Data Centre OT Security & Managed OT SOC India | AiCyberWatch

Your uptime has a blind spot

You built for 2N. You certified for Tier III. You engineered every single point of failure out of the building. Except one — and it has authority over both your power paths at the same time.

AiCyberWatch runs a dedicated managed OT SOC for data centres: continuous monitoring of the control layer that your IT security programme cannot see and your Tier certification does not test.

30+
Years in security and IT operations
25+
Analysts in our dedicated SOC
< 15 min
Incident response commitment
51
Data centre OT detection use cases

The gap nobody owns

Everything in your facility is redundant.
So is your control layer — and that is the problem.

Every resilience decision in your data centre assumes one thing: that failures are independent, random and physical. A breaker trips. A pump fails. A UPS module drops out. You built a second path for exactly that reason, and it works.

An intruder with control authority is not an independent failure. He does not take out UPS A and leave UPS B running. He is inside the layer that commands both — and redundancy at that layer does not contain him, it carries him. A standby controller inherits a malicious logic download by design. A dual redundant ring delivers an unauthorised command on both halves, with zero loss.

What your redundant paths still share

Assume it is all working exactly as designed — hot-standby controller pairs, segregated A and B groups, PRP or HSR rings, a clustered supervisory layer. These remain shared:

  • One supervisory authority. A hot-standby pair is two servers running one application, one credential store, one project database.
  • One engineering environment. The same workstation, tooling and credentials that programmed Controller Group A programmed Group B.
  • One logic source. A program download replicates to the standby CPU by design — that is the feature working correctly.
  • Two networks, one trust model. BACnet, Modbus and GOOSE carry no authentication on either half of the ring.
  • One vendor access route established at commissioning, reaching both paths, and rarely governed since.
  • One configuration and credential store — factory defaults, shared accounts, and the backup set both sides would be restored from.

Redundancy makes your control layer replicated. It does not make it isolated.

The common-mode failure

Redundancy protects you from failure. Not from compromise.

Tier III certification guarantees concurrent maintainability — you can take any component or distribution path out of service without dropping IT load. Tier IV adds fault tolerance. Both are extraordinary engineering achievements, and both are defences against things breaking.

Neither was designed for an adversary who holds legitimate control authority over your building.

This is not a theoretical risk. It is a common-mode failure sitting inside a facility architecture that was specifically designed to eliminate common-mode failures — and it has never been assessed, because nobody has been looking at that layer.

Hot-standby controllers, PRP and HSR rings, clustered SCADA and headless autonomous control are excellent availability engineering. Not one of them is a security control. Every one of them was built to survive a component failing, not to contain a component being commanded incorrectly by something with legitimate authority.

An outage does not care whether the cause was a failed breaker or an unauthorised command.

Both redundant paths depend on one control layer A-path UPS A · Chiller A B-path UPS B · Chiller B Shared control layer BMS · EPMS · engineering workstation 2N becomes 1
Two independent paths. One point of control authority.

What we hear

"But we already have that covered"

The claimOur control network is air-gapped.
What we find

In critical facility work across India, we have not yet found a genuinely air-gapped data centre. There is a jump host, a vendor VPN, a DCIM integration, or remote-desktop software installed during commissioning that nobody removed.

The gap exists on the drawings, not on the network.

The claimOur IT SOC already covers it.
What we find

Your IT SOC ingests syslog. Your control estate speaks BACnet, Modbus, DNP3, Niagara Fox, IEC 61850, OPC UA and LonWorks. None of them produce syslog.

On a first assessment we typically find 3–5× more control-layer devices than the operator's own inventory records.

The claimOur BMS vendor handles security.
What we find

Your BMS vendor secures their product. Nobody secures the estate — and there are four to six other control vendors in your building.

Their maintenance contract covers availability of their system, not adversary activity within it. And their remote access is frequently the exposure itself.

Detection coverage

Fifty-one detections built for a data hall

Not a generic OT template with "data centre" on the cover. A detection catalogue built specifically for the electrical, mechanical, life-safety and physical security systems in a live facility.

Asset and access integrity

Every device on your control network, continuously inventoried. Every remote session governed and correlated against a change record. Unauthorised remote-access tools flagged the moment they appear.

Control command monitoring

Write commands from unauthorised sources. Setpoints pushed outside safe envelopes. Alarm thresholds modified. Controller mode changes and logic downloads — all at protocol level, all passively.

Redundancy integrity

A single host issuing commands to both your A-path and B-path. Simultaneous configuration changes across redundant units. A B-side unit silently sitting in bypass. No other managed service in this market monitors for this.

Physical–logical correlation

An engineering workstation login inside a secured plant room with no badge entry placing anyone in that room. A camera going dark within minutes of a control command. Your IT SOC and your facilities team cannot see this separately.

Life safety and environmental

Fire suppression or VESDA zones disabled outside a scheduled test. Cooling capacity falling below your N+1 threshold for current load. Leak detection and thermal anomalies correlated with control activity.

Compliance and configuration

Controller configuration drift from approved baselines. Zone and conduit policy violations against your IEC 62443 model. Evidence packs generated quarterly for CERT-In, CEA and audit.

How we work

D3E, applied to a live data hall

Our proprietary four-step framework, adapted to an environment where availability outranks everything else. Read more about D3E.

01. DISCOVER

A five-day Control Layer Exposure Assessment

Passive collection only — no agents on controllers, no active scanning, no disruption to live load. You receive a complete asset inventory, an unauthorised access path map, a ranked exposure register, and a redundancy collapse analysis specific to your building.

02. DESIGN

Architecture around your maintenance windows

Zone and conduit architecture to IEC 62443. Sensor and TAP placement. An OT DMZ with a hardware-enforced data diode, so telemetry flows to our SOC and nothing flows back.

03. DEFEND

24×7 monitoring, advisory response

Under 15 minutes to acknowledge a critical incident. Every automated response below Level 3 is advisory only — we detect, correlate and recommend; your facility authority decides and executes. An OT SOC that introduces operational risk has failed, however good its detection is.

04. EVOLVE

Quarterly tuning and evidence

Detection tuning against your site's actual behaviour. Compliance evidence packs as CEA and CERT-In requirements mature. New use cases released quarterly with a changelog, so you can see the service improving.

Service tiers

Three levels of cover

Watch

Establishing visibility

  • Business-hours monitoring
  • 22 detection use cases
  • Continuous asset inventory
  • Vulnerability tracking against ICS advisories
  • Monthly reporting and review
Recommended

Guard

The standard offering

  • Everything in Watch, plus:
  • 24×7×365 monitoring
  • 42 detection use cases
  • Under 15 minutes to acknowledge a P1
  • Incident response retainer, 24-hour on-site
  • Vendor remote access governance
  • Quarterly compliance evidence packs
  • Named service delivery manager

Fortress

Flagship facilities

  • Everything in Guard, plus:
  • All 51 detection use cases
  • 10-minute P1 acknowledgement, 4-hour on-site
  • Resident site security engineer
  • Controller configuration backup and tested restore
  • Annual OT tabletop and adversary simulation
  • SBOM and supply chain monitoring

Priced per site on IT load, monitored zones, and whether physical security systems are in scope. Multi-site framework pricing available from three sites.

How we start

Start with one site

A five-day Control Layer Exposure Assessment. Fixed price. Passive collection only. No commitment beyond it.

Complete asset inventory

Every device on your control network, identified by make, model, firmware and protocol. Most operators have never had this.

Unauthorised access path map

Every route into your control estate that is not documented — including the ones nobody remembers creating.

Ranked exposure register

Findings prioritised by proximity to IT load impact, mapped to IEC 62443 and CERT-In.

Redundancy collapse analysis

A diagram of exactly where your A-path and B-path share a compromise point. Specific to your building.

A 30-minute technical scoping call first. No pitch.

Why AiCyberWatch

We come from your world

Facility domain depth

Data centre design, TIA-942 audit and critical-facility certification experience. Not an IT security team learning what a CRAH unit is on your site.

Built for availability first

In a data hall, availability outranks confidentiality. Our playbooks are constrained accordingly, and we tell you so before we start.

India-operated, India-resident

Monitored from our SOC in India with in-country data residency, local incident reporting under CERT-In timelines, and engineers within reach of your site.

Multi-vendor by design

Nozomi Networks, OPSWAT, Honeywell, Seceon and Imperum. We are not reselling one platform — we operate several and choose per estate.

Technology partners

Powered by the world's best. Operated by us.

OPSWAT Seceon Imperum ARCON Fortinet CrowdStrike

Common questions

What data centre operators ask us first

Those are excellent availability controls, and they do exactly what they were designed to do. They are not security controls. A hot-standby CPU inherits a malicious logic download by design, because replicating logic to the standby is the feature working correctly. A PRP or HSR ring delivers an unauthorised write on LAN A and LAN B with zero loss. A/B controller segregation prevents faults propagating, but the same engineering environment and credentials programmed both groups. Headless autonomous control keeps the plant running when the supervisory server fails — and also means manipulated setpoints execute indefinitely with nobody watching. Redundancy makes your control layer replicated. It does not make it isolated.

No. Collection is passive — network TAPs or SPAN sessions, with no agents installed on controllers, relays or field devices, and no active scanning of the control network. Physical installation happens inside your approved maintenance windows under your change control.

No, and this is architectural rather than a policy promise. A hardware-enforced data diode sits between your estate and our SOC. Telemetry travels one way. There is no technical return path.

You don't need another SOC — you need coverage of an estate your current one cannot decode. IT SIEMs consume syslog; your control layer speaks industrial protocols that produce none. The two services are complementary, and we routinely work alongside an incumbent IT provider.

Nine to twelve weeks from contract to full service, across six phases. The two phases that typically extend are change approval and physical deployment, both governed by your maintenance windows rather than our schedule.

Yes. Guard and Fortress tiers include quarterly evidence packs mapped to IEC 62443, CERT-In directions and CEA cyber security requirements. Compliance becomes a by-product of the monitoring rather than a separate exercise.

That is extremely common and it does not prevent monitoring — in fact it raises the priority. Because collection is passive, we can monitor legacy supervisory systems that cannot accept modern security agents at all.

Yes. We govern and monitor vendor remote access rather than replacing vendor relationships. Most operators find this improves the vendor relationship, because access becomes documented and defensible.

Sites from around 5 MW IT load upward, where there is a supervisory BMS or EPMS layer. Below that, a lighter assessment-only engagement usually makes more sense.

Find out what's actually on your control network

A 30-minute conversation with a senior consultant who has worked inside data halls. No pitch, no pressure — just an honest view of where your control-layer exposure sits.

  • Passive collection only — zero risk to live load
  • Fixed price, one site, no ongoing commitment
  • Findings you can take straight to your board

Get in touch with us

Replace this block with the site's existing Contact Form 7 / recaptcha shortcode on implementation.

Get in Touch