When minutes replace months in manufacturing cybersecurity
For decades, cybersecurity teams had one advantage over their attackers: time. A vulnerability might be discovered today, but it often took weeks or even months before someone developed a practical way to exploit it. That window gave software developers, equipment manufacturers and industrial operators valuable time to assess the risk, deploy patches and strengthen their defenses. According to Rich Campagna, Senior Vice President of Product Management, Network Security at Palo Alto Networks, that advantage is disappearing. Frontier AI models can now identify previously unknown vulnerabilities and generate exploit code in minutes, fundamentally changing the pace of cyber warfare.
For manufacturers, the implications are particularly significant. Unlike traditional IT environments, operational technology often supports production systems that cannot simply be taken offline to apply security updates. Many factories continue to rely on legacy equipment, embedded firmware and industrial control systems that may remain in service for decades. As the time between discovering and exploiting vulnerabilities continues to shrink, manufacturers are being forced to rethink how they protect critical operations.
“We’ve seen a dramatic increase in sophisticated attacks,” Campagna explains. “Across our customer base of more than 70,000 organizations, we now stop over 30 billion attacks every day. About eighteen months ago, we saw around two million sophisticated attacks each day. Today that figure is closer to nine million. What’s really changing is that Frontier AI models are becoming incredibly effective at finding vulnerabilities that no human and no existing tool has discovered before, then generating exploit code almost immediately.”
For Campagna, AI has not simply made cyberattacks faster. It has fundamentally compressed the time available for defenders to respond, forcing manufacturers to rethink cybersecurity from a race to recover into a race to prepare.
Why manufacturing cannot simply patch faster
For most enterprise IT environments, discovering a vulnerability triggers a familiar response. Systems are patched, software is updated and the risk is reduced. Manufacturing operates to a very different timetable. Production lines run around the clock, critical assets may remain in service for decades and taking equipment offline is rarely a decision that can be made without affecting output, quality or customer commitments.
That operational reality means manufacturers often find themselves caught between two competing priorities: maintaining production continuity while responding quickly enough to an increasingly fast-moving cyber threat landscape.
“The problem isn’t just that AI is helping attackers find vulnerabilities more quickly,” Campagna says. “The bigger issue is that they’re also extremely good at generating exploit code. In the past, a vulnerability might have existed for months before somebody figured out how to exploit it. Today, that process can happen in minutes. Attackers don’t need weeks or months anymore.”
For operational technology environments, that shift creates a significant challenge. A newly discovered vulnerability may be exploitable almost immediately, while the affected industrial asset cannot realistically be patched until the next planned maintenance shutdown. Legacy controllers, embedded firmware and even unsupported operating systems remain common across manufacturing because they continue to perform critical production functions long after mainstream IT has moved on.
Rather than expecting manufacturers to accelerate patching beyond what operations will safely allow, Campagna believes the industry needs to rethink how vulnerabilities are managed. One approach gaining increasing attention is virtual patching, where security controls positioned within the network identify and block attempts to exploit a known vulnerability before malicious traffic ever reaches the vulnerable device.
“You place security in front of the asset,” he explains. “Even though the device itself hasn’t yet been patched, the firewall or network security platform recognizes the exploit attempt and blocks it before it reaches the system. That allows manufacturers to patch according to operational schedules instead of feeling pressured into emergency downtime every time a new vulnerability is discovered.”
As the gap between vulnerability discovery and exploitation continues to shrink, approaches such as virtual patching are becoming less of a contingency measure and more of a practical requirement for protecting industrial operations without compromising production availability.
AI is becoming the defender’s greatest advantage
While AI is enabling attackers to move faster than ever before, Campagna believes its greatest long-term impact may ultimately be on the defensive side of cybersecurity. In fact, AI has been embedded within cybersecurity platforms for many years, quietly analyzing enormous volumes of network activity to distinguish genuine threats from routine business operations. What has changed is the speed, sophistication and autonomy with which those systems can now operate.
“AI isn’t new to cybersecurity,” he says. “Across our own products we use thousands of AI models every day. They’re helping us identify the billions of attacks we see, detect the millions of new threats that appear daily and automate much of the analysis that previously required highly skilled security analysts.”
For manufacturers, one of the most immediate benefits lies in reducing the burden on already overstretched security teams. Modern industrial environments generate huge numbers of security alerts, many of which require investigation before a decision can be made. AI is increasingly able to prioritize those alerts, eliminate false positives and automate many of the repetitive tasks that consume valuable analyst time, allowing security specialists to focus on the incidents that genuinely threaten production.
Looking further ahead, Campagna believes Frontier AI has the potential to transform software development itself. The same models capable of identifying previously unknown vulnerabilities after software has been released can also be integrated into development processes, enabling manufacturers and software vendors to discover and remediate weaknesses before products are deployed into operational environments.
“We’re on the verge of being much more proactive,” he explains. “As more organizations embed Frontier AI into their software development lifecycle, we’ll be able to identify the vast majority of previously undiscovered vulnerabilities before software is released. That won’t eliminate cyber risk, but it will dramatically reduce the opportunities available to attackers.”
For manufacturing, the long-term significance extends beyond stronger cyber defenses. As AI increasingly identifies vulnerabilities before products reach the factory floor, cybersecurity has the potential to become less about reacting to incidents and more about preventing them altogether, fundamentally changing how industrial systems are designed, tested and protected.
Keeping people in the loop
As AI becomes increasingly embedded within cybersecurity platforms, the question for manufacturers is no longer whether intelligent systems should participate in cyber defense, but how much authority should they be given. From detecting threats and recommending new security policies to autonomously responding to suspicious activity, AI is steadily moving from an advisory role towards operational decision-making.
Campagna believes that transition should happen gradually. While AI can analyze threats at machine speed, manufacturers remain understandably cautious about allowing autonomous systems to make decisions that could interrupt production or block legitimate operational activity.
“Most manufacturers want to keep a human in the loop,” he explains. “An AI system may recommend a new security policy based on suspicious behavior, but before that policy is deployed into a live production environment, somebody validates that it’s the right decision. That’s how organizations build confidence.”
Over time, however, that relationship is likely to evolve. As AI consistently demonstrates that its recommendations match the judgement of experienced cybersecurity professionals, manufacturers will become more comfortable automating routine decisions while reserving human intervention for more complex or higher-risk situations.
Campagna compares the process to the gradual acceptance of driver assistance technologies in the automotive industry. Initially, people closely monitor every recommendation. As confidence grows, they begin to rely on automation for routine tasks while remaining ready to intervene when necessary. He believes cybersecurity will follow a similar path, with confidence built through repeated evidence rather than blind faith.
“The technology has to earn that confidence,” he says. “Once organizations see that the recommendations are consistently accurate and aligned with what their own experts would decide, they’re far more willing to let AI act on its own in lower-risk scenarios.”
For manufacturers, the future of cybersecurity is unlikely to be defined by humans or AI working independently. The greatest resilience will come from combining the speed and analytical power of intelligent systems with the operational judgement, accountability and experience that people continue to provide.
Winning the race against time
The defining impact of AI on industrial cybersecurity is not simply that attacks are becoming more sophisticated. It is that the time available to respond is shrinking dramatically. Vulnerabilities that once gave manufacturers weeks or months to assess, patch and protect can now be identified and exploited in a matter of minutes, forcing security strategies to evolve just as quickly.
For Campagna, the answer is not to slow AI down, but to use it more intelligently. Manufacturers must assume cyber threats will continue to accelerate and build security around that reality, combining stronger development practices, technologies such as virtual patching and AI-driven threat detection with the operational discipline needed to protect production without compromising availability.
“We’re in a state of flux right now,” Campagna concludes. “But over the next couple of years, I think all of this is a very positive thing for cybersecurity and for defenders.”

