That question was the reason Sphynx was invited by SEV, the Hellenic Federation of Enterprises, to take part in its workshop “Cybersecurity in the Age of AI”. The event brought together important voices in cybersecurity, including Microsoft, Mind The Hack, Hack The Box, and MetaMind Innovations, to unpack ways that this technology is simultaneously the industry’s biggest opportunity and one of its newest sources of risk.
Our contribution centered on Sphynx Device Intelligence, and the problem it exists to solve: most organizations cannot fully see what is actually connected to their own networks.
Our Commercial Director, Michalis Oikonomakis, took the stage to present Sphynx Device Intelligence in more detail. Critical environments today do not run on IT infrastructure alone. Hospitals, factories, and utilities increasingly depend on OT, IoT, and field devices that sit outside the standard boundaries of IT systems, and traditional security tools were never built with these devices in mind. The scale of the problem is significant:
- 21 billion IoT devices are estimated to be online worldwide today
- 50–70% of them are considered vulnerable
- Attacks targeting IoT devices are estimated to occur at a rate of roughly 800,000 per day
Regulation is beginning to catch up with this reality. Both NIS2 and the Cyber Resilience Act (CRA) now include provisions requiring organizations to account for IoT and OT assets, not just conventional IT infrastructure. For many organizations, that alone represents a significant compliance gap.
That gap predates AI, but AI is making it more urgent on two fronts at once. It gives attackers faster, more automated ways to discover and exploit exposed devices at scale, and it gives defenders, for the first time, a realistic way to close that visibility gap without adding agents, integrations, or operational overhead to already-stretched security teams. Device Intelligence is built around that second half of the equation: agentless, AI-powered discovery that brings every IT, OT, IoT, and mobile device into view, and turns that visibility into prioritized, actionable risk data rather than another disconnected inventory.
Following the presentation, our CTO, Michalis Smyrlis, led a live demonstration of Device Intelligence in action.
Device Intelligence delivers:
- Automatic discovery and visibility across all IoT and OT devices, spanning 800+ vendors and covering millions of device types
- Device-level risk scoring
- A complete, mapped vulnerability inventory
- End-of-life data and firmware update status
- Actionable remediation guidance
That visibility doesn’t sit in isolation. It feeds directly into the broader Sphynx SPA Suite, which correlates device-level findings with premium cyber threat intelligence, connecting vulnerabilities to real exploitation models and active campaigns for far more accurate risk prioritization. The result is a 360-degree view of cyber risk across IT assets, OT devices, IoT devices, and mobile endpoints, feeding into SOC services, incident monitoring, automated response, and awareness training.
The Takeaway
What stood out most from the day AI is changing the tools available to both defenders and attackers, and it’s changing them quickly. What it hasn’t changed is the need for a comprehensive security strategy across your entire environment, including the devices most organizations have never fully mapped.
Our thanks to SEV for convening the discussion and to our fellow speakers for a day of genuinely useful exchange.
If your organization is still working out where IoT and OT fit into your risk picture, we’re happy to talk through where the gaps typically hide.