Ilyass MotyaIlyass Motya
An AI just ran a full kill chain. Your old network problems are still the defense.
Back to blog

An AI just ran a full kill chain. Your old network problems are still the defense.

· By Ilyass Motya

Source: Industrial Cyber — Booz Allen, 'The Offensive Frontier: AI as the Attacker'

What the testing actually showed

Booz Allen's Cyber Weapon Index tested 18 U.S. and Chinese frontier models. One — a Claude model — autonomously completed a full kill chain in a production-grade enterprise network, including gaining administrator-level access with a stolen employee credential, and breaching the network without credentials in a harder variant. About two-thirds of the models reliably gained initial access to a defended network with no credentials at all. Most models, the report says, could reach full autonomous capability within six months.

Then the detail that should shape your response: every frontier API model scored zero against real-world vulnerabilities. The same models that cruised through intentionally introduced flaws found nothing in actual production code. There is a gap between benchmark performance and operational reality. Arguing that the gap is permanent would be naive — the report's own counter-AI testing reduced autonomous attacker success by over 95%, which proves the techniques work both ways.

OT security engineer commissioning industrial control equipment on the plant floor

The response window is the new unit of risk

Nothing about this changes the fundamentals that already decide OT outcomes. Two-thirds of models getting initial access without credentials only matters because passwords, exposed interfaces, and flat networks still exist. The AI compressed the timeline, not the architecture.

The defensive reading is almost boring: segment so a foothold is not a paved road to the engineering workstation, enforce least privilege so one credential does not equal the plant, isolate high-value assets, and assume access will be obtained — then measure whether you can contain it while production keeps running.

What to do this quarter

Keep the AI as a reason, not an excuse. The same week the Booz Allen report landed, OpenAI and a coalition launched a collective defense initiative for essential services — and their own statement noted that unpatched software, misconfigurations, weak authentication, and legacy debt remain the standing exposures. That is the list. AI changes who can press the trigger; it does not change what is pointed at.

On a plant floor, the containment question is: if an agent reaches the OT network tomorrow, how long before a human can isolate the affected zone and keep production running? If the answer is not measurable, that is the project.

Next up