Skip to content
Apex
ApexProductsAether for cyber-physical security

Aether for cyber-physical security.

Security for the systems where a packet moves a turbine.

In OT and critical infrastructure, the question isn't whether a path is reachable — it's what it does to the physical world. Aether is the only security model that can answer it, because it couples a twin of your network with a twin of the physics and forward-rolls the intrusion to the turbine it trips or the feeder it destabilises. Twelve specialist agents — asset and protocol mapping, IT/OT boundary analysis, consequence simulation and ICS adversary emulation — under one model, capability-gated, safety-first, and built never to touch a live process.

Agents
12
Path
Intrusion → Physical consequence
Posture
Safety-first · read-only OT
Tiers
Asset → Boundary → Coupled sim → Engineer
Coverage

Network and physics, on one model.

IT security tools stop at the firewall to the plant; OT tools watch traffic but can't tell you what an attack does to the process. Aether for cyber-physical security is one model that holds both — the same weights that simulate the turbine reason about the packet that attacks it.

01

Cyber-physical digital twin

Aether couples a twin of your network with a twin of the physics — grid, process, mechanical or hydraulic — so an intrusion is forward-rolled all the way to its physical consequence. The capability only a simulation-native model has: it already speaks CFD, power-flow and structural dynamics.

02

OT / ICS asset & protocol mapping

PLCs, RTUs, historians, drives and safety controllers discovered and placed on the Purdue model — Modbus, DNP3, OPC-UA, EtherNet/IP and PROFINET parsed passively, never by probing a live process.

03

IT/OT boundary analysis

Segmentation, conduits and zones mapped to IEC 62443. Finds the path from a phished laptop in IT to a controller in OT, and the shortest set of conduits to cut it.

04

Consequence simulation

Not “is it exploitable” but “what does it do” — does this attack trip the turbine, overpressure the vessel, or destabilise the feeder? The physical safety envelope is computed, not assumed.

05

Firmware & embedded research

Static and sandboxed analysis of controller and device firmware, logic-tampering and unauthorised-ladder detection — run against an image, never a live PLC.

06

Process-anomaly intelligence

Tells a cyber intrusion apart from a mechanical fault by reasoning over process telemetry against the physics twin — the false alarm a pure-IT tool can't resolve.

07

Safety-system integrity

Reasons about whether an attack can defeat or mask the safety-instrumented system (SIS) — the layer that must hold even when control is compromised — and flags any path that does.

08

OT incident response

Investigation that respects the constraint you can't pull the plug on a running plant. Provenance-tracked, with containment options ranked by physical safety, not just by network impact.

09

ICS adversary emulation

ATT&CK-for-ICS scenarios played out against the coupled twin — measuring detection, response and physical resilience in simulation, where a failed control costs nothing.

10

Sensor & actuator integrity

False-data-injection and replay analysis: can a spoofed sensor drive the controller into an unsafe action while the HMI still looks green? Detected against the twin.

11

Physical-access coupling

Badge, door, camera and perimeter systems modelled alongside the network — so a tailgating or cloned-credential path that reaches an OT cabinet is reasoned about, not siloed in a separate system.

12

Safety-first guardrail layer

The agent never actuates a live process. Every capability is gated and the refusal corpus is red-team-verified; an action that could endanger a physical system is refused, and every privileged step is logged to an audit-grade trace.

The integrity contract

Every finding knows its physical consequence.

The governing principle: reachability is never presented as danger, and a simulated consequence is never presented as a live one. The four-tier ladder makes that structural — and an action that could endanger a physical system is refused, not gated.

T1

Asset & signature

Passive asset inventory, protocol fingerprinting and known-vulnerability lookup against the OT estate. Never an active scan of a live controller — discovery is read-only by construction.

T2

Boundary & dataflow

IT/OT path analysis, segmentation and privilege reasoning across the Purdue zones. The tier most assessments live in — finds the route without touching the process.

T3

Coupled cyber-physical simulation

Network and physics twins run together: the attack is executed against a sandboxed copy and its physical consequence is forward-rolled. Confirms whether a path is not just reachable but dangerous.

T4

Engineer & operator escalation

Safety-critical conclusions are human-in-the-loop. A consequence the model cannot establish with confidence returns “needs a controls engineer”, never a guess about a system that can hurt people.

Sectors

Six critical sectors, one coupled twin.

Not six monitoring appliances — one model whose physics changes per sector but whose contract does not.

Energy & grid

Substations, feeders, generation and DER. Couples power-flow with the network twin so a relay-misconfiguration or load-altering attack is traced to the feeder it destabilises.

Water & wastewater

Treatment, pumping and dosing. Models the hydraulics and chemistry so a setpoint-tampering attack is evaluated for its actual public-safety consequence, not just its CVSS.

Manufacturing & process

Discrete and continuous process control. Reasons over the mechanical and thermal envelope so logic-tampering that trips a line or overpressures a vessel is caught in sim.

Transportation & rail

Signalling, interlocking and fleet control. Safety-interlock integrity analysis where the physical consequence of a defeated control is measured against the dynamics.

Buildings & physical access

BMS, access control, cameras and perimeter. The literal-physical layer — modelled alongside the network so a door-to-cabinet path is one analysis, not two.

Robotics & autonomous fleets

Embodied systems on the floor and in the field. Couples to the robotics world model so a compromised policy or spoofed sensor is reasoned about with real dynamics.

Platform

Safety-first by construction.

In OT, a careless test is a safety incident. The guardrails are the product as much as the analysis is — we report what the model does, and as deliberately, what it refuses.

Cyber-physical
consequence, not just reachability

Network twin coupled to a physics twin

Read-only OT
safe by construction

Discovery is passive; the agent never actuates a live process

4-tier
evidence ladder per finding

Asset → boundary → coupled-sim → engineer

62443
standards-aligned assessment

Mapped to IEC 62443 zones and conduits

Refusal
red-team-verified per release

Safety-endangering actions refused, not gated

Audit-grade
trace + chain-of-custody

Every privileged step logged

Stack it replaces

One model for IT and OT.

Two SIEMs, a monitoring appliance, a consultant's spreadsheet and a HIL bench collapse into one agent, one contract, one audited trace.

Passive OT-monitoring appliances
Separate IT and OT SIEMs
Bespoke ICS asset-inventory tools
Spreadsheet IEC 62443 assessments
Tabletop-only consequence analysis
Disconnected process-historian analytics
Manual firmware-review workflows
One-off breach-and-attack-sim rigs
Vendor-locked OT threat feeds
Siloed physical-access logs
Standalone safety-case documents
Hand-built HIL test benches
Why the cycle shortens

Consequence analysis, compressed.

What compounds is knowing which attacks actually endanger the process, not how fast any single query runs.

Stage
Today
With Aether
Why
Assess a new ICS advisory's real impact
weeks of tabletop
hours
The advisory is mapped to your actual controllers and conduits, then its physical consequence is forward-rolled in the coupled twin — ranked by what it does to the process, not by raw severity.
IT/OT path discovery
a consultant engagement
interactive
Boundary and privilege analysis traces the route from IT to a controller and returns the shortest conduit cut — without an active scan that risks the process.
OT incident triage
is it cyber or mechanical?
resolved
Process-anomaly reasoning against the physics twin separates an intrusion from a failing bearing — the question a pure-IT SOC cannot answer.
62443 evidence
weeks of paperwork
minutes
Zone-and-conduit mapping and assessment evidence assembled with provenance an auditor can follow.
Specialist agents
12

From the coupled twin to the safety-first refusal layer — each emitting results under one integrity contract, with every privileged action logged.

Cyber + physics twin
Coupled

Forward-roll an intrusion to the turbine it trips — the engineering and security disciplines on one model, which no IT-only product can offer.

By construction
Safety-first

Discovery is passive, the agent never actuates a live process, and safety-endangering actions are refused — not policy promises that can be prompted around.

AI scientists, not chatbots

An AI controls-security analyst, not an appliance.

It reads the plant and the network, picks methods, confirms the consequence in simulation, writes the safety case, and refuses to touch the process — for an expert audience.

  • 01

    Reads the plant and the network

    Builds a coupled model of the OT assets, the IT/OT boundary and the physics they control — passively, before any analysis runs.

  • 02

    Picks the right tier

    Knows when a passive asset match is enough, when to trace the IT/OT path, and when a consequence has to be confirmed in the coupled twin — by the evidence the conclusion needs.

  • 03

    Confirms the consequence in simulation

    An attack is executed against a sandboxed copy and forward-rolled to its physical effect — exploitability and danger demonstrated, with the live process never touched to prove it.

  • 04

    Separates cyber from mechanical

    Reasons over process telemetry against the physics twin to tell an intrusion apart from a fault — and flags out-of-distribution signals for a controls engineer rather than scoring them blindly.

  • 05

    Writes the fix and the safety case

    Each finding ships with the shortest conduit cut or hardening step, the physical blast radius it closes, the residual risk, and an evidence trail — with the model-version hash.

  • 06

    Refuses to touch the process

    Actuation of a live system, weaponisation and any safety-endangering action are outside the capability envelope and refused — the analysis that protects a plant cannot be turned against it.

Where this leads

Critical-infrastructure defense that improves with every assessment.

Each resolved finding returns into the coupled twin and the threat model, so the model that protected one plant gets better at protecting the next — and the safety-first refusal corpus is re-verified against the red-team set on every release.

In production · Cascade Grid Operator

“It showed us which intrusion would actually drop the feeder — and which were noise. Our alerts finally rank by physics.”

— OT Security Lead, Cascade Grid Operator

Read the Cascade Grid Operator case study →

Forward-roll an attack to its physical consequence.

Aether couples a twin of your network with a twin of the physics, finds the paths that actually endanger the process, and ships the fix — passively, safety-first, and audited end to end. Request access to deploy it behind your firewall, or see how it couples to the rest of the platform.

Cyber-physical security sits on the same foundation as the rest of Aether — one model, every discipline.