Cyolo Introduces AI-Powered Live Risk Detection for Real-Time Oversight of Remote OT Sessions | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Cyolo, a provider of secure connectivity for critical infrastructure and operational technology (OT), has announced Live Risk Detection, an AI-powered capability designed to provide real-time supervision of remote OT sessions.

Live Risk Detection applies context-aware AI to active OT sessions, detecting cyber threats, operational risks, and anomalous behavior as they occur. When potentially risky activity is identified, the capability alerts security and operations teams within seconds, giving them an opportunity to investigate and respond before an incident escalates or affects operations.

The need for session oversight is increasing as employees, vendors, and OEMs conduct more critical OT activities remotely. Meanwhile, AI-enabled threats are accelerating the speed and scale of malicious activity. Manually monitoring every remote session on a 1:1 basis is not practical in large environments, leaving some potentially risky activity without direct oversight. Live Risk Detection addresses this challenge by providing AI-based supervision across sessions and focusing human attention on activity that may require intervention.

Rather than assessing individual actions solely against predefined allow or block policies, Live Risk Detection analyzes activity in the context of the broader session. The capability is designed to identify malicious or unsafe activity, as well as user mistakes that could contribute to downtime or operational disruption. It can also detect patterns in which a series of individually legitimate actions may collectively signal an attack, while distinguishing activity that appears risky on its own but is appropriate within the context of the session.

Live Risk Detection does not take autonomous action. Instead, it identifies potential risks and alerts the appropriate teams, maintaining human oversight throughout the response process. Security and operations personnel can determine whether to continue observing, join, or terminate a session. This human-controlled model is particularly important in OT and critical infrastructure environments, where actions taken within digital systems can produce physical consequences.

“Zero Trust doesn’t end at login,” said Almog Apirion, CEO and co-founder of Cyolo. “Getting the right person connected to the right system is key, but that’s just the beginning of the story. Risk can emerge even after a session is underway. Live Risk Detection gives teams another set of eyes, helping them spot risk while there’s still time to intervene—and without taking control away from the people who know the environment best.”

Live Risk Detection enables security and operations teams to:

• Identify cyber and operational risk: Detect malicious activity, human errors, unsafe actions, and configuration changes that could affect equipment, processes, or production, including activity during third-party vendor sessions.

• Assess risk in context: Analyze activity throughout a session, including user intent, to identify combinations of otherwise legitimate actions that may create risk and accelerate the containment of AI-enabled threats.

• Respond during active sessions: Deliver real-time alerts to relevant security and operations stakeholders, allowing them to evaluate activity and intervene or terminate the session when necessary.

• Scale remote session oversight: Reduce reliance on 1:1 manual monitoring by prioritizing sessions and activities that are most likely to require human review.

• Maintain human control: Apply AI to identify potential risks and provide contextual information without autonomously taking action, keeping response decisions with human experts.

Designed as an agentless capability, Live Risk Detection requires no software installation or changes to the remote user’s device and supports RDP, VNC, and other remote access protocols. Teams can configure risk sensitivity and notification thresholds according to severity. Alerts provide information including the risk level, relevant activity, and user identity to support investigation. Alert data and activity logs can also integrate with existing security workflows, including SIEM platforms.

The launch expands Cyolo’s efforts to help OT defenders improve visibility and accelerate response to both AI-enabled and traditional cyber threats. Live Risk Detection complements Session Intelligence, which Cyolo introduced earlier this year to make session recordings searchable and provide operational insights, by extending AI-powered analysis into active remote sessions.

Live Risk Detection is available as a capability within the Cyolo PRO (Privileged Remote Operations) remote access solution and forms part of Cyolo’s full-stack Secure Connectivity Platform for OT and critical infrastructure.

To learn more or request a personalized demonstration, visit https://cyolo.io.

_____

About Cyolo

Cyolo secures every connection across critical infrastructure and operational technology (OT) with a full-stack Secure Connectivity Platform that unifies remote privileged access and zero trust microsegmentation. Leading manufacturers, utilities, and data centers rely on Cyolo to securely connect employees and third parties to cyber-physical systems, limit lateral movement, contain blast radius, and keep critical operations running.

Join our LinkedIn group Information Security Community!

——————————————————-


Click Here For The Original Source.