Cybersecurity
Skills Gap in OT Cybersecurity: Leaving to AI What It Does Best
Flat budgets and too few, half-expert analysts: how artificial intelligence can close the skills gap in OT security without replacing people.

Defending industrial environments runs into a structural problem: threats grow while the people capable of addressing them remain few. This is not a temporary emergency — it is a condition that will accompany OT security teams for a long time to come. The most realistic response is not to hire more people, a path that is often impractical, but to redesign how work is distributed between automation and human expertise.
Three Numbers That Capture the Gap
The skills gap in OT and ICS security is not a feeling — it is a measurable fact. Three data points make it clear.
- Budgets are not really growing. The average increase in cybersecurity spending is around 4% annually, in line with inflation. In real terms, available resources are stagnant.
- Almost nobody works exclusively on OT. A minimal fraction of professionals — around 9% — dedicates themselves exclusively to industrial systems security. The majority splits their time between IT and OT, two worlds with profoundly different logic.
- Experience is scarce. More than half of the workforce has five years of experience or less, precisely at a time when they must deal with legacy plants, proprietary protocols, and systems that do not forgive mistakes.
The result is a bottleneck: few specialists, little time, too many signals to analyze. This is where artificial intelligence can make a difference — as long as it is assigned the right tasks.
What Makes Sense to Delegate to AI
AI excels where volume overwhelms human attention. In an OT environment, sensors and monitoring systems generate a volume of events that no analyst can manually review. The activities where automation offers maximum value are the repetitive, high-volume, low-ambiguity ones.
- Filtering noise, separating irrelevant events from signals that deserve attention.
- Correlating and prioritizing, linking anomalies, vulnerabilities, and exposures to surface what truly matters.
- Proposing remediation, suggesting countermeasures and providing pre-structured context to the analyst.
The goal is not to replace those who investigate, but to prevent them from spending their days doing what a machine does better and faster.
What Stays with Analysts
The final decision, however, cannot be automated. Judgment about which risk to accept, which plant to stop, and which intervention to postpone requires knowledge of the production context, business priorities, and the physical consequences of each choice. These are areas where human expertise remains irreplaceable.
- Strategic decisions, calibrated against real business impact and operational continuity.
- Business context, which no model knows better than those who operate in the plant daily.
- Complex investigation, when an incident falls outside normal patterns and requires intuition, not just correlation.
The MON5 Angle
This balance underpins MON5's approach. Our platform automates the most burdensome part of the work: continuous asset visibility on the network without manual inventories; correlation between vulnerabilities and real exposures, avoiding the chase after CVEs with no actual impact; anomaly triage, surfacing what deserves immediate review.
The time analysts no longer spend collecting and filtering data is time spent on decisions that matter. For an undersized OT team, this is not a detail — it is the difference between chasing alerts and governing risk.
In Summary
The skills gap in OT cannot be closed by hiring people who are not there, but by using the people who are more effectively. AI absorbs repetitive workload, accelerates onboarding of less experienced profiles, and frees up judgment capacity. People remain at the center, where they are truly needed.
Analysis and commentary by MON5 based on publicly available OT/ICS sector research and data.
Related articles

Cybersecurity
AI changed vulnerability discovery: but there is an OT gap you cannot ignore
New AI models discover vulnerabilities autonomously and at industrial scale. But the tools stay tuned for IT: the OT world risks falling behind just as attackers accelerate.

Cybersecurity
Anomaly detection in OT: building the baseline and managing false positives
OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.
Cybersecurity
OT Metrics for the Board: Turning Industrial Security into Decision-Ready Numbers
Management wants numbers. But which OT metrics communicate real risk instead of mere compliance? How to build a dashboard of KPIs and KRIs that speaks of potential downtime, not checklists.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.