McCrary Institute Outlined AI Security Priorities
The institute released three recommendations to protect critical infrastructure from advanced cyber threats.
Updated on Oct. 5, 2026 in Artificial Intelligence

Live Poll
Is now the right time for infrastructure providers to integrate AI into their security systems?
The McCrary Institute has published three priorities for securing power, water, and manufacturing sectors against AI-enabled cyberattacks. The guidelines were developed following a tabletop exercise conducted with Booz Allen.
Why it matters
AI-powered threats allow attackers to identify vulnerabilities and execute disruptions with unprecedented speed, necessitating a move toward machine-speed defense mechanisms.
The McCrary Institute identified three core priorities to strengthen infrastructure resilience against AI-powered threats. These findings follow an assessment of operational technology systems currently supporting national power, water, and manufacturing grids.
The players
McCrary Institute
Located at Auburn University, this organization focuses on protecting critical infrastructure and cyber-physical systems.
Booz Allen
This management consulting firm specializes in technology and cybersecurity services for government and commercial sectors.
Frank Cilluffo
He is an expert in cybersecurity and authored the recommendations for infrastructure security readiness.
Brad Medairy
As a collaborator on the study, he contributed to defining the necessary priorities for defending against AI-enabled cyber threats.
The details
Organizations are urged to pressure-test security controls using realistic, emulated AI threats while deploying agentic systems to detect and contain attacks automatically. These measures aim to shift security processes away from reliance on slow human-led alert investigations.
Timeline
A tabletop exercise was convened by Booz Allen and the McCrary Institute in September 2026.
The institute published its security recommendations on September 28, 2026.
The Tech Race
These priorities represent a strategic shift as infrastructure providers move beyond standard protocols to counter threats capable of operating at machine speed. This evolution parallels the transition seen in the National Institute of Standards and Technology Cybersecurity Framework toward more dynamic, AI-integrated defensive postures.
While these priorities focus on enterprise-level defense, they ultimately influence the reliability of essential services like water and electricity. Organizations adopting these standards may reduce the risk of outages and systemic failures in critical utility networks.
The takeaway
Critical infrastructure operators must transition from manual alert investigation to automated, machine-speed defense to remain resilient. Implementing proactive stress-testing against emulated AI attacks is now considered essential for maintaining operational continuity.
Further reading
Learn more about the latest developments in the Artificial Intelligence sector.
Source note: This article includes information reported by Industrial Cyber.
Live Poll
Is now the right time for infrastructure providers to integrate AI into their security systems?










