Industries - Energy & Utilities
Substations, control centres and corporate networks, defended as one estate.
Utilities run some of the most consequential and most heavily regulated networks in the country, across geography that no analyst can walk. Spharaka Signal™ monitors substation and control traffic passively, without a packet sent to a protection relay, while Spharaka Sphere™ correlates it with corporate IT, identity and cloud telemetry into a single autonomous investigation.
Cybersecurity Landscape
A utility's estate spans generation plants, transmission substations, distribution automation, wide-area telemetry links and the corporate network that plans and bills for all of it. The equipment that matters most is frequently the equipment that can least tolerate interference: a protection relay exists to trip a breaker in milliseconds, and a security tool that probes it has become the incident it was meant to prevent.
Regulation compounds the problem rather than solving it. NERC CIP, IEC 62443 and, for water operators, AWWA G430 all expect continuous, demonstrable control effectiveness across an estate most operators cannot fully enumerate. Evidence gathered by hand once a quarter satisfies neither the auditor's question nor the operational one.
Intelligent electronic devices, RTUs and protection relays accumulate across decades of build-out, with no inventory that survives contact with the field.
DNP3, IEC 60870-5-104 and IEC 61850 MMS and GOOSE all change grid state, and most carry those commands without proving who sent them.
Remote substations and pumping stations are monitored over links that are themselves part of the attack surface.
Long-lived field devices frequently have no supported patch path and no tolerance for active scanning.
An intrusion that starts in email or a vendor VPN reaches engineering workstations, and from there the control network.
NERC CIP, IEC 62443 and AWWA G430 expect demonstrable control effectiveness rather than an annual snapshot.
Autonomous Cyber Defence
Spharaka Sphere™ gives a utility one investigation surface rather than two security programmes that meet at a quarterly review. Corporate telemetry from endpoints, identity, email and cloud arrives alongside substation and control network telemetry from Spharaka Signal™, and the platform reasons across both.
That matters because the attacks worth worrying about cross the boundary. An intrusion that begins with a phished credential and ends at an engineering workstation is one investigation, and it can only be seen as one if the evidence from both sides sits in the same place. Sphere assembles it autonomously, in a cycle measured in seconds rather than the hours a cross-team escalation takes.
Corporate and control network evidence reasoned about together, so a cross-domain intrusion reads as one incident rather than two unconnected alerts.
AuraXP™ forms competing hypotheses and queries the telemetry needed to test them, producing a verdict, evidence trail and attack timeline without analyst pivoting.
Control room staff, field engineers and vendor accounts profiled continuously, so privileged misuse and off-hours engineering access surface without manual triage.
Reachability from the corporate estate toward control assets modelled from observed traffic, so the route is closed before it is used.
Low-risk containment executes automatically; anything that could touch an operational system holds for approval under AirWatch™ policy.
Control evidence assembled continuously against NERC CIP, IEC 62443 and AWWA G430 rather than reconstructed before an audit.
The AI Cybersecurity Analyst
SAGE™ is Spharaka's cybersecurity model, trained for security reasoning rather than adapted to it. Inside Sphere it explains multi-signal detections in plain language, which matters in an environment where the person who understands the process and the person who understands the intrusion are rarely the same person.
An analyst can ask what a sequence of substation events amounts to and receive a reasoned answer with the evidence attached. A control engineer can read the same narrative without a log query. A regulator can be handed the timeline that produced a decision, not a summary of it.
For utilities operating under data residency or restricted connectivity requirements, SAGE™ runs locally in the on-premises deployment, so no investigation data leaves the environment to be reasoned about.
Natural language investigations
Guided AI-assisted analysis
Root cause reconstruction
Contextual threat intelligence
Accelerated analyst productivity
Executive-friendly explanations
Industry Use Cases
Passive visibility into IEC 61850 MMS and GOOSE, DNP3 and IEC 60870-5-104 traffic without a packet sent to a protection relay.
Observed communication patterns between control centre and field, with deviation flagged against learned normal rather than a static rule.
Configuration and firmware compared continuously against approved baselines, with change outside a maintenance window escalated.
Third-party engineering sessions reconstructed and monitored, including first-time geography and out-of-hours access.
Cross-domain attack paths from corporate systems into engineering workstations and control networks detected as one chain.
The same passive approach applied to pumping, treatment and distribution control, with AWWA G430 evidence assembled continuously.
Asset inventory completeness, configuration baselines, patch posture and access audit mapped to CIP-002 through CIP-014.
Enterprise-side containment executed at machine speed before encryption reaches the systems that schedule and dispatch.
OT / ICS Security
Spharaka Signal™ is the passive-first industrial platform behind the OT half of this picture. Edge sensors collect at line rate from tap and span points and never inject traffic into a protection or safety device, which is the only posture a transmission operator will accept in a live substation.
Signal decodes utility protocols at the application layer, so what is recorded is the command rather than the connection, and resolves each register to the tag, engineering unit and safety relevance it actually represents.
Line-rate collection from tap and span points, with no traffic injected into relays or controllers.
IEC 61850 MMS and GOOSE, DNP3 and IEC 60870-5-104 read at the application layer rather than counted as sessions.
IEDs, RTUs, engineering workstations and field devices fingerprinted passively into a device-of-record.
Program logic, configuration, firmware and controller mode watched against captured baselines.
Device fingerprints matched to the CVE catalogue with no scan and no agent, prioritised by KEV and exploitability rather than CVSS alone.
Observed traffic compared against the segmentation the architecture claims, so drift is visible.
First-seen protocols, function codes and peer pairs flagged against learned baselines per device and zone.
If a device is compromised, the downstream impact through observed conduits is modelled rather than guessed.
Continuous control evidence against NERC CIP, IEC 62443-3-3, NIST SP 800-82r3 and AWWA G430.
Integration Layer
Signal feeds OT telemetry continuously into Sphere, so substation context is not stranded in a separate console that only the OT team opens. It becomes part of the enterprise investigation surface: reasoned about by SAGE™, correlated by AuraXP™, and present in every investigation where it is relevant.
Why Spharaka
Nothing is sent to a protection relay or safety device, which is what makes deployment possible in a live substation.
Signal and Sphere together remove the seam that cross-domain attacks are designed to hide in.
Continuous control evidence against NERC CIP, IEC 62443 and AWWA G430, drawn from operational data rather than assembled for the audit.
Vulnerability prioritisation weighs exploitability and compensating controls, because much of this estate cannot be patched on any normal cycle.
On-premises and air-gapped deployment with local model inference, for operators under data residency or isolation requirements.
A typical autonomous investigation cycle runs in 60 to 120 seconds against 60 to 90 minutes of manual triage.
Deployment
Spharaka Sphere™ is engineered for the operational realities of modern enterprises. Whether your infrastructure is fully in the cloud, on-premises, air-gapped for regulatory reasons, or spread across hybrid environments, Sphere deploys where your data lives and where your security teams operate.
Elastic, multi-region cloud deployment for born-in-cloud enterprises.
Full control within your data centre for strict data residency needs.
Isolated environments for regulated, classified, or critical operations.
Unified visibility across cloud, on-prem, and edge in one platform.
Yes. Signal collects passively from tap and span points and never injects traffic into a protection relay or controller. Optional active OT polling exists, but it is opt-in, explicitly scoped and never pointed at a safety device.
IEC 61850 MMS and GOOSE, DNP3 and IEC 60870-5-104 for substation and telemetry traffic, alongside Modbus, OPC UA and the discrete control protocols found in generation and water treatment plants.
Control evidence is assembled continuously from data the platform already collects: asset inventory completeness, configuration baseline conformance, patch posture, access audit and segmentation. Each control carries a score, a status and a drill-through to the underlying evidence, mapped across CIP-002 to CIP-014.
The device fingerprint is derived passively from observed traffic and matched against the vulnerability catalogue, so a relay is assessed without receiving a packet. Prioritisation weighs CVSS, exploit prediction and the CISA known-exploited catalogue together, and records compensating controls where patching is not an option.
Yes. The same passive approach applies to pumping, treatment and distribution control networks, and continuous control evidence is reported against AWWA G430 alongside IEC 62443 and NIST SP 800-82r3.
Yes. Sphere On-Premises runs ingestion, detection, investigation and response inside the customer controlled network with local SAGE™ inference, and threat content arrives through controlled offline packages.
Corporate and control telemetry sit on one investigation surface, so a chain that begins with a phished credential and ends at an engineering workstation is investigated as a single incident rather than as separate alerts in two consoles.
AirWatch™ validates every action against verified evidence and customer policy before execution. Low-risk enterprise-side containment can run automatically; anything that could touch an operational system holds for analyst, manager or customer approval.
Book a personalized demonstration of Spharaka Sphere™ and see how AI-native security operations transform detection, investigation, and response for your organization.