New AI-powered capability helps OT defenders keep pace with AI-driven threats by monitoring active remote sessions, identifying security and operational risk in context, and alerting teams in real time so they can intervene before incidents escalate or disrupt operations.
Miramar, FL, September 30, 2026 — Cyolo, the leading provider of secure connectivity for critical infrastructure and operational technology (OT), today announced Live Risk Detection, a first-of-its-kind AI capability that sets a new standard for remote session supervision.
Live Risk Detection brings real-time, context-aware detection and response to active OT sessions by identifying cyber threats, operational risks, and unexpected behavior as they occur. When potential risk is detected, Live Risk Detection alerts teams within seconds, enabling them to investigate and respond while the session is still active and before operations are impacted.
As remote connectivity continues to expand, employees, vendors, and OEMs are performing more critical OT work remotely. At the same time, AI-enabled threats are increasing the speed and effectiveness of malicious activity. But 1:1 monitoring of every session is not practical at scale, meaning potentially risky sessions may go unsupervised. Live Risk Detection removes this bottleneck by adding AI supervision to every session and directing human attention to activity that may require intervention.
In contrast to approaches that evaluate individual actions against predefined allow or block criteria, Live Risk Detection uses context-aware AI to assess activity across the full session. It identifies activity that is inherently malicious or unsafe, as well as mistakes that could lead to downtime or other operational disruptions. It can also recognize when a sequence of individually legitimate actions may indicate that an attack is underway or, conversely, when activity that may appear risky in isolation is benign in the context of the session.
Crucially, Live Risk Detection never acts autonomously. It flags potential risk and alerts relevant teams, always keeping a human in the loop to decide whether to observe, join, or terminate the session. This human-controlled approach is essential in OT and critical infrastructure environments, where digital actions can have physical consequences.
“Zero Trust doesn’t end at login,” said Almog Apirion, CEO and co-founder of Cyolo. “Getting the right person connected to the right system is key, but that’s just the beginning of the story. Risk can emerge even after a session is underway. Live Risk Detection gives teams another set of eyes, helping them spot risk while there’s still time to intervene—and without taking control away from the people who know the environment best.”
Live Risk Detection helps security and operations teams:
Identify cyber and operational risk: Detect malicious activity as well as mistakes, unsafe actions, or configuration changes that could disrupt equipment, processes, or production, including during third-party vendor sessions.
Understand risk in context: Assess activity across the broader session, including user intent, to identify when otherwise legitimate actions combine to create risk and help contain AI-enabled threats faster.
Respond while the session is active: Alert the right security and operations stakeholders in real time so they can assess the situation and, if necessary, intervene or terminate the session before risk escalates.
Scale session oversight: Reduce the bottleneck of 1:1 manual monitoring by directing attention to the sessions and activities most likely to require review.
Keep humans in control: Use AI to flag potential risk and provide context without taking autonomous action, leaving response decisions to human experts.
Agentless by design, Live Risk Detection requires no software downloads or changes on the remote user’s device and works seamlessly across RDP, VNC, and more. Teams can adjust risk sensitivity and set notification thresholds by severity level, with alerts providing the risk level, activity details, and user identity needed for investigation. Alerts and activity logs can also feed into existing security workflows, including SIEM platforms.
This launch builds on Cyolo’s wider effort to help OT defenders scale visibility and respond faster to both AI-enabled and conventional cyber threats. Live Risk Detection complements Session Intelligence, introduced earlier this year to turn session recordings into searchable operational insights, by bringing AI-powered intelligence into the active session itself.
Live Risk Detection is available as a capability for the Cyolo PRO (Privileged Remote Operations) remote access solution and is part of Cyolo’s full-stack Secure Connectivity Platform for OT and critical infrastructure.
To learn more or request a personalized demonstration, visit https://cyolo.io.
Cyolo secures every connection across critical infrastructure and operational technology (OT) with a full-stack Secure Connectivity Platform that unifies remote privileged access and zero trust microsegmentation. Leading manufacturers, utilities, and data centers rely on Cyolo to securely connect employees and third parties to cyber-physical systems, limit lateral movement, contain blast radius, and keep critical operations running.
Gabi Benedyk
Headline Media
gabi@headline.media
+972 584847380