As the pace of AI development makes it more challenging to fix vulnerabilities before they can potentially be exploited, critical infrastructure operators face a complex challenge. Industrial cybersecurity vendor Nozomi Networks has joined Anthropic’s Project Glasswing initiative, which aims to identify vulnerabilities before attackers exploit them, to focus on securing operational technology (OT), industrial systems and cyber-physical environments.
For enterprise technology and customer experience leaders, the challenge brings cybersecurity closer to the customer experience conversation, as vulnerabilities in underlying systems increasingly affect service reliability and trust. As AI becomes embedded across business operations, the systems supporting customer experiences—from cloud platforms to connected devices and physical infrastructure—will increasingly need to withstand a faster-moving cyber threat landscape.
When it comes to managing vulnerabilities before they become incidents that affect customers, decades-old technology, operational constraints and safety requirements can require more than simply applying a software patch.
Protecting the Infrastructure Behind Customer Experiences
Nozomi Networks joins Project Glasswing as Anthropic continues to expand the initiative beyond its original launch partners. Last month, the company added around 150 organizations from more than 15 countries after early participants identified over 10,000 high- and critical-severity vulnerabilities using the Claude Mythos Preview large language model (LLM). Although the U.S. government lifted export controls on Mythos-class models at the end of June, the model remains available only to pre-vetted organizations through Project Glasswing and other approved cybersecurity partnerships, rather than being released for general use.
Nozomi said its role in Project Glasswing will focus on applying advanced AI models to OT and IoT-focused vulnerability discovery, contributing insights to Anthropic’s research and sharing findings with the wider cybersecurity community.
“AI models like Mythos are on track to fundamentally change how vulnerabilities are identified,” Nozomi Networks said. “They can help defenders find risks faster and at greater scale.”
The company pointed out that critical infrastructure environments require specific expertise because the consequences of vulnerabilities can extend beyond data loss or system compromise.
“Operational and critical infrastructure environments face unique constraints, including long lifecycles, patching limitations, and direct physical consequences from cyber incidents.”
Sectors such as energy, manufacturing, transportation and utilities cannot easily take systems offline for updates.
“OT and IoT cybersecurity expertise are important contributions to Project Glasswing and ensuring advanced, AI-driven vulnerability discovery is applied to real-world environments,” the company added.
While AI-powered vulnerability discovery creates new defensive opportunities, Nozomi warns that the industry needs to address a widening gap between identifying vulnerabilities and reducing risk.
As part of Project Glasswing, the vendor said it will apply advanced AI models to OT and IoT-focused vulnerability discovery in its platform, contribute to Anthropic’s research and share its findings with the broader cybersecurity community.
While AI-powered vulnerability discovery creates new defensive opportunities, Nozomi Networks warned that the industry needs to address the widening gap between identifying vulnerabilities and reducing risk.
“Getting ahead of vulnerabilities before adversaries find them is exactly the right use of a capability like this,” Moreno Carullo, Founder and Chief Technical Officer at Nozomi Networks, wrote in a recent blog post.
However, critical infrastructure environments controlled by Supervisory Control and Data Acquisition (SCADA) systems combining software and hardware monitoring require a different approach from traditional enterprise IT.
“I think the industry needs to have an honest conversation about what Mythos and GPT 5.5 Cyber are and are not, yet. Critical infrastructure OT/ICS systems are missing from the picture.”
“For OT and critical infrastructure, the calculus is different,” Carullo added. “The consequence of finding a vulnerability in a SCADA system or a safety instrumented system is not as simple as ‘here’s a CVE to patch,’” Carullo added.
Unlike many enterprise IT systems, industrial systems often prioritise availability and safety over rapid software updates. A manufacturing plant, energy facility or transportation system cannot always apply patches immediately without extensive testing or operational disruption.
As Quincy Castro, Chief Information Security Officer (CISO) at ChainGuard, noted in an interview with CX Today:
“Sometimes you have highly performance systems that can’t be patched without breaking stuff. Organizations have legacy tech that maybe can’t be touched at all.”
This creates a gap between vulnerability discovery and vulnerability remediation.
A vulnerability affecting an enterprise application may be resolved through a software update, while a similar issue in an industrial control environment may require extensive testing, compensating controls or scheduled maintenance windows.
With many security processes designed around slower development cycles, more vulnerabilities entering the software supply chain and faster discovery capabilities could overwhelm existing workflows.
“Remediation and the traditional way of doing this has become a bottleneck,” Castro said.
The result is a growing concern that AI could compress vulnerability discovery timelines while remediation processes remain tied to slower organizational workflows.
Why Infrastructure Security Is Becoming a CX Issue
Cybersecurity decisions are increasingly connected to customer experience outcomes.
Modern customer journeys depend on a wide technology ecosystem spanning cloud platforms, contact centers, connected devices, supply chains and physical infrastructure. Disruption in one area can quickly affect service availability, customer trust and operational continuity.
For example, a cyber incident affecting a manufacturing supplier could disrupt product availability. An attack against critical infrastructure could affect services customers rely on every day. A vulnerability in connected devices could create customer-facing security and privacy risks.
The expansion of AI-powered systems into customer-facing environments adds another layer of complexity. Retail automation, connected products, robotics and intelligent service platforms all depend on software and hardware ecosystems that must be secured.
As enterprises expand their use of AI-driven automation, security leaders and CX executives will need closer alignment around resilience planning.