Aether for cyber-physical security.
Security for the systems where a packet moves a turbine.
In OT and critical infrastructure, the question isn't whether a path is reachable — it's what it does to the physical world. Aether is the only security model that can answer it, because it couples a twin of your network with a twin of the physics and forward-rolls the intrusion to the turbine it trips or the feeder it destabilises. Twelve specialist agents — asset and protocol mapping, IT/OT boundary analysis, consequence simulation and ICS adversary emulation — under one model, capability-gated, safety-first, and built never to touch a live process.
- Agents
- 12
- Path
- Intrusion → Physical consequence
- Posture
- Safety-first · read-only OT
- Tiers
- Asset → Boundary → Coupled sim → Engineer
Network and physics, on one model.
IT security tools stop at the firewall to the plant; OT tools watch traffic but can't tell you what an attack does to the process. Aether for cyber-physical security is one model that holds both — the same weights that simulate the turbine reason about the packet that attacks it.
Cyber-physical digital twin
Aether couples a twin of your network with a twin of the physics — grid, process, mechanical or hydraulic — so an intrusion is forward-rolled all the way to its physical consequence. The capability only a simulation-native model has: it already speaks CFD, power-flow and structural dynamics.
OT / ICS asset & protocol mapping
PLCs, RTUs, historians, drives and safety controllers discovered and placed on the Purdue model — Modbus, DNP3, OPC-UA, EtherNet/IP and PROFINET parsed passively, never by probing a live process.
IT/OT boundary analysis
Segmentation, conduits and zones mapped to IEC 62443. Finds the path from a phished laptop in IT to a controller in OT, and the shortest set of conduits to cut it.
Consequence simulation
Not “is it exploitable” but “what does it do” — does this attack trip the turbine, overpressure the vessel, or destabilise the feeder? The physical safety envelope is computed, not assumed.
Firmware & embedded research
Static and sandboxed analysis of controller and device firmware, logic-tampering and unauthorised-ladder detection — run against an image, never a live PLC.
Process-anomaly intelligence
Tells a cyber intrusion apart from a mechanical fault by reasoning over process telemetry against the physics twin — the false alarm a pure-IT tool can't resolve.
Safety-system integrity
Reasons about whether an attack can defeat or mask the safety-instrumented system (SIS) — the layer that must hold even when control is compromised — and flags any path that does.
OT incident response
Investigation that respects the constraint you can't pull the plug on a running plant. Provenance-tracked, with containment options ranked by physical safety, not just by network impact.
ICS adversary emulation
ATT&CK-for-ICS scenarios played out against the coupled twin — measuring detection, response and physical resilience in simulation, where a failed control costs nothing.
Sensor & actuator integrity
False-data-injection and replay analysis: can a spoofed sensor drive the controller into an unsafe action while the HMI still looks green? Detected against the twin.
Physical-access coupling
Badge, door, camera and perimeter systems modelled alongside the network — so a tailgating or cloned-credential path that reaches an OT cabinet is reasoned about, not siloed in a separate system.
Safety-first guardrail layer
The agent never actuates a live process. Every capability is gated and the refusal corpus is red-team-verified; an action that could endanger a physical system is refused, and every privileged step is logged to an audit-grade trace.
Every finding knows its physical consequence.
The governing principle: reachability is never presented as danger, and a simulated consequence is never presented as a live one. The four-tier ladder makes that structural — and an action that could endanger a physical system is refused, not gated.
Asset & signature
Passive asset inventory, protocol fingerprinting and known-vulnerability lookup against the OT estate. Never an active scan of a live controller — discovery is read-only by construction.
Boundary & dataflow
IT/OT path analysis, segmentation and privilege reasoning across the Purdue zones. The tier most assessments live in — finds the route without touching the process.
Coupled cyber-physical simulation
Network and physics twins run together: the attack is executed against a sandboxed copy and its physical consequence is forward-rolled. Confirms whether a path is not just reachable but dangerous.
Engineer & operator escalation
Safety-critical conclusions are human-in-the-loop. A consequence the model cannot establish with confidence returns “needs a controls engineer”, never a guess about a system that can hurt people.
Six critical sectors, one coupled twin.
Not six monitoring appliances — one model whose physics changes per sector but whose contract does not.
Substations, feeders, generation and DER. Couples power-flow with the network twin so a relay-misconfiguration or load-altering attack is traced to the feeder it destabilises.
Treatment, pumping and dosing. Models the hydraulics and chemistry so a setpoint-tampering attack is evaluated for its actual public-safety consequence, not just its CVSS.
Discrete and continuous process control. Reasons over the mechanical and thermal envelope so logic-tampering that trips a line or overpressures a vessel is caught in sim.
Signalling, interlocking and fleet control. Safety-interlock integrity analysis where the physical consequence of a defeated control is measured against the dynamics.
BMS, access control, cameras and perimeter. The literal-physical layer — modelled alongside the network so a door-to-cabinet path is one analysis, not two.
Embodied systems on the floor and in the field. Couples to the robotics world model so a compromised policy or spoofed sensor is reasoned about with real dynamics.
Safety-first by construction.
In OT, a careless test is a safety incident. The guardrails are the product as much as the analysis is — we report what the model does, and as deliberately, what it refuses.
Network twin coupled to a physics twin
Discovery is passive; the agent never actuates a live process
Asset → boundary → coupled-sim → engineer
Mapped to IEC 62443 zones and conduits
Safety-endangering actions refused, not gated
Every privileged step logged
One model for IT and OT.
Two SIEMs, a monitoring appliance, a consultant's spreadsheet and a HIL bench collapse into one agent, one contract, one audited trace.
Consequence analysis, compressed.
What compounds is knowing which attacks actually endanger the process, not how fast any single query runs.
From the coupled twin to the safety-first refusal layer — each emitting results under one integrity contract, with every privileged action logged.
Forward-roll an intrusion to the turbine it trips — the engineering and security disciplines on one model, which no IT-only product can offer.
Discovery is passive, the agent never actuates a live process, and safety-endangering actions are refused — not policy promises that can be prompted around.
An AI controls-security analyst, not an appliance.
It reads the plant and the network, picks methods, confirms the consequence in simulation, writes the safety case, and refuses to touch the process — for an expert audience.
- 01
Reads the plant and the network
Builds a coupled model of the OT assets, the IT/OT boundary and the physics they control — passively, before any analysis runs.
- 02
Picks the right tier
Knows when a passive asset match is enough, when to trace the IT/OT path, and when a consequence has to be confirmed in the coupled twin — by the evidence the conclusion needs.
- 03
Confirms the consequence in simulation
An attack is executed against a sandboxed copy and forward-rolled to its physical effect — exploitability and danger demonstrated, with the live process never touched to prove it.
- 04
Separates cyber from mechanical
Reasons over process telemetry against the physics twin to tell an intrusion apart from a fault — and flags out-of-distribution signals for a controls engineer rather than scoring them blindly.
- 05
Writes the fix and the safety case
Each finding ships with the shortest conduit cut or hardening step, the physical blast radius it closes, the residual risk, and an evidence trail — with the model-version hash.
- 06
Refuses to touch the process
Actuation of a live system, weaponisation and any safety-endangering action are outside the capability envelope and refused — the analysis that protects a plant cannot be turned against it.
Critical-infrastructure defense that improves with every assessment.
Each resolved finding returns into the coupled twin and the threat model, so the model that protected one plant gets better at protecting the next — and the safety-first refusal corpus is re-verified against the red-team set on every release.
“It showed us which intrusion would actually drop the feeder — and which were noise. Our alerts finally rank by physics.”
Forward-roll an attack to its physical consequence.
Aether couples a twin of your network with a twin of the physics, finds the paths that actually endanger the process, and ships the fix — passively, safety-first, and audited end to end. Request access to deploy it behind your firewall, or see how it couples to the rest of the platform.
Cyber-physical security sits on the same foundation as the rest of Aether — one model, every discipline.