All articles

When The Systems Worth Protecting Are Unpatchable, Architecture Has To Carry The Defense

The Security Digest - News Team
Published
July 19, 2026

Veteran CISO Todd Wade on why OT defense must start with architecture, segmentation, and asset visibility as AI compresses attack timelines to minutes.

Credit: The Security Digest

Make The Security Digest one of your go-to sources on Google

Add The Security Digest on Google

If your security solution is to patch, you're in a lot of trouble.

Todd Wade

Veteran CISO

Todd Wade

Veteran CISO

AI is exposing the limits of a patch first strategy. Patch-first defense works when the systems worth protecting can actually be patched. In OT environments, they often cannot. The HVAC controllers, medical devices, manufacturing lines, and legacy firmware running critical infrastructure frequently have no central update mechanism, no vendor still in business, and no maintenance window short enough to matter once AI compresses attack timelines from overnight to minutes. The organizations that survive the coming wave of AI-driven OT threats will be the ones that built their security around architecture, defense in depth, identity, asset visibility, segmentation, and blast-radius control, rather than around remediation promises they were never able to keep.

Todd Wade is a veteran Chief Information Security Officer and author who has led security for fintech, technology, and private equity organizations. He recently served as interim CISO for a hyperscale data center group with a heavy OT footprint. Wade's work focuses on the practical realities of defending complex, legacy-laden environments against a fast-evolving threat landscape. In his view, AI automation is forcing a complete rewrite of incident response playbooks.

"If your security solution is to patch, you're in a lot of trouble," he says. That warning lands hardest in exactly the environments least able to patch.

Patching was never going to save OT

The core problem is structural. OT and IoT systems are frequently unpatchable, and the reasons compound. Proprietary software blocks remediation. Firmware can't be updated without breaking operations. And unlike the server and workstation world, there's no central authority pushing security updates. "When you buy a computer, you have an operating system: Windows, Apple, Linux. Many OT companies build their own firmware. They're not using any external party. There's no central patching Tuesday," he explains. "It's up to the company to update it, and in some cases those companies go out of business while you still have their gear in your organization."

The result is estates running equipment 10 or 20 years old, from vendors that no longer exist, with no third party thinking about how to secure them. Wade is blunt that organizations leaning on remediation promises are buying a band-aid. Vendors often overstate how much risk automated patch management can eliminate in legacy OT environments.

AI collapses the response window

What makes the unpatchable-systems problem urgent now is speed. AI has dramatically compressed the timeline between a vulnerability being announced and being exploited, which breaks the patch-planning model that OT and IT teams have relied on for years. "Microsoft announces a zero-day and you'd typically arrange a patch window that night. Internet facing vulnerabilities may now be exploited within hours, leaving far less time for traditional patch windows. It moves that fast due to AI," Wade cautions.

That compression is why cyber resilience, rather than patch cadence, becomes the central question. Organizations now have far less time to react before attackers begin exploiting exposed systems. The defense has to be architectural rather than reactive.

Defense in depth is the strategy companies keep getting wrong

Wade's foundational prescription is defense in depth, and he's candid that it's the thing organizations most consistently fail to execute, regardless of size. "I had a client go through a massive ransomware attack. They thought they had defense in depth, but they didn't. It was a domino effect. The attackers got in one layer, attacked the next, and there was no defense in depth."

Getting the basics right is harder than it sounds. A vulnerability that grants access to one system should not grant access to the entire organization, and preventing that requires segmentation, strengthened identity and access management, and additional layers an attacker has to defeat before a compromise spreads. Wade sees this failure at large and small organizations alike, which is why he anchors OT defense in blast-radius control rather than perimeter patching.

The same architectural thinking applies to identity. Many OT environments still rely on shared administrator accounts, vendor VPNs with standing privileges, and service accounts that have accumulated permissions over decades. As AI accelerates reconnaissance and privilege escalation, identity becomes another form of segmentation. Limiting what an attacker, or a compromised AI agent, can access is increasingly more valuable than assuming every vulnerable device can be patched.

The AI worm threat sharpens the stakes. Where traditional malware like WannaCry was programmable and fixed, research has demonstrated self-propagating malware that adapts, showing limited intelligence to change its route through an environment and spread. "Researchers have demonstrated early concepts of AI assisted self-propagating malware capable of adapting aspects of its propagation. While these techniques have not yet been observed at scale, they illustrate how future malware will become more autonomous," Wade says.

Against a threat that finds and exploits gaps automatically, poor segmentation and unknown assets become liabilities that AI tooling can discover far faster than any human attacker could.

You cannot protect what you cannot see

Before segmentation or detection can work, an organization has to know what it actually has, and Wade repeatedly returns to asset visibility as the first and most commonly failed step. "You could have an estate and think you have threat detection in an OT environment, then realize you have whole rooms of gear operating that you're just not aware of. If you don't know your assets and you're not monitoring them, that's a huge blind spot."

His practical playbook for walking into a poorly secured manufacturing environment starts there: deploy threat detection tooling that also handles asset discovery across the estate, then scrutinize network segmentation, redundancy, and single points of access. AI cuts both ways here. It will test segmentation faster than a traditional pen test, which means organizations that believe they are segmented but are not will have those holes exposed quickly.

The blind spot extends to the newest layer of risk. AI agents are being deployed across organizations with significant permissions and little security governance, operating on protocols that existing EDR and NDR tools can't see. "You have a blind spot, and you're giving these agents huge permissions," Wade says. "Imagine the threats of these agents getting compromised and the access they'll have."

The failure is often budget, not knowledge

Wade's most sobering point is that the security teams in the most exposed environments frequently know exactly what to do. They just can't get it funded. Manufacturing and other cost-sensitive sectors routinely accept more risk than their security teams recommend. "A lot of times the security team is recommending the right course of action, but they don't get approval for the cost from management. These tools are not cheap. And there's an old irony: if you want your security budget to increase, go through a ransomware attack. Everyone gives you more money after an attack," Wade notes.

The contrast he draws is stark. Having run security for both manufacturing groups and hyperscale data centers, he describes the difference in investment as night and day, with data centers flush with money and spending more on cybersecurity and manufacturing operating with minimal cybersecurity budgets despite sometimes carrying critical infrastructure.

That gap is why Wade expects the first major AI-driven OT incident to expose years of deferred architecture work. The fixes are known. The tooling is improving. But in the environments where an attack would do the most damage, the investment tends to arrive only after the damage is done.