Executive summary

Operational technology (OT) underpins the buildings, factories, utilities, and critical infrastructure that society relies on. The structural realities of OT — long asset lifecycles, constrained maintenance windows, and the operational risk of changing software that runs mission-critical processes — mean that the patch-first defensive playbook used in corporate IT should be supplemented with defense-in-depth network security measures. The recent emergence of frontier AI systems capable of autonomous vulnerability discovery, including Anthropic’s Claude Mythos Preview, dramatically compresses the time needed for adversaries to weaponize newly disclosed flaws. Johnson Controls’ OpenBlue Airwall delivers a zero-trust overlay — aligned with U.S. NIST SP 800-82r3 guidance — that markedly strengthens the security posture of OT assets across vendors and device generations.

The threat landscape has shifted

The April 2026 disclosure that Anthropic’s Claude Mythos Preview model autonomously discovered thousands of zero-day vulnerabilities—including a 27-year-old flaw in OpenBSD that had survived decades of expert review—marks a turning point for OT security. AI-augmented vulnerability discovery compresses the window between flaw identification and weaponization beyond the timelines traditional patch cycles were designed to address. What once took adversaries months or years of skilled research can now happen in hours. For OT operators, the question is no longer whether attackers will gain AI-augmented vulnerability discovery, but how the defensive architecture should evolve to protect systems that cannot be patched on the threat actor’s timeline.

The OT cybersecurity challenge: an industry-wide reality

Operational technology shares a defining set of operational characteristics that distinguish it from consumer devices and corporate IT. These characteristics, listed below, are inherent to mission-critical industrial environments and apply across OT equipment and environments. They are not weaknesses of any individual product; they are the engineering trade-offs that make industrial systems safe, reliable, and long-lived in the first place.

  • Industrial assets stay in service for decades and outlive software support timelines. Building controllers, PLCs, and field devices often live multidecade service lives far exceeding the period any manufacturer can maintain active security updates. When software support ends, installed equipment is left without a patching path.
  • Software changes carry operational and regulatory risk. OT devices control physical processes— chillers, pumps, turbines, elevators, fire suppression systems, PLCs—where an untested update can cause equipment failure, safety incidents, or regulatory noncompliance. Often patches need to undergo lengthy specialized rigorous regression testing against the specific configurations and integrations of a given facility before it can be applied, especially in safety-critical, mission-critical or highly regulated environments.
  • Patching is challenging for devices on OT networks. Unlike other asset and device classes, OT devices are engineered for reliability in isolated networks, not continuous connectivity, which would itself be a security risk. They lack mechanisms for automated, remote updates, and their positioning behind layered firewalls often requires on-site technician visits to deploy patches.
  • Customer maintenance windows are narrow and infrequent. Teams responsible for OT typically authorize software changes only during pre-scheduled maintenance windows. In many 24/7 environments — hospitals, data centers, continuous manufacturing — those windows occur quarterly, annually, or less often.

Beyond patching: OpenBlue Airwall

Recognizing these realities, the U.S. National Institute of Standards and Technology has provided clear guidance. NIST Special Publication 800-82, Revision 3—the federal standard for operational technology security—directs operators to consider isolating unpatchable assets using zero-trust architecture, as defined in the companion standard NIST SP 800-207, as a part of a layered security model. The idea is simple. If, despite best efforts, you cannot promptly patch a device, shrinking its attack surface adds critical protection.

OpenBlue Airwall is designed to do precisely this.

OpenBlue Airwall implements a zero-trust overlay network where every Airwall has a unique cryptographic identity, independent of its network address. Airwall enforces default-deny access, only allowing user-defined policies between devices. Under this deployment model, devices cannot communicate with other devices unless a specific policy has been granted. The result is that even if an attacker compromises one endpoint on an operational network, lateral movement to other devices— the technique that transforms a single breach into a facility-wide event—is substantially mitigated.

Critically, OpenBlue Airwall is designed to be easily deployable and can be deployed without requiring substantial implementation efforts, such as firmware or configuration changes to the underlying device. This is essential in operational environments where device modifications can trigger the very recertification and regression-testing burdens described above.

OpenBlue Airwall: built for this moment

AI-augmented vulnerability discovery has compressed the timeline between flaw identification and exploitation. The window for a planned, proactive response is closing. OpenBlue Airwall was purpose- built to meet this moment—delivering zero-trust segmentation that protects OT assets. Johnson Controls brings more than 140 years of building technology leadership and an installed presence across a multitude of commercial and industrial facilities worldwide. We understand OT because we build, deploy, and support it every day. Cybersecurity is a strategic imperative for Johnson Controls. Three years ago, we embedded OpenBlue Airwall technology across our edge, building management, and automation platforms. Today, we continue to lead with this approach—offering solutions that deliver zero- trust cybersecurity by design, not as an afterthought.

With AI-driven cyber threats accelerating, now is the time to upgrade your OT security by deploying OpenBlue Airwall and put zero trust between your critical assets and whatever comes next.

Learn more

Explore how OpenBlue Airwall fits within your operational technology cybersecurity roadmap.

Get the full white paper PDF

Download now