Skip to main content
Use case · Defense Contractors

Industrial IoT Governance

Governance for AI agents acting on industrial and operational-technology systems.

The risk

What an ungoverned agent gets wrong here.

Industrial control systems, the operational technology (OT, the systems that run physical processes) behind power grids, water plants, pipelines, and factories, are increasingly driven by AI agents. Network security tools watch the wire, but none govern the controller's behavior: an unauthorized setpoint change, tampered controller firmware, a bypassed safety system, or a breach of the boundary between the corporate network and the plant floor. The attacks are documented. The Colonial Pipeline ransomware attack shut roughly 5,500 miles of pipeline for six days in May 2021. In February 2021 an intruder reached the Oldsmar water plant's controls and raised sodium hydroxide (lye) to 111 times its normal level before an operator reversed it. Stuxnet, discovered in 2010, destroyed roughly 1,000 uranium centrifuges by altering programmable logic controller (PLC) logic while replaying normal readings to operators. Triton/TRISIS, in 2017, targeted a petrochemical plant's safety system directly. Without governance there is no enforced limit on what an agent may change and no trustworthy record of who, or what, changed it.

Without governance

Where it goes wrong.

01

A setpoint changed by no one accountable

An agent or an intruder writes a new setpoint (a chemical dose, a pressure, a temperature) from an unauthorized source or outside a maintenance window, and the process moves toward an unsafe state while the control room sees nothing wrong.

02

Firmware and sensors that lie

A controller's firmware is modified to alter the physical process while it replays normal-looking sensor readings, so operators watch healthy dashboards as equipment is driven to failure.

03

The safety system switched off

A safety instrumented system (SIS, the independent layer that trips a process to a safe state) is bypassed or disabled outside an approved procedure, removing the last line of defense before a hazardous event.

04

A jump from the office network to the plant

Traffic crosses the boundary between the corporate IT network and the OT control network without authorization, letting a compromise on the business side reach systems that move physical equipment.

With Agentomy

How Agentomy governs it.

01

Discover every agent on the OT network

Inventory every agent and account with reach into controllers, historians, and safety systems. An unregistered agent falls back to read-only: it can observe the process but cannot change it.

02

Authorize every setpoint change

A setpoint change is validated against the operator workstations registered as authorized for that controller before it reaches the process. The allowlist is server-side: a list of authorized sources sent on the request is dropped and recorded, and a controller with no registered allowlist denies every setpoint source rather than accepting any. Process variable deviation is flagged against the controller's behavioral baseline.

03

Guard controller firmware

Every firmware attestation is compared against the sha256 baselines registered for that controller fleet. Both halves of that comparison used to arrive in the same request; now only the observed hash does, an approved hash sent beside it is dropped and recorded, and a fleet with no registered baseline fails the attestation instead of passing it. A controller that does not match is denied and quarantined, and a safety instrumented system pushed into bypass is caught against its behavioral baseline and attributed to whoever issued it.

04

Halt and prove it

One switch halts every governed controller in a fraction of a second, and a tamper-evident, hash-linked log captures every proposed and applied change: what changed, under whose authorization, and why.

What it detects

The detection patterns behind this workload.

Agentomy carries a dedicated ICS pattern family for Industrial IoT Governance. Each one is a specific failure this layer watches for, with the signal it watches, checked at runtime before the action reaches your systems.

10 of 166 governance patterns
  • Critical
  • High
  • ICS-001Severity: Critical

    Process variable deviation

    DetectionContinuous comparison of process variable readings against configured safe operating ranges.

  • ICS-002Severity: Critical

    Unauthorized setpoint change

    DetectionTrack all setpoint change commands with source attribution.

  • ICS-003Severity: Critical

    Controller firmware tampering

    DetectionMaintain cryptographic hashes of approved firmware images for every controller.

  • ICS-004Severity: Critical

    PLC command injection

    DetectionDeep packet inspection of industrial protocol traffic.

  • ICS-005Severity: Critical

    Safety system override

    DetectionMonitor all SIS status changes: bypass requests, force commands, maintenance mode transitions.

  • ICS-006Severity: Critical

    Network segmentation breach

    DetectionMonitor all traffic crossing Purdue model zone boundaries.

  • ICS-008Severity: Critical

    Sensor data manipulation

    DetectionStatistical analysis of sensor data streams.

  • ICS-009Severity: Critical

    Cascading shutdown propagation

    DetectionTrack shutdown events across interconnected process units.

  • ICS-010Severity: Critical

    Air gap violation

    DetectionMonitor for new network interfaces, USB device connections, wireless signal detection in control areas, and unexpected DNS or NTP traffic from isolated networks.

  • ICS-007Severity: High

    Unscheduled maintenance window

    DetectionIntegrate with change management system to track approved maintenance windows per asset.

ICS family, ICS-001 to ICS-010 · 10 of 166 governance patterns Agentomy enforces at runtime. Severity as classified in the pattern definition.

Frameworks

Maps to what you answer to.

Agentomy does not certify you. It gives you the enforcement and the audit trail these frameworks ask for, so readiness is something you can show rather than assert.

NERC CIPthe North American Electric Reliability Corporation's Critical Infrastructure Protection standards, mandatory cybersecurity for the bulk electric system; Agentomy supplies the access controls, change management, and monitoring evidence they requireIEC 62443the international standard series for the security of industrial automation and control systems; governance maps to its authorization, segmentation, and firmware-integrity requirementsNIST SP 800-82the US National Institute of Standards and Technology guide to operational-technology security, covering supervisory control and data acquisition (SCADA) and control components; capabilities map to its authentication and monitoring controlsNIS2the European Union's directive on the security of network and information systems for essential entities such as energy, water, and transport; the audit trail and incident record support its notification duties
See it in the record

Every action, logged and provable.

A tamper-evident, hash-linked trail of every governance decision for this workload: what an agent did, under whose authorization, and why. Plain-English reasons for every allow and deny, exportable to the framework your auditors care about.

Agentomy Command CenterFilter Industrial IoT Governance
  • 100% Integrity
  • 40,610 Blocks
  • SHA-256 hash-linked
Audit trail: one tamper-evident block per governance decision, hash-linked to the one before it
BlockTimestampAgentActionTierHash
40,610Today 12:42:08process-research-agentdata_access_requestEvaluator14a6890d658ceba1
40,609Today 12:41:54maintenance-triage-agentoutput_validationAnalyst7f3a072d02ccaf99
40,608Today 12:41:37supplier-review-agentpolicy_checkBuilderdff0127b956ec4f4
40,607Today 12:40:58yield-extract-agentbehavior_driftOperator3c3d40360a41645f
40,606Today 12:40:21safety-draft-agenthalt_initiatedStrategist48afc62ca9d13dd7
40,605Today 12:39:46shift-report-agentprompt_reviewEvaluator7d3d3528f672ea40
Governance events today: 12,842Demo environment
Illustrative interface with sample data, in the shipped Command Center’s structure. Not a customer environment and not a live feed.

Ready to govern your agents?