequence I should have flagged: many programs are now building for audit reporting first and resilience second. We are quietly creating compliant environments that cannot survive a real incident. That is the next failure mode, and it will not be subtle when it lands.

7. Disaster Recovery and Business Continuity — Movement, not maturity.

Plans got written. Drills got scheduled. But OT-specific BCP, including safe-state restoration, process recovery, operator integration, and recovery time objectives that respect physical lead times, is still uncommon. Most of the "OT BCPs" I have reviewed over the last 18 months are IT BCPs with their titles changed.

8. The OT CISO Role — Slowly real.

The role exists more often than it did two years ago. But it is too often a renamed senior security manager rather than a true executive function with budget, authority, and architectural ownership. The title moved. The mandate has not caught up. Until OT CISOs hold P&L accountability for resilience outcomes, the role remains symbolic in too many organizations.

9. Generative AI and OT Threats — More aggressive than I predicted.

Phishing reached a level of contextual sophistication that has fundamentally changed the cost curve of social engineering. Reconnaissance got cheaper, faster, and harder to detect. What I underestimated: how quickly adversaries integrated AI into their tradecraft compared to defenders. The asymmetry widened, not narrowed.

10. Digital Twin and LLM-Based Predictive Security — Mostly aspirational.

A handful of well-funded programs are doing meaningful work here. The rest are buying tools and calling it a strategy. Two hype waves, asset discovery and GenAI, have now passed through OT, and both left scars. The promise is real. The maturity is not. Anyone selling this as a turnkey capability in 2026 is either uninformed or selling something else.

🚨 What I Didn't See Coming

Five threats that emerged in the gap between my forecast and the field.

Building automation became the new soft underbelly.

Chillers, HVAC, elevators, fire suppression, access control, and the systems running under hospitals, data centers, pharmaceutical plants, and high-rises were outside both IT and OT cybersecurity programs. The orphan of operational technology became one of the most attractive attack surfaces. I should have called this in 2024. I did not. I have started writing about it in The OT Orphan now.

Supply chain compromise moved downstream.

We knew the supply chain was a problem. What we missed: how quickly attackers shifted from named-platform compromise to component-level compromise, embedded firmware, integrator credentials, third-party libraries, vendor support routines run during scheduled maintenance windows. The new perimeter is not your network. It is everyone who touches it.

Cyber insurance became a quiet forcing function.

Insurers are now shaping OT cybersecurity programs more than many regulators. Sometimes that produces better outcomes than rule-makers do. Often, it produces rigid, checklist-driven thinking that ignores operational reality entirely. Either way, the conversation in many boardrooms now starts with "what will our policy require," not "what will keep us safe."

The skills gap inverted.

Two years ago, we worried about not having enough OT cybersecurity engineers. Today, the deeper problem is something else: too many people with cybersecurity certifications who have never set foot in a plant. Theory is plentiful. Field judgment is scarce. That gap shows up in incidents, in audits, and in advice I would not personally follow.

The slow-motion failure pattern.

The Iberian Peninsula event in April 2025 reminded us that cyber risk and operational fragility now overlap in ways that do not always announce themselves as cyberattacks. Sometimes the lesson is not "we got hacked." Sometimes the lesson is "our system was so brittle it did not need to be hacked." Either way, the consequence is the same. The next disruption will not come with a warning.

🧭 What to Watch From Here

Agentic AI in OT operations. Not suggestion engines, agents that act. The governance, rollback, kill-switch, and safety-boundary work is years behind the deployment curve. Watch this carefully. It is the next place where architectural failure becomes a physical event.

The legacy reckoning. A wave of decades-old controllers and HMIs is reaching true end-of-life faster than upgrades can be funded. The cost of doing nothing is finally becoming a number boards can see, sometimes for the first time.

OT-specific incident response, professionalized. A new tier of practitioners who understand process, safety, and cyber together is emerging. Slowly. They are the ones who will write the next ten predictions, and they will be more right than I was.

Quantum-readiness is creeping into critical infrastructure planning. Not an imminent threat. Not optional to ignore.

Predictions are a form of public thinking. They are useful not because they are always right, but because they force the field to argue with itself.

One year from now, I will write this list again. I expect to be right about some of it. Wrong about others. And blindsided by something I have not yet imagined.

That is not a flaw in the method. That is the method working.

Previous
Previous

The Compliance Trap: Why Audit-Ready OT Programs Can Still Fail Their First Real Incident

Next
Next

The Orphan in OT Security: Why Building Systems Are Everyone’s Blind Spot