< All Posts

2026-10-02 | ニュース

NTT DOCOMO BUSINESS and Powder Keg Technologies Develop an AI-Powered System to Automate OT Asset Visibility and Attack Risk Validation

Overview diagram of the system developed by NTT DOCOMO BUSINESS and PKT for OT asset visibility and attack risk validation

Advancing OT Security Operations through Continuous Threat Exposure Management (CTEM)

NTT DOCOMO BUSINESS, Inc. (formerly NTT Communications Corporation; hereinafter “NTT DOCOMO BUSINESS”) and Powder Keg Technologies, Inc. (hereinafter “PKT”) have developed a system (hereinafter “the System”) that integrates NTT DOCOMO BUSINESS’s IDS*1 for OT systems, “OsecT*2,” with PKT’s autonomous penetration testing tool*3 “MUSHIKAGO*4,” and incorporates AI technology to automate the entire process from OT asset visibility to attack risk validation. In OT environments that control and operate equipment at factories and plants, the System enables Continuous Threat Exposure Management (CTEM)*5, continuously visualizing and evaluating cyber risk and supporting countermeasures prioritized by risk.

1. Background

In recent years, as factories become smarter and IoT and physical AI are increasingly used in social infrastructure, sophisticated cyberattacks such as ransomware targeting OT environments have surged, making continuous risk management an urgent priority. However, OT environments face a number of challenges. The growing number of managed devices complicates asset management, and because stable system operation must be prioritized, vulnerability assessments using high-load active scanning*6 are difficult to perform. As a result, passive scanning*7 can miss vulnerabilities, and it is difficult to assess and prioritize risks based on validation of actual attack feasibility in real environments. In addition, a shortage of security personnel is increasing the burden of ongoing security operations.

2. Overview of the System

By leveraging the advanced reasoning and autonomous processing capabilities of AI, the System automates the entire process in OT environments end to end, from asset visibility and vulnerability detection to attack validation and risk assessment. Through joint development, the two companies have combined OsecT’s “visualization and detection” of assets and vulnerabilities within OT environments with MUSHIKAGO’s “safe, autonomous validation” of attack paths and risks, realizing in OT environments Continuous Threat Exposure Management (CTEM), which is becoming increasingly important in cyber risk management.

The key features of the System are as follows.

(1) Automated visibility of large-scale OT assets

Simply by connecting the devices deployed at factories, plants, and other sites to the network, the System automatically detects, without omission, all equipment present within a large-scale OT network. It visualizes OT assets every day, including devices that administrators have not fully identified, preventing gaps in asset management.

(2) Identifying vulnerabilities through availability-conscious active scanning

By performing active scanning with legitimate, read-only commands, the System identifies device models and firmware without degrading the availability of the OT environment. Based on the model and firmware information, it can detect the vulnerabilities contained in each device. By collecting reliable information rather than relying on estimates, it reduces missed vulnerability detections.

(3) Fully automated process through to penetration testing

Using AI technology, the System automatically executes the entire process of “asset visibility → vulnerability detection and management → penetration testing” end to end. Even where security professionals with advanced expertise are in short supply on site, practical security validation can be operated.

(4) Risk prioritization based on the real environment

Rather than simply listing vulnerabilities exhaustively, the System verifies misconfigurations and the actual feasibility of attacks through detailed security testing, and clearly presents the security risks that should be addressed and remediated first on site.

3. Future Plans

NTT DOCOMO BUSINESS and PKT plan to begin offering the System within fiscal year 2026 as a corporate solution for manufacturers and operators of social infrastructure. In the future, the companies are also considering incorporating it as a security feature into the network services provided by NTT DOCOMO BUSINESS, contributing to the realization of secure industrial digital transformation (DX).

4. Exhibiting at NTT docomo Business Forum’26

A demonstration of the System is planned at “NTT docomo Business Forum’26,” to be held on Thursday, October 8 and Friday, October 9, 2026. For details, please refer to the exhibition information on the official website.

Official website: https://www.ntt.com/business/go-event.html

■ Exhibit title: Centralized OT Security Monitoring for Overseas Sites
■ Exhibit number: GD-04
* Venue: The Prince Park Tower Tokyo, B2 Floor
* Dates: Thursday, October 8 – Friday, October 9, 2026, 9:30–17:30 (JST)
* Participation: By invitation only
* Admission: Free

Powder Keg Technologies, Inc. company information

Powder Keg Technologies, Inc. is a startup focused on developing next-generation cybersecurity technology. The company designs and provides MUSHIKAGO, a domestically developed AI-driven security assessment device, supporting enterprises with IT asset visibility, vulnerability assessment, penetration testing, and security consulting.

MUSHIKAGO is an AI-driven security assessment device that performs, end to end, everything from automated visualization of IT assets, in office environments as well as factory OT environments, to vulnerability assessment and penetration testing. It supports alignment with the JAMA/JAPIA Cybersecurity Guidelines — Factory Domain Edition, and we welcome inquiries and product demonstration requests from companies looking to strengthen their factory security.

*1: IDS stands for Intrusion Detection System, a security technology that detects unauthorized access and attacks on networks and systems in real time and issues alerts.

*2: OsecT is a service provided by NTT DOCOMO BUSINESS that visualizes and detects security risks in industrial control systems that support, for example, factory production lines.

*3: Penetration testing is a testing method that verifies the effectiveness of security measures by attempting to break into systems and networks using the same techniques as real attackers.

*4: MUSHIKAGO is a domestically developed security product from Powder Keg Technologies, Inc. that uses AI to visualize all assets (PCs, IoT devices, printers, etc.) on networks, including closed-network and OT environments, and carries out everything through to penetration testing end to end.

*5: Continuous Threat Exposure Management (CTEM) is a security management approach for continuously discovering, evaluating, validating, and improving, from an attacker’s perspective, the attack surface and risks (exposures) that exist in a company or organization.

*6: Active scanning is a method of investigating the state and vulnerabilities of devices by sending packets or commands directly from a diagnostic tool to systems and devices on a network and analyzing their responses.

*7: Passive scanning is passive monitoring of communications. It is a method in which forwarded packets are copied using a network equipment function called mirroring and monitored by an external monitoring device.

Related Links

WideAngle (OsecT) | NTT DOCOMO BUSINESS (Japanese)
MUSHIKAGO | Powder Keg Technologies

Contact Information for This Release

NTT DOCOMO BUSINESS, Inc.
Innovation Center, Technology Division
https://www.mkt.ntt.com/jp_news_261002_02_01_req.html

Powder Keg Technologies, Inc.
Executive Office, Headquarters
(TEL: +81-50-3631-8083, Email: business@powderkegtech.com)

< All Posts

Category

Archive