This week, Anthropic launched the Critical Infrastructure Defense Program, a partner-led program focused on helping defend critical infrastructure, and Nozomi Networks is proud to join as a partner. Protecting the systems that keep energy, water, transportation, manufacturing and other essential services running has been our mission for more than a decade. The program creates a new opportunity for organizations with complementary expertise to help operators put frontier Claude models to work responsibly in environments where security decisions can affect availability, safety and resilience. Learn more in Anthropic’s announcement.
Longevity and Obscurity: Two Aspects of the Same Challenge
Somewhere in a plant right now there’s a controller that was installed before most of the people who maintain it were hired. It communicates with a protocol designed when "network" meant a serial cable to the panel down the hall. It has run for 20 or more years and it has done its job without fail.
This combination of legacy technology and operational criticality makes OT devices difficult to defend. Its longevity and obscurity are two aspects of the same challenge. Engineers built it to standards that provide decades of reliability, physical safety and predictable behavior. However, these standards were set when cyber risk existed but was not yet treated as an engineering requirement tied to uptime and safety. The controller still meets its original design requirements, but cybersecurity requirements have evolved rapidly.
Why OT Cybersecurity Lags IT Cybersecurity
An IT security team may patch as often as weekly or monthly. An OT security team may only get one maintenance window a year. For some equipment, “patching” means an engineer on site, a halted production line and a change board that meets quarterly. This creates a structural constraint that can be mischaracterized as negligence. Given the rapidly evolving threat landscape and the high cost of planned downtime, protecting OT systems requires a fundamentally different approach.
Limited Visibility, Patching Windows and Downtime
The challenge has multiple dimensions, and I'll start with the most important one: defenders in industrial environments are asked to protect systems they can’t fully inventory, easily patch or afford to interrupt. This means defending potentially unknown or mischaracterized assets that can’t be freely modified or taken offline to investigate. IT security tools and processes assume at least one of these options is available. In OT security, these options are rarely available.
Disparate Vendors, Protocols and Operating Systems
Heterogeneity compounds the cybersecurity challenges. Walk one facility and you will find equipment from dozens of vendors, spanning several technology generations, each generation with its own protocol and idea of what a legitimate message looks like. Modbus coexists with DNP3, EtherNet/IP, and some custom undocumented protocol a system integrator wrote in 2004. In a standard IT estate, with its handful of operating systems and its shared primitives, there’s no equivalent.
Scarcity of OT Cybersecurity Talent
Compounding the problem is the number of professionals fluent in both industrial processes and the evolving landscape of OT-specific cyber threats. How many candidates in a hiring round for an OT security analyst do you think would be able to read a Modbus function code and a Sigma rule with equal comfort? At Nozomi, I’ve been hiring professionals with this combination of expertise for product engineering and other roles for more than a decade. It hasn’t gotten easier.
Cybersecurity Is a Team Sport
A water utility, a semiconductor lab and a rail operator share very little technically. They each use different equipment and different protocols, have different failure modes, and are subject to different regulations. However, they do face overlapping adversaries, and the knowledge required to defend each of these sectors is scattered across separate hands: operators who understand their processes, OEMs who know their firmware, integrators who know how the pieces were wired together, researchers who know the attack patterns and governments who see the threat picture across sectors.
The collective picture only forms when those hands share what they hold, but unfortunately, sharing is hard to sustain. Information-sharing agreements take years to put into practice, vendors see only their own slice, and operators understandably limit what they disclose.
Anthropic’s Critical Infrastructure Defense Program is bringing together the right people to strengthen the defensive baseline. By applying frontier Claude models and sharing what they learn, partners can help defenders act faster and with greater confidence..
How Frontier AI Is Helping OT Security Teams
For operators, the value of frontier AI is practical: it can help small, specialized teams make sense of unfamiliar devices, protocols and attack patterns, while reducing the time spent triaging and correlating alerts. Two developments stand out.
- Augmented investigation. Frontier AI can help security teams reason across technical documentation, device behavior, protocol details and threat research when they encounter a system or attack pattern outside their direct experience. It does not replace an OT expert. It helps that expert cover more ground, test assumptions and focus judgment where it matters most.
- Augmented defense. Through Project Glasswing, we use frontier Claude models to find and fix vulnerabilities in our own platform, and that review is now part of our standard platform security process. Across our broader research and product work, Claude helps our researchers analyze and verify more information, while people retain responsibility for decisions and actions in operational environments.
Frontier AI is evolving rapidly, and its use in critical infrastructure requires people to remain vigilant and accountable. Joining Anthropic’s Critical Infrastructure Defense Program gives Nozomi another forum to contribute what we have learned from protecting operational environments and to learn from other partners working on the same challenge.
What Nozomi Networks Brings as a Program Partner
Nozomi has spent more than a decade helping critical infrastructure operators understand what is connected, how those assets normally behave and which changes or threats require action. Our work supports some of the world’s largest industrial organizations. The impact is straightforward: give defenders the context to investigate faster and reduce risk without disrupting the processes they are protecting.
That mission is reflected in the Nozomi Networks platform, which combines asset visibility, threat detection and operational context for OT, IoT and cyber-physical systems. We have built AI capabilities in-house since day one, applying machine learning, Bayesian inference and now large language models to cyber defense. Vantage IQ, our agentic AI assistant, provides continuous alert analysis, threat insights and remediation guidance so teams can move from signal to informed action faster, with human experts always in the loop for decisions where the consequences of error can be severe.
The Question that Launched Nozomi Networks
Nozomi began as a research question: could an industrial network be understood well enough to be defended? Thirteen years later, the question remains the same even as tools and technology have evolved.
We are grateful for the opportunity to join Anthropic’s program as a member, share what we have learned and learn from organizations bringing complementary expertise to the same mission. Critical infrastructure operators need technology that helps them act with greater speed and confidence without losing the operational context or human judgment their environments demand. That is the standard we will continue to bring to our products, research and participation in the program, because the controller described earlier may keep running for another 20 years.






