For the nation’s critical infrastructure, cyber security conversations often start in the control room – SCADA, PLCs, HMIs and other operational technology.
That focus is understandable. But it is only part of the story.
The endpoint can be where an attack begins.
It could be a contractor’s laptop, a remote-support session, an engineering workstation, a shared operations terminal or a sensor running a legacy operating system somewhere deep in the operational environment.
And as attacks become increasingly automated and AI-assisted, that risk is only going to increase.
When detection can't move fast enough
We are already seeing how AI can change the economics of cyber attacks. Attackers can use AI to automate reconnaissance, identify vulnerabilities, generate convincing phishing and social engineering campaigns, and accelerate the process of finding their way into an environment.
The question is: what happens when the attack moves faster than our ability to detect and respond to it?
This is particularly important in critical infrastructure.
Many operational environments contain legacy software and systems that cannot simply be patched or replaced. Sensors, control devices and other OT endpoints may still be running older operating systems because the application or equipment they support was designed around them.
These systems can be essential to operations, but they can also become difficult-to-manage points of exposure.
So the question should not just be: “Can we detect an attack?”
It should also be: “When we are attacked, how quickly can we contain it, recover and get back to a known-good state?”
That is where cyber resilience starts.
We ask too much of the traditional endpoint
Most organisations have spent years adding layers of protection around Windows endpoints – patching, Endpoint Detection and Response (EDR), vulnerability management, application control, encryption and monitoring.
All of these controls have an important role.
But there is a bigger question worth asking: Does every endpoint actually need to be a general-purpose computer?
A control-room terminal, engineering workstation, field-services kiosk or dedicated access device may only need to provide access to a small number of approved applications or services.
If that is the case, why give it the ability to install software, store data locally, change its configuration and run anything a traditional PC can?
Every additional capability creates another potential attack path.
This is where immutable or controlled endpoint approaches become interesting.
Rather than treating the endpoint as a computer that can continually change, it becomes a tightly governed access point with a defined purpose and configuration.
It doesn't eliminate cyber risk. Nothing does.
But it can reduce the opportunity for persistence, minimise configuration drift and, importantly, make recovery simpler.
Recovery is part of the security strategy
This is where cyber security and business continuity and disaster recovery (BC&DR) need to come together.
Imagine an endpoint has been compromised. Your security team may be investigating the incident, isolating systems and working out exactly what happened. But operations still need to continue.
If that endpoint is a traditional, mutable device, recovery may mean rebuilding the operating system, reinstalling applications, applying patches, restoring configurations and validating everything before it can safely return to service.
With an immutable endpoint, the recovery process can typically be much simpler.
Reboot. Restore the known-good state. Get back to work.
That doesn't mean every immutable endpoint will recover instantly, or that it removes the need for incident response. It means the endpoint itself is designed with recovery in mind.
And in critical infrastructure, that difference matters.
Resilience is bigger than the endpoint
Of course, changing the endpoint is not a silver bullet.
A resilient IT and OT environment still needs strong identity and privileged-access controls, meaningful segmentation, secure remote access, vulnerability management, asset visibility, monitoring, tested backups and well-practised recovery processes.
The important thing is how those controls work together.
Cyber resilience is not about collecting more security products. It is about creating an environment that is harder to compromise, easier to control and faster to recover.
That means asking some straightforward questions:
• Does every endpoint have a clearly defined purpose?
• Are legacy operating systems and software still required – and if so, how are they protected?
• Are sensors and other OT devices running software that can no longer be supported or patched?
• Can compromised endpoints be isolated quickly?
• How much capability and data actually needs to remain on the endpoint?
• Can the endpoint be returned to a known-good state quickly?
• Are third-party and remote-access pathways properly controlled?
• Do IT, OT, engineering and security teams have the same view of the risk?
These are not just IT questions.
For critical infrastructure, they are operational resilience questions.
AI readiness starts here too
There is another reason this conversation matters. As organisations look at AI, the focus often moves quickly to what AI can do for the business. But before AI can safely access business or operational information, organisations need to understand where their data lives, who can access it and what controls are in place.
The same principle applies to AI-powered attacks. If attackers can use AI to move faster, organisations need to think about resilience before the attack reaches the endpoint – and have a recovery path when prevention and detection don't work.
AI readiness and cyber resilience therefore belong in the same conversation.
It is not just about being ready to use AI. It is about being ready for what AI changes on both sides of the security equation.
Start with the risk, not the technology
We are not suggesting every Windows endpoint needs to disappear.
There will always be applications, vendors and operational requirements that require a conventional operating environment. And there are legitimate reasons why legacy OT systems remain in service.
The point is to challenge the assumption that every device needs to work like a personal computer.
For some use cases, a more controlled or immutable endpoint architecture could reduce the attack surface and provide a faster path to recovery.
But you need to understand the environment first and that is where Com-X comes in.
Through our Cyber Maturity Uplift Program, we help organisations understand where their greatest risks sit and build a practical roadmap to improve resilience – from vulnerability management and incident response through to governance, BC&DR and secure-by-design practices, for your IT and OT environments.
And as organisations prepare for AI, our AI Readiness approach helps businesses understand their data, security, privacy and governance requirements before putting AI to work.
Because the goal isn't simply to prevent every attack.
It's to make sure that when something does get through, it doesn't become an outage.
If you are responsible for IT, OT or security within critical infrastructure, talk to Com-X about where your current endpoint architecture may be creating unnecessary risk – and where you can build greater resilience into the environment.




