Your uptime has a blind spot
You built for 2N. You certified for Tier III. You engineered every single point of failure out of the building. Except one — and it has authority over both your power paths at the same time.
AiCyberWatch runs a dedicated managed OT SOC for data centres: continuous monitoring of the control layer that your IT security programme cannot see and your Tier certification does not test.
The gap nobody owns
Everything in your facility is redundant.
So is your control layer — and that is the problem.
Every resilience decision in your data centre assumes one thing: that failures are independent, random and physical. A breaker trips. A pump fails. A UPS module drops out. You built a second path for exactly that reason, and it works.
An intruder with control authority is not an independent failure. He does not take out UPS A and leave UPS B running. He is inside the layer that commands both — and redundancy at that layer does not contain him, it carries him. A standby controller inherits a malicious logic download by design. A dual redundant ring delivers an unauthorised command on both halves, with zero loss.
What your redundant paths still share
Assume it is all working exactly as designed — hot-standby controller pairs, segregated A and B groups, PRP or HSR rings, a clustered supervisory layer. These remain shared:
- One supervisory authority. A hot-standby pair is two servers running one application, one credential store, one project database.
- One engineering environment. The same workstation, tooling and credentials that programmed Controller Group A programmed Group B.
- One logic source. A program download replicates to the standby CPU by design — that is the feature working correctly.
- Two networks, one trust model. BACnet, Modbus and GOOSE carry no authentication on either half of the ring.
- One vendor access route established at commissioning, reaching both paths, and rarely governed since.
- One configuration and credential store — factory defaults, shared accounts, and the backup set both sides would be restored from.
Redundancy makes your control layer replicated. It does not make it isolated.
The common-mode failure
Redundancy protects you from failure. Not from compromise.
Tier III certification guarantees concurrent maintainability — you can take any component or distribution path out of service without dropping IT load. Tier IV adds fault tolerance. Both are extraordinary engineering achievements, and both are defences against things breaking.
Neither was designed for an adversary who holds legitimate control authority over your building.
This is not a theoretical risk. It is a common-mode failure sitting inside a facility architecture that was specifically designed to eliminate common-mode failures — and it has never been assessed, because nobody has been looking at that layer.
Hot-standby controllers, PRP and HSR rings, clustered SCADA and headless autonomous control are excellent availability engineering. Not one of them is a security control. Every one of them was built to survive a component failing, not to contain a component being commanded incorrectly by something with legitimate authority.
An outage does not care whether the cause was a failed breaker or an unauthorised command.
What we hear
"But we already have that covered"
Our control network is air-gapped.
In critical facility work across India, we have not yet found a genuinely air-gapped data centre. There is a jump host, a vendor VPN, a DCIM integration, or remote-desktop software installed during commissioning that nobody removed.
The gap exists on the drawings, not on the network.
Our IT SOC already covers it.
Your IT SOC ingests syslog. Your control estate speaks BACnet, Modbus, DNP3, Niagara Fox, IEC 61850, OPC UA and LonWorks. None of them produce syslog.
On a first assessment we typically find 3–5× more control-layer devices than the operator's own inventory records.
Our BMS vendor handles security.
Your BMS vendor secures their product. Nobody secures the estate — and there are four to six other control vendors in your building.
Their maintenance contract covers availability of their system, not adversary activity within it. And their remote access is frequently the exposure itself.
Detection coverage
Fifty-one detections built for a data hall
Not a generic OT template with "data centre" on the cover. A detection catalogue built specifically for the electrical, mechanical, life-safety and physical security systems in a live facility.
Asset and access integrity
Every device on your control network, continuously inventoried. Every remote session governed and correlated against a change record. Unauthorised remote-access tools flagged the moment they appear.
Control command monitoring
Write commands from unauthorised sources. Setpoints pushed outside safe envelopes. Alarm thresholds modified. Controller mode changes and logic downloads — all at protocol level, all passively.
Redundancy integrity
A single host issuing commands to both your A-path and B-path. Simultaneous configuration changes across redundant units. A B-side unit silently sitting in bypass. No other managed service in this market monitors for this.
Physical–logical correlation
An engineering workstation login inside a secured plant room with no badge entry placing anyone in that room. A camera going dark within minutes of a control command. Your IT SOC and your facilities team cannot see this separately.
Life safety and environmental
Fire suppression or VESDA zones disabled outside a scheduled test. Cooling capacity falling below your N+1 threshold for current load. Leak detection and thermal anomalies correlated with control activity.
Compliance and configuration
Controller configuration drift from approved baselines. Zone and conduit policy violations against your IEC 62443 model. Evidence packs generated quarterly for CERT-In, CEA and audit.
How we work
D3E, applied to a live data hall
Our proprietary four-step framework, adapted to an environment where availability outranks everything else. Read more about D3E.
A five-day Control Layer Exposure Assessment
Passive collection only — no agents on controllers, no active scanning, no disruption to live load. You receive a complete asset inventory, an unauthorised access path map, a ranked exposure register, and a redundancy collapse analysis specific to your building.
Architecture around your maintenance windows
Zone and conduit architecture to IEC 62443. Sensor and TAP placement. An OT DMZ with a hardware-enforced data diode, so telemetry flows to our SOC and nothing flows back.
24×7 monitoring, advisory response
Under 15 minutes to acknowledge a critical incident. Every automated response below Level 3 is advisory only — we detect, correlate and recommend; your facility authority decides and executes. An OT SOC that introduces operational risk has failed, however good its detection is.
Quarterly tuning and evidence
Detection tuning against your site's actual behaviour. Compliance evidence packs as CEA and CERT-In requirements mature. New use cases released quarterly with a changelog, so you can see the service improving.
Service tiers
Three levels of cover
Watch
Establishing visibility
- Business-hours monitoring
- 22 detection use cases
- Continuous asset inventory
- Vulnerability tracking against ICS advisories
- Monthly reporting and review
Guard
The standard offering
- Everything in Watch, plus:
- 24×7×365 monitoring
- 42 detection use cases
- Under 15 minutes to acknowledge a P1
- Incident response retainer, 24-hour on-site
- Vendor remote access governance
- Quarterly compliance evidence packs
- Named service delivery manager
Fortress
Flagship facilities
- Everything in Guard, plus:
- All 51 detection use cases
- 10-minute P1 acknowledgement, 4-hour on-site
- Resident site security engineer
- Controller configuration backup and tested restore
- Annual OT tabletop and adversary simulation
- SBOM and supply chain monitoring
Priced per site on IT load, monitored zones, and whether physical security systems are in scope. Multi-site framework pricing available from three sites.
How we start
Start with one site
A five-day Control Layer Exposure Assessment. Fixed price. Passive collection only. No commitment beyond it.
Complete asset inventory
Every device on your control network, identified by make, model, firmware and protocol. Most operators have never had this.
Unauthorised access path map
Every route into your control estate that is not documented — including the ones nobody remembers creating.
Ranked exposure register
Findings prioritised by proximity to IT load impact, mapped to IEC 62443 and CERT-In.
Redundancy collapse analysis
A diagram of exactly where your A-path and B-path share a compromise point. Specific to your building.
A 30-minute technical scoping call first. No pitch.
Why AiCyberWatch
We come from your world
Facility domain depth
Data centre design, TIA-942 audit and critical-facility certification experience. Not an IT security team learning what a CRAH unit is on your site.
Built for availability first
In a data hall, availability outranks confidentiality. Our playbooks are constrained accordingly, and we tell you so before we start.
India-operated, India-resident
Monitored from our SOC in India with in-country data residency, local incident reporting under CERT-In timelines, and engineers within reach of your site.
Multi-vendor by design
Nozomi Networks, OPSWAT, Honeywell, Seceon and Imperum. We are not reselling one platform — we operate several and choose per estate.
Technology partners
Powered by the world's best. Operated by us.
Common questions
What data centre operators ask us first
Those are excellent availability controls, and they do exactly what they were designed to do. They are not security controls. A hot-standby CPU inherits a malicious logic download by design, because replicating logic to the standby is the feature working correctly. A PRP or HSR ring delivers an unauthorised write on LAN A and LAN B with zero loss. A/B controller segregation prevents faults propagating, but the same engineering environment and credentials programmed both groups. Headless autonomous control keeps the plant running when the supervisory server fails — and also means manipulated setpoints execute indefinitely with nobody watching. Redundancy makes your control layer replicated. It does not make it isolated.
No. Collection is passive — network TAPs or SPAN sessions, with no agents installed on controllers, relays or field devices, and no active scanning of the control network. Physical installation happens inside your approved maintenance windows under your change control.
No, and this is architectural rather than a policy promise. A hardware-enforced data diode sits between your estate and our SOC. Telemetry travels one way. There is no technical return path.
You don't need another SOC — you need coverage of an estate your current one cannot decode. IT SIEMs consume syslog; your control layer speaks industrial protocols that produce none. The two services are complementary, and we routinely work alongside an incumbent IT provider.
Nine to twelve weeks from contract to full service, across six phases. The two phases that typically extend are change approval and physical deployment, both governed by your maintenance windows rather than our schedule.
Yes. Guard and Fortress tiers include quarterly evidence packs mapped to IEC 62443, CERT-In directions and CEA cyber security requirements. Compliance becomes a by-product of the monitoring rather than a separate exercise.
That is extremely common and it does not prevent monitoring — in fact it raises the priority. Because collection is passive, we can monitor legacy supervisory systems that cannot accept modern security agents at all.
Yes. We govern and monitor vendor remote access rather than replacing vendor relationships. Most operators find this improves the vendor relationship, because access becomes documented and defensible.
Sites from around 5 MW IT load upward, where there is a supervisory BMS or EPMS layer. Below that, a lighter assessment-only engagement usually makes more sense.
Find out what's actually on your control network
A 30-minute conversation with a senior consultant who has worked inside data halls. No pitch, no pressure — just an honest view of where your control-layer exposure sits.
- Passive collection only — zero risk to live load
- Fixed price, one site, no ongoing commitment
- Findings you can take straight to your board
Get in touch with us
Replace this block with the site's existing Contact Form 7 / recaptcha shortcode on implementation.
ESMA – Maturity Assessment