The AOT Predictive Maturity Curve

Progressive scaling of automation as the system earns trust — from augmented analytics to closed-loop resilience.

AOT Predictive Maturity Curve showing five phases — from Organizational Readiness to Closed-Loop Resilience

* This model is static — awaiting federal guidance from the NIST AI Agent Standards Initiative (launched Feb 2026) and NCCoE Agent Identity & Authorization Framework. Once published, the maturity model will be updated to incorporate agent identity governance and federal control overlay requirements.

Phase 0 — Organizational Readiness

People, Process & Organizational Commitment

AOT cannot succeed without organizational capacity to sustain it. Every framework (ISA/IEC 62443-2-1, NIST 800-82r3) assumes organizational readiness — but most programs fail because they deploy technology without the people to operate it. Phase 0 audits whether the organization has the roles, competencies, and change management infrastructure to run AOT before any software ships. This work runs in parallel with the technical architecture assessment — you can't design what you can't staff, and you can't staff what you haven't designed.

Required Roles

AOT Operator (maps to existing Control Room Operator / SCADA Technician): Interprets AI-generated alerts, executes containment playbooks, monitors the AOT dashboard during incidents. Must understand both the physical process and the network topology.

Macro Custodian (maps to existing I&C Engineer / OT Security Analyst): Writes, tests, and signs off on containment macros. Must understand plant process safety, the network fabric, and the MOC process. Minimum 2 years OT engineering experience required.

Security Lead (maps to OT Security Analyst / IT Security Manager): Oversees AOT deployment, manages promotion gates, coordinates third-party audits. Acts as the bridge between corporate security and plant operations.

Executive Sponsor (maps to Plant Manager / VP Operations): Organizational commitment, resolves cross-departmental conflicts, approves MOC submissions. Must be a VP-level decision-maker, not a middle manager.

IT/OT Liaison: The single most critical missing role in OT programs. Translates corporate IT security policy to OT reality and vice versa. Without this person, AOT will be blocked by IT security policies that don't understand OT constraints, or OT engineers who don't understand security requirements.

Process Engineer Representative: Someone who understands the physical process being protected. A containment macro that isolates a network segment may also starve a reactor of cooling water — only this person knows the difference.

Readiness Assessment

  • Staffing: Minimum 2 trained AOT Operators per shift (24/7 or documented partial-coverage plan with escalation path)
  • Macro Custodian: Named individual with documented OT engineering experience + completed AOT macro writing tabletop exercise
  • IT/OT Liaison: Named individual with authority in both IT and OT domains
  • Executive Sponsor: VP-level sign-off on AOT program with confirmed organizational commitment
  • MOC Integration: Containment macro updates flow through existing Management of Change process — documented procedure, not a new parallel process
  • Incident Response: IR runbooks updated to reference AOT alert types, escalation paths, and veto procedures
  • Training: Operators complete ≥24 hours combined classroom + hands-on tabletop exercises with passing score (≥80%) on written competency exam covering: Modbus/DNP3 protocol basics, network isolation concepts, AOT alert interpretation, veto kill-switch procedures
  • Baseline Competency: Each named operator demonstrates: ability to identify a Modbus write function code; distinguish legitimate engineering workstation from lateral movement; execute the 3-step veto procedure within 30 seconds
  • Organizational Commitment: Documented commitment covering Year 1 — confirmed by decision-maker, not just identified sponsor

Items 10–12 (Regulatory, Vendor Plan, IT Dep Map) are addressed in the AOT Implementation Guide, not Phase 0. See the Phase 0 Design Rationale for methodology.

🎯 Target: Organization capacity, not technology deployment

Completion Gate

Phase 0 gates are split into hard requirements (must pass before any AOT technology deploys) and soft requirements (remediation allowed, must resolve before Phase 2). This prevents the common failure mode of deploying tools without the people to operate them — while not paralyzing organizations that are close but not perfect.

Hard Gates — Must Pass Before Phase 1 Starts

  • Operator Qualification (H1): Each named operator completed ≥24 hours combined classroom + tabletop exercises, passed written competency exam ≥80%
  • Macro Custodian (H2): Named individual with ≥2 years OT engineering experience, passed macro-writing tabletop exercise
  • Telemetry Baseline (H3): Existing OT security tools (Dragos, Claroty, Nozomi, or equivalent) confirmed operational in AOT coverage zones, producing baseline alert data. The Cognitive Engine cannot operate without validated telemetry input.
  • Staffing Model (H4): Documented roster, shift schedule, and escalation path for AOT coverage — approved by operations management. H1 tests individual qualification; H4 tests organizational structure and backup coverage.

Soft Gates — Remediation Allowed, Must Complete Before Phase 2

  • IT/OT Liaison: Named individual with authority in both domains — needed to coordinate AI system access across network boundaries
  • MOC Integration: Macro updates flow through the plant's existing Management of Change process
  • Incident Response: IR runbooks updated to reference AOT alert types and escalation paths

Evidence Requirements

  • Tabletop exercise: Operators respond to a simulated AOT alert in real-time. Measured: alert interpretation accuracy ≥80%, veto procedure executed within 30 seconds, escalation path followed correctly
  • Written competency exam: Each operator scores ≥80% on protocol identification, alert interpretation, and containment execution knowledge
  • MOC procedure tested: One containment macro update flows through the documented MOC process — verified end-to-end with sign-off from Process Engineer Representative

⏱️ Typical duration: 1-4 weeks for small/medium facilities with existing OT security programs. 3-12 months for large organizations requiring procurement cycles, HR approvals, or union negotiations. This phase runs in parallel with the technical architecture design.

Phase 1 — 20% Trust

Augmented Analytics

The system observes, correlates, and explains. The human does everything else.

AI Role

Translates multi-tool alerts into natural language telemetry. Suggests playbook options from the pre-approved macro library.

Human Role

100% In-the-Loop. Manual copy, paste, and execution of playbooks. The human is the decision-maker and executor at every step.

🎯 Target: Core Production Subnets
Trust Level: 20% — Read-only monitoring, no execution

Promotion Criteria to Phase 2

  • Minimum 90 days of Phase 1 operation with zero false-positive escalation incidents
  • AOT analysis matches or exceeds human triage accuracy (≥85% concordance)
  • All four Architectural Guardrails verified through penetration testing
  • 50% improvement in time-to-understand incidents vs. baseline
  • At least 20 containment macros written, tested, and signed off
Phase 2 — 40% Trust

Directed Playbooks

The system generates tailored scripts. The human approves with a single click.

AI Role

Generates localized, pre-validated containment scripts specific to the threat, zone, and operational context. Scripts are assembled from the pre-approved macro library.

Human Role

In-the-Loop. Reviews proposed scripts with full context (affected assets, expected outcome, rollback path). Single-click "Approve & Execute."

🎯 Target: IT/OT DMZ Boundaries
Trust Level: 40% — AI generates, human approves

Promotion Criteria to Phase 3

  • Minimum 180 days of Phase 2 operation
  • 95% of proposed scripts approved without modification
  • Zero safety incidents caused by executed scripts
  • All rollback procedures tested and verified
  • Mandatory minimum review dwell-time (15 seconds) before approval button activates
  • Random weekly audit sampling of approved actions by Macro Custodian
  • At least 50 containment macros covering IT/OT boundary threats
  • Enforcement Gate penetration test passed — zero bypasses
Phase 3 — 70% Trust

Conditional Autonomy

The system acts at machine speed. The human watches with a kill-switch.

AI Role

Instantly shoots pre-configured playbooks to the Enforcement Gate. No human approval required — the system acts within strictly defined safety boundaries.

Human Role

On-the-Loop. Real-time visibility with a 5-second human veto kill-switch. The operator supervises, not executes.

🎯 Target: Out-of-Band Networks
Trust Level: 70% — Automated execution, human can veto

Promotion Criteria to Phase 4

  • Minimum 365 days of Phase 3 operation
  • Zero false-positive containment incidents
  • Kill-switch exercised in ≥3 drills with successful abort verified
  • Containment of simulated attacks in <2 seconds end-to-end
  • All four guardrails re-validated by independent third-party audit
  • At least 200 containment macros validated
Phase 4 — 90% Trust

Closed-Loop Resilience

The system defends itself. The human recovers and reviews.

AI Role

Runs continuous parallel simulations to optimize defense postures. Full machine-speed containment within strictly defined safety boundaries. Generates forensic reports post-incident.

Human Role

By-Exception. Notified only when the system encounters unknown scenarios. Primary responsibility: post-incident recovery, forensic review, and system tuning.

🎯 Target: Modernized Software-Defined Networks (SDN)
Trust Level: 90% — Full autonomous defense, human handles recovery

Ongoing Requirements

  • Quarterly independent security audits
  • Annual macro library review and update
  • Continuous measurement: false positive rate, containment success rate, MTTR
  • Human operator training and certification on AOT oversight
  • IEC 61508 SIL 2 or equivalent safety certification

Transition Summary

TransitionMinimum DurationKey Gate
Phase 0 → Phase 11 week – 12 months9-point assessment passed, evidence documented, commitment confirmed
Phase 1 → Phase 290 days85% concordance, 20+ macros
Phase 2 → Phase 3180 days95% approval rate, zero safety incidents
Phase 3 → Phase 4365 daysZero false positives, <2s containment, 3rd-party audit

No phase can be skipped. Each promotion requires all criteria met AND all four Architectural Guardrails re-validated.

← Back to the Seminal Article