Cyolo lets AI flag dangerous OT activity but humans stay in control

AI is showing up everywhere in cybersecurity, but there is a big difference between using it to identify trouble and letting it make decisions on its own. Cyolo is taking the more cautious route with a new feature designed to monitor remote sessions inside operational technology environments while leaving the final response to humans.

The company has introduced Live Risk Detection for its Cyolo PRO remote access platform. The AI-powered capability monitors active sessions for potentially malicious, unsafe, or otherwise risky behavior and alerts security teams while the activity is still happening.

That matters in OT environments, where employees, contractors, vendors, and equipment manufacturers may remotely access systems tied to factories, utilities, data centers, and other critical infrastructure. A bad command or suspicious sequence of actions can have consequences that extend beyond a compromised account and into physical operations.

Cyolo says Live Risk Detection evaluates activity across an entire session instead of simply comparing individual actions against predefined allow or block rules. That broader context is intended to help the system recognize when several actions that look harmless on their own may collectively point to a developing problem.

The same contextual approach can also prevent legitimate work from being flagged unnecessarily. Administrators and technicians often perform unusual tasks in OT environments, so an action that appears suspicious in isolation may make complete sense when viewed as part of the larger session.

The key limitation is intentional. Live Risk Detection can assign risk, provide context, and alert security or operations teams, but it does not automatically terminate sessions or take control of the response. A human decides whether to keep watching, join the session, or shut it down.

That approach makes sense for critical infrastructure, where digital actions can affect physical equipment and production. AI may be useful for watching more activity than a human team could realistically monitor, but giving a model autonomous power to interrupt industrial systems would introduce its own set of risks.

Cyolo CEO and co-founder Almog Apirion says authentication alone is not enough to secure remote access.

“Zero Trust doesn’t end at login,” Apirion said. “Getting the right person connected to the right system is key, but that’s just the beginning of the story. Risk can emerge even after a session is underway. Live Risk Detection gives teams another set of eyes, helping them spot risk while there’s still time to intervene, and without taking control away from the people who know the environment best.”

The feature is also meant to reduce the burden of manually supervising remote sessions one by one. Instead of trying to watch everything, security teams can focus on sessions that the system believes may deserve closer attention.

Cyolo says the technology can identify both cybersecurity threats and operational mistakes, including unsafe actions or configuration changes that could disrupt equipment or production. Third-party access is one obvious use case, since outside vendors often need remote access to industrial systems but can also introduce additional security risk.

Live Risk Detection is agentless, so remote users do not need to install software on their devices. It supports technologies including RDP and VNC, while administrators can adjust sensitivity levels and notification thresholds based on severity.

Alerts can include the user’s identity, details about the activity, and the assigned risk level. Cyolo says those alerts and activity logs can also feed into existing security workflows, including SIEM platforms.

The company previously introduced Session Intelligence, which uses AI to make recorded remote sessions searchable and easier to analyze after the fact. Live Risk Detection brings that analysis into active sessions, where defenders may still have time to intervene before suspicious behavior turns into an incident.

The unanswered question is how accurately the system can separate genuinely dangerous behavior from unusual but legitimate administrative work. False positives could create alert fatigue quickly, particularly in environments where technicians routinely perform uncommon or highly specialized tasks.

Cyolo is still drawing a clear boundary around what the AI can do. It gets to watch, analyze, and flag potential trouble, but the people responsible for the environment remain the ones making the final call.

☕

Support independent tech journalism

NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.

Support NERDS.xyz
Written by

Brian Fagioli ✔

Technology journalist and founder of NERDS.xyz

Brian Fagioli is a technology journalist and founder of NERDS.xyz. A former BetaNews writer, he has spent over a decade covering Linux, hardware, software, cybersecurity, and AI with a no nonsense approach for real nerds.

Leave a Comment