Industrial OT & ICS Cybersecurity

    Spharaka Signal™

    Built for Critical Infrastructure.

    Industrial environments cannot afford downtime. Traditional IT security tools were never designed for operational technology, where visibility is limited, proprietary protocols dominate, and even a single disruptive scan can impact production.

    Spharaka Signal™ extends the power of Spharaka Sphere™ into Operational Technology, delivering passive asset discovery, protocol-aware threat detection, industrial network visibility, and continuous compliance monitoring, without interfering with industrial operations.

    Complete OT Visibility. Deep Industrial Intelligence. Zero Operational Disruption.

    Passive-First Architecture

    Purpose-Built for Industrial Security

    Unlike traditional IT security platforms that rely on active scanning, Spharaka Signal™ adopts a passive-first architecture engineered specifically for industrial control environments.

    Every network packet is analysed, enriched, and correlated to build a complete understanding of industrial assets, communications, operational behaviour, vulnerabilities, and threats, without modifying device state or interrupting production.

    Built for environments where uptime is non-negotiable.

    FIELD LAYEREDGE COLLECTIONINGESTENRICHMENTSTORAGESURFACEPLCs / Safety PLCsS7, ControlLogix, TriconRTUs / DrivesDNP3, IEC-104, ACS880HMIs / EWS / SCADAWonderware, TIA PortalField InstrumentsHART, Rosemount, E+HIEDs / SubstationIEC 61850, SEL, MMSSwitches / FirewallsCisco, ASA, syslog/NetFlowVision / IT-OT EdgeCognex, Historian, JumphostSPHARAKA Edge SensorPassive tap / SPAN / ERSRANDPI - 150+ decodersIDS - Suricata + customPassive Asset FingerprintNetFlow / SessionsSyslog / WEL / SNMPDNS / TLS / AnomalyOptional Active OT PollLocal hybrid bufferPCAP retain, LZ4 compressTLS / mTLSLZ4 + protobufOT Signal IngestTCP :5145, mTLSEnrollment gatecert + sensor-idHybrid Buffer1M memory + disk spillWriter workers5k batch / 5s flushInline Semantic TagW2.SEM.E - at write timeEnrichmentRegister-map cache25M lookups/sec/coreProcess contexttag / unit / rangeVulnerability matchfingerprint → CPE → CVEThreat intel matchIOC: IP/domain/hashAsset / session enrich5-step background loopSecurity narrative“Why this matters”Unified Storagespharakaot.event_logs364 fields · all event types8 dm + domain MVsauto-compute on INSERTassets_livedevice-of-record tableenriched_* / corr_*analysis output tablesContentDBCVE · IOC · MITRE · refsPostgreSQL (otprotect)users · sensors · CMDB · casesSOC UIDashboardInventoryAlertsWorkbenchExposureSensorsReportsREST APIJWT + RBACAnalysis Modules - read from unified store, write back to enriched_/corr_/alertsAsset IntelNetwork IntelThreat DetectionVulnerabilityRisk ScoringExposure MgmtIntegrityAccess MonitorProcess SemanticsComplianceReports / SOARAQL Search · WebSocketEdge collectionIngest / TransportStorageAsset / Network IntelThreat DetectionVulnerabilityRisk ScoringIntegrityAccessProcess SemanticsExposureCompliance
    Spharaka Signal™ passive-first OT architecture: the field layer, edge collection over a passive tap, ingest, enrichment against CVE and threat intelligence, unified storage, and the analysis modules that read from it. Nothing in this path writes to a control device. Scroll the diagram sideways on a narrow screen.

    Why Industrial Networks Need a Different Approach

    Operational Technology environments present challenges that conventional cybersecurity platforms cannot address.

    Limited Visibility

    Thousands of PLCs, RTUs, HMIs, historians, engineering workstations and IIoT devices often remain undocumented.

    Protocol Diversity

    Industrial networks use hundreds of specialised protocols that traditional security tools cannot interpret.

    Zero Tolerance for Downtime

    Production systems cannot tolerate intrusive scans, unnecessary traffic or endpoint agents.

    Critical Infrastructure Threats

    Modern attacks specifically target industrial protocols, safety systems and control networks.

    Compliance Requirements

    Industrial organisations must continuously demonstrate compliance with frameworks such as IEC 62443, NERC CIP and NIST CSF.

    Spharaka Signal™ addresses each of these challenges using industrial-native cybersecurity.

    Asset Intelligence

    Complete Industrial Asset Visibility

    Know every device connected to your industrial network. Spharaka Signal™ continuously discovers, identifies and inventories industrial assets using passive network analysis and protocol intelligence.

    Without sending a single packet into production systems, Signal™ automatically identifies:
    PLCs
    RTUs
    DCS Controllers
    HMIs
    Historians
    SCADA Servers
    Protection Relays
    Industrial Switches
    IIoT Devices
    Engineering Workstations
    Every discovered asset is enriched with detailed contextual information including:
    Vendor
    Model
    Firmware Version
    Serial Number
    Purdue Level
    Criticality
    Communication Relationships
    Network Zone
    Operational Role
    Asset Risk

    A continuously updated industrial asset inventory becomes the foundation for threat detection, vulnerability management and compliance.

    What Spharaka Signal™ discovers on an industrial network without sending a packet: the device classes it identifies, and the vendor, firmware, Purdue level and risk it attaches to each one.
    Deep Packet Inspection

    DPI for Industrial Protocols

    Industrial cybersecurity demands more than protocol identification. Signal™ performs protocol-aware Deep Packet Inspection capable of understanding the operational semantics of industrial communications.

    Every packet is processed through a multi-stage enrichment pipeline, providing complete network, process and security context for every event.

    Function Codes
    Register Values
    Process Variables
    Device Commands
    Operational States
    Engineering Values
    Session Context
    Device Identity
    370+ Protocols

    Industry-Leading Protocol Coverage

    Signal™ supports more than 370 industrial and enterprise protocols across multiple operational domains, giving organisations visibility into mixed-vendor environments from a single platform.

    SCADAPLC NetworksDCS SystemsPower Grid ProtocolsBuilding AutomationManufacturingOil & GasWater UtilitiesMiningMaritimeIIoTEnterprise IT
    Vulnerability Management

    Passive Vulnerability Management

    Understand your industrial attack surface without introducing operational risk. Signal™ continuously identifies vulnerable devices through passive fingerprinting and protocol intelligence.

    Firmware Identification
    CVE Correlation
    CPE Mapping
    Device Risk Scoring
    Attack Surface Analysis
    Crown Jewel Identification
    Patch Tracking
    Exposure Analysis

    No active vulnerability scans.

    No production disruption.

    Only continuous visibility into industrial cyber risk.

    Threat Detection

    Industrial Intrusion Detection System

    Signal™ combines multiple detection methodologies to identify both known and unknown industrial threats.

    Signature Detection

    Detect known attacks using industrial protocol signatures and deep protocol inspection.

    Protocol-Aware Detection

    Understand misuse of industrial protocols, unauthorised commands and unsafe operational behaviour.

    Behavioural Anomaly Detection

    Automatically learn normal industrial communications and detect deviations that indicate compromise.

    Signal™ identifies threats including:

    Unauthorised PLC ProgrammingController ManipulationSafety System AttacksProtocol AbuseLateral MovementConfiguration ChangesSuspicious Engineering Workstation ActivityIndustrial Malware

    Alerts are enriched with industrial context, dramatically reducing investigation time.

    Network Visibility

    Segmentation Monitoring

    Gain complete visibility across industrial communications. Signal™ continuously analyses:

    Device-to-Device CommunicationsZone-to-Zone TrafficNetwork TopologyCross-Zone ViolationsCommunication BaselinesTraffic PatternsBandwidth Utilisation

    Industrial segmentation policies are continuously validated against operational behaviour, helping organisations enforce secure Purdue Model architectures.

    Threat Intelligence

    Threat Intelligence Built for ICS

    Modern industrial attacks require industrial intelligence. Signal™ correlates detections with:

    MITRE ATT&CK® for ICSThreat Intelligence FeedsIndicators of Compromise (IOCs)Known Industrial Threat GroupsCISA Known Exploited Vulnerabilities (KEV)Multi-stage Attack Chains

    Security teams gain immediate context on attacker techniques, affected assets and operational impact.

    Compliance

    Continuous Compliance Monitoring

    Compliance should be continuous, not an annual exercise. Signal™ continuously measures industrial security posture against major operational security frameworks.

    Generate audit-ready evidence, executive dashboards and compliance reports from a single platform.

    IEC 62443
    NERC CIP
    NIST Cybersecurity Framework
    AWWA
    Collection

    What each edge sensor runs

    Sensors observe mirrored traffic from a SPAN port, a network tap or ERSPAN. They are never in the traffic path and never transmit to a control device, which is what allows an evaluation to run against live production without a change window. Each collection module operates independently.

    Deep packet inspection

    Industrial and IT protocols decoded at the application layer, so a command is visible as a command rather than as a session.

    Industrial intrusion detection

    Suricata-derived rules tuned for ICS protocols, evaluated at line rate inside the sensor.

    Passive asset fingerprinting

    Devices identified from stack behaviour, TLS fingerprints, vendor prefixes, protocol banners and identity objects exposed in normal operation.

    Session and flow accounting

    Every conversation recorded, which is what makes observed topology possible.

    Host and infrastructure telemetry

    Syslog, Windows Event Log and SNMP from firewalls, switches, HMIs and engineering workstations.

    DNS and TLS observation

    Encrypted and name-resolution metadata, increasingly load-bearing as cleartext protocols are replaced.

    Optional active OT polling

    Opt-in, explicitly scoped, and never pointed at a safety controller.

    Process Semantics

    From register numbers to process meaning

    Most tooling stops at decoding. It can report that Modbus function code 06 wrote to register 40001, which tells a control engineer nothing useful. The questions that matter are which tag that register is, what engineering unit it carries, what its safe range is, whether it is safety-relevant, and which zone is permitted to write it.

    Signal™ resolves every register through a five-tier ladder and records which tier matched, so semantic coverage is auditable rather than assumed. Resolution happens as the event is written rather than in a later batch, so safety relevance is queryable from the moment traffic is seen.

    00

    Customer override

    Tags your integrator named differently from the vendor manual.

    01

    Exact model match

    The register map published for that specific device model.

    02

    Vendor fallback

    A vendor-wide map where the exact model is not catalogued.

    03

    Generic protocol

    Protocol-level meaning where no device map applies.

    04

    Explicit miss

    Recorded as a miss so coverage is auditable and the gap can be filled.

    This is what makes a detection like alert when a write to a safety-relevant register comes from any zone other than the engineering workstation a single expression. No signature rule can state it, because a signature engine does not know what register 40001 means on that specific controller.

    Detection

    Three engines, one alert pane

    No single technique covers industrial threat detection. Signatures catch known protocol abuse and miss an attack made entirely of valid operations. Behavioural models catch the unfamiliar but struggle to explain themselves. Signal™ runs all three over one event store and renders their output identically, because the analyst does not care which engine fired.

    Signature detection

    Runs inside the sensor at line rate against known industrial protocol abuse, with no dependence on the central platform being reachable.

    Query-language rules

    Multi-event, multi-asset logic written against resolved process meaning rather than raw bytes, which is what allows a detection to reference safety relevance directly.

    Behavioural models

    First-seen activity, statistical deviation, rate and change, and topology-aware zone-boundary crossing, each scored against the asset's own history.

    Every alert, whichever engine raised it, opens with the same context: the contributing events, the asset, the resolved process meaning and the risk impact. Detections are mapped onto MITRE ATT&CK for ICS rather than the enterprise matrix, so coverage is measured against industrial adversary behaviour.

    Integrity

    Detecting change you did not authorise

    The consequential incidents involve a change to the controller rather than traffic towards it. Four artefacts are tracked continuously.

    Program logic

    Compared by hash against a captured baseline.

    Configuration

    Drift measured against an approved snapshot.

    Firmware

    Tracked against both the vendor release and your approved build.

    Controller mode

    RUN, PROGRAM, STOP and FAULT transitions, correlated against declared maintenance windows.

    A controller moving from RUN to PROGRAM outside a maintenance window warrants an alert by itself. A program hash that diverges after that transition warrants a critical one. Signal™ captures both and links them, so the sequence reads as one event rather than two unrelated ones.

    Exposure

    Four questions, one storyline

    Exposure score

    One number per organisation and per zone, with its trend.

    Attack surface

    What is genuinely reachable, from the internet, from IT into OT, and from OT into IT.

    Blast radius

    If one device is compromised, what follows through the conduits actually observed.

    Attack paths

    Ranked multi-hop routes from an initial foothold towards a control system.

    Each panel links into the next, and every asset carries a risk score from zero to one hundred with its five-factor breakdown visible. Compensating controls subtract from that score, so a device behind strong segmentation is rated on its defended posture rather than on raw severity, which is what makes an estate of unpatchable equipment assessable at all.

    Deployment

    Built for Industrial Deployment

    Industrial environments require deployment flexibility. Signal™ supports:

    On-Premises Deployment
    Air-Gapped Environments
    Hybrid Deployments
    Multi-Site Industrial Networks
    MSSP & Multi-Tenant Deployments

    Distributed edge sensors collect and analyse industrial traffic locally while securely forwarding enriched metadata to the central Signal™ Console, minimising bandwidth while preserving analytical depth.

    Industries

    Industries We Protect

    Spharaka Signal™ is engineered for organisations operating critical infrastructure.

    Manufacturing
    Energy & Utilities
    Oil & Gas
    Water & Wastewater
    Mining
    Power Generation
    Smart Cities
    Pharmaceuticals
    Transportation
    Maritime
    Chemicals
    Food & Beverage
    Automotive
    Healthcare
    Industrial Campuses
    Public Infrastructure

    Part of the Spharaka Sphere™ Platform

    Spharaka Signal™ is fully integrated into Spharaka Sphere™, enabling OT and IT security teams to operate from a unified autonomous cyber defence platform.

    By combining industrial visibility with AI-native threat correlation, autonomous investigation and enterprise-wide security operations, organisations eliminate silos between IT and OT while improving operational resilience.

    Key Highlights

    CapabilityCoverage
    Industrial Protocol Support370+ Protocols
    DPI Protocol Decoders276+
    Industries Supported16+
    Industrial Event Schema364+ Security Fields
    Passive Asset Discovery
    Deep Packet Inspection
    Industrial IDS
    Vulnerability Management
    MITRE ATT&CK for ICS
    Compliance Reporting
    Air-Gapped Deployment
    Multi-Site Architecture

    Secure the Systems That Keep the World Running

    Protect industrial operations with complete OT visibility, protocol-aware threat detection and continuous operational resilience.

    Discover how Spharaka Signal™ brings autonomous cyber defence to industrial environments.

    Learn More

    OT cybersecurity in depth

    Signal™ is the product. These pages cover the subject it addresses, from the control layer up to the standards an industrial programme is measured against.

    Questions

    Frequently asked questions

    What is Spharaka Signal?

    Signal extends Sphere into Operational Technology. It provides passive asset discovery, protocol-aware threat detection and continuous compliance for industrial and critical infrastructure environments.

    Will Signal disrupt our production systems?

    No. Production systems cannot tolerate intrusive scans, unnecessary traffic or endpoint agents, so Signal discovers and monitors assets passively rather than probing them.

    Which industrial assets can Signal discover?

    Signal builds an inventory of PLCs, RTUs, HMIs, historians, engineering workstations and IIoT devices, the population that typically remains undocumented in industrial estates.

    How does Signal detect threats in industrial protocols?

    It combines three methods: industrial protocol signatures with deep protocol inspection for known attacks, analysis of protocol misuse and unauthorised commands, and behavioural baselining that learns normal industrial communications and flags deviations.

    Which compliance frameworks does Signal support?

    Signal supports continuous demonstration of compliance with frameworks including IEC 62443, NERC CIP and NIST CSF.

    Why not use our IT security tools on the OT network?

    Industrial networks use hundreds of specialised protocols that traditional security tools cannot interpret, so IT tooling produces both blind spots and false positives on legitimate industrial traffic.