Skip to content

Cybersecurity

Skills Gap in OT Cybersecurity: Leaving to AI What It Does Best

Flat budgets and too few, half-expert analysts: how artificial intelligence can close the skills gap in OT security without replacing people.

2 min read
Industrial SOC analyst working alongside an AI assistant that filters alerts and anomalies on OT systems

Defending industrial environments runs into a structural problem: threats grow while the people capable of addressing them remain few. This is not a temporary emergency — it is a condition that will accompany OT security teams for a long time to come. The most realistic response is not to hire more people, a path that is often impractical, but to redesign how work is distributed between automation and human expertise.

Three Numbers That Capture the Gap

The skills gap in OT and ICS security is not a feeling — it is a measurable fact. Three data points make it clear.

  • Budgets are not really growing. The average increase in cybersecurity spending is around 4% annually, in line with inflation. In real terms, available resources are stagnant.
  • Almost nobody works exclusively on OT. A minimal fraction of professionals — around 9% — dedicates themselves exclusively to industrial systems security. The majority splits their time between IT and OT, two worlds with profoundly different logic.
  • Experience is scarce. More than half of the workforce has five years of experience or less, precisely at a time when they must deal with legacy plants, proprietary protocols, and systems that do not forgive mistakes.

The result is a bottleneck: few specialists, little time, too many signals to analyze. This is where artificial intelligence can make a difference — as long as it is assigned the right tasks.

What Makes Sense to Delegate to AI

AI excels where volume overwhelms human attention. In an OT environment, sensors and monitoring systems generate a volume of events that no analyst can manually review. The activities where automation offers maximum value are the repetitive, high-volume, low-ambiguity ones.

  • Filtering noise, separating irrelevant events from signals that deserve attention.
  • Correlating and prioritizing, linking anomalies, vulnerabilities, and exposures to surface what truly matters.
  • Proposing remediation, suggesting countermeasures and providing pre-structured context to the analyst.

The goal is not to replace those who investigate, but to prevent them from spending their days doing what a machine does better and faster.

What Stays with Analysts

The final decision, however, cannot be automated. Judgment about which risk to accept, which plant to stop, and which intervention to postpone requires knowledge of the production context, business priorities, and the physical consequences of each choice. These are areas where human expertise remains irreplaceable.

  • Strategic decisions, calibrated against real business impact and operational continuity.
  • Business context, which no model knows better than those who operate in the plant daily.
  • Complex investigation, when an incident falls outside normal patterns and requires intuition, not just correlation.

The MON5 Angle

This balance underpins MON5's approach. Our platform automates the most burdensome part of the work: continuous asset visibility on the network without manual inventories; correlation between vulnerabilities and real exposures, avoiding the chase after CVEs with no actual impact; anomaly triage, surfacing what deserves immediate review.

The time analysts no longer spend collecting and filtering data is time spent on decisions that matter. For an undersized OT team, this is not a detail — it is the difference between chasing alerts and governing risk.

In Summary

The skills gap in OT cannot be closed by hiring people who are not there, but by using the people who are more effectively. AI absorbs repetitive workload, accelerates onboarding of less experienced profiles, and frees up judgment capacity. People remain at the center, where they are truly needed.

Analysis and commentary by MON5 based on publicly available OT/ICS sector research and data.

AIOTskills gapSOCICS

Related articles

Abstract illustration: artificial intelligence and vulnerability discovery in OT systems

Cybersecurity

AI changed vulnerability discovery: but there is an OT gap you cannot ignore

New AI models discover vulnerabilities autonomously and at industrial scale. But the tools stay tuned for IT: the OT world risks falling behind just as attackers accelerate.

2 min read
OT network traffic baseline chart with anomalous deviations highlighted and a maintenance-window calendar

Cybersecurity

Anomaly detection in OT: building the baseline and managing false positives

OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.

5 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna