GridCORTEX Live · Cyber & OT Security  ·  ← All Demos
On this page What you are watching The business case Run this at your utility Where you see it and how you say yes

The Dwell Time Synthetic Data · Simulation

Intrusions into OT networks don't announce themselves; they settle in and wait, and the industry's ugly secret is that dwell time is measured in months. Seventy-two hours at Cedar Ridge Utility's security desk: passive behavioral monitoring that has spent 30 days learning what every SCADA conversation normally looks like notices an engineering workstation quietly polling 14 field RTUs it has no business talking to, at 2 AM, through a vendor remote-access path. Watch the difference between compliance and defense: flag in hours, contain without touching operations, run the CIP-008 clock properly, and close the attack path the threat model had already ranked #3. The grid never notices. That's the whole point.

HOUR 0
PASSIVE BASELINE, 30 DAYS LEARNED
⏳ DECISION POINT: TIME SLOWED
SYNTHETIC DATA
Baseline traffic Anomalous flow Confirmed unauthorized Isolated / contained Monitoring sensor

Dwell time: 4 hours. Operational impact: none.

What OT security looks like when the network's behavior is the signature
,
Dwell time
,
Operational impact
,
Response cost
The Incident
WithoutWith GridCORTEXΔ
The Program
WithoutWith GridCORTEXΔ
Illustrative simulation on synthetic data; Cedar Ridge Utility is fictional; no real utility, incident, threat actor, or vendor is depicted, and no attack technique is described. The scenario is a defensive tabletop composite. All monitoring shown is passive and read-only on the OT network; every response action is decided by the utility's security and operations leadership. See UC 13.2.
2,340
OT devices monitored (passive)
0
Open anomalies
,
Dwell clock
NONE
Operational impact
Security Desk Feed, passive OT monitoring · CISO and operations decide
Baseline
First anomaly
Contain
CIP-008
Close the path
All clear
The Validated Use Cases Behind This Scenario
UC 13.2
OT Network Anomaly Detection
The behavioral baseline that noticed: passive, read-only monitoring that knows what every device's normal conversation looks like, and flags what signature tools can't.
UC 13.3
Cyber Incident Response Copilot
The CIP-008 workflow run properly under pressure: classification, notification clocks, evidence package, ops briefings, drafted by the copilot, decided by the CISO.
UC 13.1
OT Cybersecurity Threat Modeling
The vendor remote-access path was already ranked #3 on the modeled attack-path list; this incident turns the ranking into a closed gap.
187 UCs
One Framework
The Dwell Time is one of 187 validated use cases across 10 solution areas and 23 utility domains.
Inside the Demo
What you are watching, and what it proves

The scenario is 72 hours at the security desk of Cedar Ridge Utility, a fictional power company. The stakes: intruders who get into the networks that run physical grid equipment, called operational technology or OT networks, typically go undetected for months. The industry calls that period dwell time. Cedar Ridge watches its OT network with passive listening only: sensors that read traffic but can never send anything. Over 30 days, the system has learned what normal looks like for 2,340 devices: who talks to whom, when, how often, and with what kinds of commands. At hour 2, at 02:10 on the wall clock, an engineering workstation called ENG-WS-07 starts polling 14 remote terminal units, the small field computers that report readings from substations and power lines. No alarm matches a known attack. The system flags it anyway, for one simple reason: in 30 days of history, this workstation has never talked to field equipment at all, and never at 2 AM.

Four decisions go to the chief information security officer. At hour 4.2, the first asks permission to watch harder, at 91 percent confidence: record the full sessions, pull the vendor's remote-access logs, and map how critical the 14 devices are. Watch first, act second. The watching pays off: the polling is slow, systematic, and shaped like someone drawing a map of the grid's control network, and the vendor's own calendar shows no maintenance scheduled. At hour 5.8, the second decision proposes containment at 97 percent confidence, computed so it costs grid operations nothing: cut the one workstation off at the network switch, suspend the vendor's remote entrance, and change the affected passwords and keys, while every link the control room depends on stays untouched and the forensic evidence is preserved first. Approved, the intruder is locked out at hour 6.2. Total dwell time: 4.2 hours from first odd traffic to containment, against an industry norm measured in months.

The back half is about the program, not the packets. Forensic review confirms the intruder only looked: no control commands sent, no settings changed. At hour 12, the third decision runs the required federal incident paperwork under rule CIP-008, which sets a reporting clock for grid cyber incidents: a classification worksheet, a draft notification to the industry's threat-sharing center, a sealed evidence chain, and a plain-language briefing for the operations team, all signed by the security chief with hours to spare by hour 16. At hour 24 comes the uncomfortable detail: the utility's own threat model had ranked this exact entry route, the vendor remote-access path, third out of ten likely attack paths last quarter. It was flagged, but never funded. At hour 30, the fourth decision closes it for good: require a second proof of identity on every vendor login, force all vendor access through one controlled gateway computer, add a standing alert for any workstation talking to field devices, and add the scenario to the next practice exercise. The simulation ends after 48 quiet hours: zero operational impact, one page for the board. The grid never noticed. That is the point.

Without GridCORTEX

The same intrusion arrives through an authorized vendor doorway, so the firewall logs look healthy and every tool that matches known attack patterns stays silent; there is nothing known to match. The 2 AM polling becomes a patient, unobserved mapping of the network that controls grid switches. Following the industry pattern, the access persists for months, about 118 days on the outcome chart, and discovery finally comes from an audit or a tip from the vendor, never from the network itself. By then the response is an emergency: grid control links yanked offline with real operational disruption, outside response consultants at retainer rates, regulators asking how months went unnoticed, and a bill of $2.3 million or more. The failure is structural: pattern-matching tools catch what has been seen before, and long dwell times live in what has not.

With GridCORTEX

The core capability is behavioral anomaly detection (use case 13.2): the system learns each device's normal conversations, so one workstation's brand-new 2 AM habit stands out from a thousand routine alerts, and correlation stitches three minor oddities into one incident at 97 percent confidence. Containment is computed against the live state of the grid, so the response costs operations nothing: one workstation and a set of credentials, and the control room never blinks. An incident-response copilot runs the federal CIP-008 reporting clock correctly (use case 13.3), and the threat model turns the incident into a permanently closed attack path (use case 13.1). Every step keeps a human in charge: the monitoring only listens, and the security chief and operations leadership approve all four actions. The numbers: 4.2 hours of dwell, zero operational impact, $140,000 total response cost.

The scorecard, side by side
MeasureWithout GridCORTEXWith GridCORTEXDelta
Dwell timehow long an intruder roams inside before being found and locked outmonths: discovered by accident4.2 hours, by the network itselfthe entire difference
Detectionwhat finally raised the alarmsignatures silent: nothing known matchedbehavioral: "this is not normal"knowing normal beats matching known attacks
Containmentwhat had to be shut off to lock the intruder outemergency OT isolation, ops paysworkstation + credentials onlygrid operations never felt it
Scopewhat the intruder actually did, and how soon the utility knew for sureunknown for weeksreads only: confirmed by forensicscertainty, fast
CIP-008the federal rule setting the deadline and paperwork for reporting grid cyber incidentsreconstructed under scrutinyclock met, evidence sealedclean file
The 14 RTUsthe small field computers the workstation was probing; they report readings from substations and linesmapped by someone elseback to boringas it should be
Response costeverything the incident cost, including outside responders and disruption$2.3M+: IR retainer, downtime, scrutiny$140K all-in94 percent cheaper
Operational impactwhether the response disturbed the systems that actually run the gridforced OT link isolation, hourszerothe control desks never knew
Regulatory posturehow the utility looks to its regulator after the incidentexplaining months of dwellself-detected, self-reportedthe good side of the table
Attack path #3the vendor remote-access route the utility's own threat model ranked third most likely; MFA means a second proof of identity at login, and a jump host is one controlled gateway all vendors must pass throughstill open (flagged, unfunded)closed: MFA, jump-host, rulethe model earned its keep
Vendor accesshow outside vendors reach utility systems remotelyunchanged until the audithardened fleet-wideevery account, not just one
Board storywhat leadership has to be told when it is overa very long meetingone boring pagepriceless
The live numbers on the dashboard
OT devices monitored (passive)The 2,340 grid-side devices whose normal behavior the system has learned by listening only. Full coverage is what makes "this is not normal" a provable statement; gaps are where intruders hide.
Open anomaliesHow many unexplained behavior changes are live right now. Zero is a quiet network; it rises to 1 when the workstation starts probing field devices, and returns to 0 at containment.
Dwell clockHours since the first suspicious traffic, counting up in red until containment stops it at 4.2. The lower it stops, the better; the industry norm is months.
Operational impactWhat the response cost the actual grid. NONE for the whole run is the goal, and it holds because containment was computed to leave every control-room link untouched.

The Business Case: Safety, Hours, and Cost

A utility does not buy a demo. It buys a safety exposure that goes away and a cost that goes down. Below is that case for every use case behind The Dwell Time, written the way a plant manager, a safety lead, and a CFO each need to read it. Every hour and every dollar is a formula you run with your own rates and volumes. There are no vendor benchmarks in here and no invented percentages. If a number is not yours, it is not a number.
UC 13.1 OT Cybersecurity Threat Modeling

What happens today, without this

OT threat modeling happens as a workshop, usually once a year or when a major system goes in. The security architect books a room, pulls control engineers and vendors off their work for a day or two, draws the environment on a whiteboard, and someone redraws it in a diagramming tool afterward. The risk register that comes out is a spreadsheet scored by consensus in the room. Between workshops the model is frozen while firewall rules, vendor remote access accounts, and jump hosts change every week, so by the time the mitigation list is funded, it describes an environment that no longer exists.

What it replaces or shrinks

  • The annual whiteboard threat modeling workshop and the days of engineer and vendor calendar time it consumes
  • Manual redrawing of OT network diagrams from firewall rule exports and asset inventory
  • The spreadsheet risk register scored by consensus rather than by path analysis
  • Manual cross walk between CIP control gaps and whether those gaps are actually reachable by an adversary
  • Shrinks the outside assessment engagement from discovery work to validation of a model you already hold

Why it is safer

The safety effect is indirect, and the mechanism is worth stating rather than dressing up. Closing an attack path in a planned change window avoids the alternative, which is an incident where technicians are dispatched at odd hours to isolate or verify devices under time pressure. Rushed field work in an energized environment is where people get hurt, and this use case is trying to keep that work planned.

Counted in units you already track:

  • Switching operations performed reactively to isolate a segment during a security event, versus the same work done in a planned window
  • Energized area entries by technicians dispatched to manually verify or isolate control devices during an incident
  • Night driving hours generated by security callouts to substations and control houses
  • Permits to work raised under emergency conditions rather than through normal change control

Man-hours it gives back

Workshop and diagram maintenance hours come back to the control engineers and the security architect, and the architect's remaining time shifts from drawing the environment to deciding what to do about it.

HOURS AVOIDED PER YEAR = workshops per year x participants per workshop x hours per workshop, plus diagram and inventory maintenance hours per quarter x 4, plus outside assessment days per year x hours per day, minus the architect hours still spent validating each modeled path and the engineer hours still spent confirming that a proposed mitigation is safe to make in an operating environment.

The numbers we need from you to run that formula:

  • Number of OT environments you model per year and how many people attend each workshop
  • Hours per workshop per participant, including preparation
  • Hours spent per quarter keeping network diagrams and OT asset inventory current
  • Outside assessment days purchased per year and the day rate
  • Loaded hourly rates for a security architect, a control engineer, and a SCADA or EMS administrator

Where the dollars come from

Cost driverHow it is calculated, from a rate you supply
Security and engineering laborworkshop and diagram maintenance hours avoided x your loaded architect and control engineer rates
Outside assessment spendassessment days you shift from discovery to validation x your contracted day rate, counted only where you actually reduce the scope you buy
Mitigation prioritizationthe cost of controls you defer or drop because the model shows they close no reachable path, valued at your own project cost estimates. This can be larger than the labor line and it is entirely your number.
Incident avoidanceyour own estimated cost of an OT security incident x the share of incidents you believe path closure prevents. You set that share. We will not.

Reliability and maintenance

Reliability
This does not move SAIDI or SAIFI on its own. What it does is rank attack paths by whether they reach systems that operate the grid, so the paths that could turn a cyber event into a customer outage get fixed first rather than the paths that are simply easiest to document. If you want a reliability framing, the honest one is that it prioritizes protection of your EMS and ADMS ahead of protection of your paperwork.
Maintenance
Security remediation moves out of the emergency lane and into normal change control, because the model shows the path before an adversary does. It also keeps the OT asset and connectivity picture current as a by product, which is the same picture your maintenance and outage planning teams keep rebuilding by hand.

What else it moves

ComplianceYou can show an auditor, and a board, which CIP control gaps are actually exploitable and which are documentation issues, which is a far better conversation than a flat list of findings.
Insurance and riskCyber underwriters and reinsurers ask for evidence of a maintained threat model, not a one time assessment, and this produces that evidence as a side effect.
WorkforceOT security architects are scarce and expensive. This spends their time on judgment about mitigations rather than on redrawing diagrams from firewall exports.

What it costs you, stated honestly

You pay for the scoped engagement that builds and runs this, for read only integration into your asset inventory, firewall and network configurations, and remote access records, and for your own architects' and control engineers' time to validate the first model. The validation is not optional and it is the dominant cost in year one, because a threat model your engineers do not believe is a document nobody acts on.

How to build the payback case

Payback is usually carried by outside assessment spend and by the engineer and architect hours that workshops consume, both of which are on invoices and timesheets you already have. The deferred mitigation spend is often larger but it is a judgment call, so build the case on the first two.

This is a planning model driven by your environment counts, your workshop effort, and your own rates, not a vendor claim. Re-run it after the first modeled environment is validated by your engineers, and use their correction rate as the honest input.
UC 13.2 OT Network Anomaly Detection

What happens today, without this

Control network traffic is either not monitored at all or monitored by a signature based intrusion detection tool written for enterprise networks, which alerts on known malware and stays quiet about a legitimate looking command from an unexpected source. What passes for behavioral baselining lives in the heads of two or three control engineers. A security operations analyst who sees something odd on a substation link picks up the phone and asks a control engineer whether that command was expected, and the answer can take a day to come back. Firewall and historian log reviews happen quarterly, by hand, per site, and nobody pretends they are complete.

What it replaces or shrinks

  • Quarterly manual review of firewall and historian logs, site by site, looking for unusual command activity
  • Phone calls and emails to control engineers asking whether a given command, session, or write was expected
  • Hand built spreadsheets describing normal device to device communication for each substation
  • After the fact forensic reconstruction of what a device was doing in the hours before an event
  • Shrinks signature only alert triage, most of which today resolves to known good traffic
  • Shrinks the manual verification truck roll sent to confirm what a field device is actually doing

Why it is safer

The direct safety effect is modest and specific rather than dramatic. Detecting unauthorized or abnormal command activity from the network removes the reason for the alternative, which is dispatching technicians to substations, often at night, to verify device state by hand. Every one of those verification trips is a drive and an energized area entry that existed only because nobody could see the traffic.

Counted in units you already track:

  • Energized area entries by technicians sent to verify RTU, relay, or gateway state under suspicion of abnormal behavior
  • Night driving hours on off hours dispatches to substations for device verification
  • Road miles driven for site by site device checks across a service territory
  • Switching operations performed to isolate a suspect segment before its behavior is understood

Man-hours it gives back

Log review hours come back to the security operations team and the interruption hours come back to the control engineers who currently act as the human baseline.

HOURS AVOIDED PER YEAR = sites x quarterly log review hours per site x 4, plus OT alerts per month x triage minutes per alert x 12, plus engineer verification requests per month x hours per request x 12, minus the analyst minutes still spent confirming each flagged anomaly and the engineer minutes still spent on the ones that get escalated.

The numbers we need from you to run that formula:

  • Number of monitored sites and the hours currently spent per site per quarter on log review
  • Monthly OT alert volume from existing tooling and the average triage minutes per alert
  • Verification requests sent to control engineers per month and hours spent per request
  • Field verification trips per year driven by suspected abnormal device behavior, and your loaded cost per truck roll
  • Loaded hourly rates for a security operations analyst and a control or SCADA engineer

Where the dollars come from

Cost driverHow it is calculated, from a rate you supply
Security operations laborlog review and triage hours avoided x your loaded analyst rate, including any shift differential you pay
Control engineer interruptionverification hours avoided x your loaded control engineer rate
Field verificationverification truck rolls avoided x your fully loaded truck roll cost, including overtime and callout premium where the trip was after hours
Incident containmentyour own cost per hour of degraded or isolated operation x the containment hours you believe earlier detection saves. That number is your assumption about dwell time, not ours.
Toolinglicense and maintenance spend on point monitoring tools you actually retire. Count nothing here unless you truly turn something off.

Reliability and maintenance

Reliability
An intrusion that reaches devices which operate the grid can become a customer outage, so earlier detection genuinely reduces the chance a security event turns into SAIFI and SAIDI. Be careful with that claim internally, because the size of it depends entirely on how likely you believe an OT intrusion is, which is not a number anyone can hand you. The effect you can audit is smaller and real: behavioral baselining also surfaces chattering RTUs, failing communication paths, and misconfigured devices, which are ordinary availability problems.
Maintenance
Deviation from a learned communication baseline often means a device or a communication path is degrading, not that an attacker is present, so the same alert stream feeds planned telecom and RTU maintenance. That converts comms failures that today are found when a point goes stale into scheduled work.

What else it moves

ComplianceContinuous monitoring evidence for your electronic security perimeter and system monitoring requirements, produced as a record rather than assembled before an audit.
Insurance and riskDemonstrated behavioral monitoring of the control network is a specific question on cyber insurance applications and on most utility board risk reporting.
WorkforceYour two or three engineers who know what normal looks like stop being the only copy of that knowledge, which matters as they approach retirement.

What it costs you, stated honestly

You pay for the scoped engagement that builds and runs this, for passive collection hardware and the network taps or mirror ports to feed it, for the installation work at each monitored site, and for the integration into your security operations platform. You also pay your own analysts and engineers for tuning during the baseline learning window, and that tuning is where the false positive rate is decided. Underfund it and you will get an alert queue nobody reads.

How to build the payback case

Payback is normally carried by avoided log review hours, avoided engineer interruption, and avoided field verification truck rolls, all of which you can audit. Treat avoided incident cost as upside, because it rests on a dwell time assumption you cannot verify until you have the monitoring in place.

This is a planning model built from your site counts, alert volumes, truck roll costs, and loaded rates, not a vendor claim. Re-run it after the first baseline period, using your own measured alert volume and confirmation rate.
UC 13.3 Cyber Incident Response Copilot

What happens today, without this

When an OT cyber event is declared, the security lead on shift runs it from a printed playbook and a bridge line. One person keeps the timeline in a chat channel or a notebook, and that becomes the official record whether or not it is complete. The reportability determination under CIP-008 has to be made against a clock while the same handful of people are also deciding what to isolate and what has to stay running for the operators. Notifications to E-ISAC and the regulator get drafted afterward by reconstructing the sequence from chat logs, historian exports, and memory, often days later by someone who was not on the bridge.

What it replaces or shrinks

  • The hand kept incident timeline in a chat channel or a paper notebook
  • Manual reconstruction of the event sequence from SCADA, historian, and log exports after the fact
  • Verbal playbook step tracking on a bridge line, where completed steps are remembered rather than evidenced
  • Manual drafting of E-ISAC and regulator notifications from a blank page under a reporting clock
  • Shrinks the post incident report, which today is written from scratch by someone reassembling the story
  • Shrinks the tabletop preparation effort, since the workflow and evidence trail are already built

Why it is safer

The mechanism is coordination, not protective equipment, and it is honest to say so. During an OT incident, the dangerous pattern is uncoordinated action: an operator isolating equipment while a technician is en route to the same asset, or a device being restored while someone is working on it. A single live timeline and checklist that operations can see keeps isolation and restoration deliberate rather than parallel and improvised.

Counted in units you already track:

  • Switching operations performed under incident conditions, and the split between planned and reactive within that count
  • Energized area entries by technicians dispatched to isolate or verify equipment during an active incident
  • Night driving hours from off hours incident activations
  • Permits to work issued under emergency conditions during an incident rather than through normal change control

Man-hours it gives back

Bridge line hours, evidence gathering hours, and post incident reporting hours come back to the OT security team, and the compliance staff stop rebuilding a timeline that should have been captured while it happened.

HOURS AVOIDED PER YEAR = declared events and escalations per year x responders on a typical activation x hours per activation, plus post incident and regulatory report hours per event, plus exercises per year x preparation hours per exercise, minus the incident lead's time still spent reviewing and approving each checklist step and each drafted notification before it goes anywhere.

The numbers we need from you to run that formula:

  • Declared OT security events and escalations per year, including the ones that turned out to be nothing
  • Responders on a typical activation and hours each spends on the bridge
  • Hours spent writing the post incident report and the regulatory notification after a typical event
  • Exercises and tabletops per year and the preparation hours each consumes
  • Loaded hourly rates for an OT security lead, a security analyst, a compliance analyst, and an operator, plus your callout premium

Where the dollars come from

Cost driverHow it is calculated, from a rate you supply
Responder laboractivation hours avoided x your loaded responder rates, including overtime and callout premiums for off hours events
Reporting and legal reviewpost incident report and notification drafting hours avoided x your loaded compliance analyst and counsel rates
Incident response retainerretainer hours avoided x your contracted hourly rate, if you keep an outside IR firm on call
Operational impactyour own cost per hour of degraded, isolated, or manually operated systems x the hours you believe faster coordinated containment saves. Your operations team sets that hourly cost, not us.
Exercise preparationtabletop preparation hours avoided x your loaded rates for the staff who currently build the scenario and the evidence

Reliability and maintenance

Reliability
The reliability effect shows up only on the incidents where containment happens correctly and quickly, and it shows up as customer minutes not lost because a control system stayed available. Say it that way internally rather than putting a SAIDI number on it, because the frequency term in that calculation is an assumption about how often you will be attacked.
Maintenance
Corrective actions from an incident land as tracked work items with the evidence attached, instead of a list in a report that decays over the next quarter. Across events, the recurring root causes become visible, which is what lets you fix the underlying condition rather than the last symptom.

What else it moves

ComplianceA defensible, timestamped incident timeline and a reportability determination made against the clock with the supporting evidence attached, which is exactly what a CIP-008 review examines.
Insurance and riskCyber policies carry notification windows and evidence expectations of their own, and a live timeline satisfies both without a separate reconstruction effort.
WorkforceA less experienced lead can run a structured event at two in the morning, which reduces the dependence on the two or three people who currently must be called for everything.

What it costs you, stated honestly

You pay for the scoped engagement that builds and runs this, for integration into your incident tracker, historian, SCADA logs, and document store, and for the work of encoding your own playbooks and notification templates into the workflow. That encoding is your security and compliance team's time and it is the honest bulk of the implementation. It is worth doing once, and it is not something we can do for you, because the playbook has to be the one your people will actually follow.

How to build the payback case

Payback is carried by responder hours and by post incident reporting and notification hours, both of which you can pull from past events. Avoided operational impact is the larger number and the softer one, so treat it as upside in the case you present.

This is a planning model built from your event counts, responder counts, reporting effort, and loaded rates, not a vendor claim. Re-run it after your first two activations with the real timeline the tool produced.
Each of these opens in full on the use case page, alongside the integration plan, the data ask, the path to production, and the operator console. Open the use case library.
For Your Architects and Data Owners
Run this at your utility

What is this, exactly? It is AI software: intelligent agents and models built and delivered by SoftServe, running on NVIDIA accelerated computing. It is not a hardware appliance and it does not replace the systems you run today. It deploys in your own cloud or on your premises, connects read-only to your existing systems, and recommends; your people approve every action, starting in shadow mode until it earns trust.

An analysis service for the security team that models your operational technology environment, maps the attack paths an adversary could actually use, and returns a mitigation list ranked by real risk reduction. The demo above uses synthetic data; everything below describes what the real deployment needs from your organization.

Systems it connects to

Your systemTypical productsHow we connect
Cyber and OT securityClaroty, Nozomi, Dragos, Splunkscheduled file export (CSV or CIM XML)
Document and knowledge storesnetwork diagrams, NERC CIP documentation, firewall rule exportsdocument upload
Energy Management System (EMS) / transmission SCADAGE e-terra, AspenTech OSI monarchdocument upload
SCADA historianAVEVA PI System, AspenTech eDNAhistorian mirror (one-way feed)

Data it needs from you

How it runs on your systems

This data describes how to attack your grid, so the default deployment is fully isolated: an on-premises NVIDIA server with no internet connection. All inputs are exports and documents; nothing connects to live control systems, access is need-to-know, and handling follows your BES Cyber System Information rules.

Path to production

Weeks 1-5
Stand up the isolated environment and assemble asset, network, and CIP documentation; information handling approvals are the gate.
Weeks 6-13
Model the control center OT environment and enumerate attack paths against your current controls.
Weeks 14-16
Review the top ten attack paths not covered by CIP controls and make the go or no-go call.
Months 5-6
Harden the environment, set a re-run cadence, and fold findings into the security investment plan.
Month 6 onward
The OT security team re-runs the model after every architecture change and tracks mitigations quarterly.

What we need from your team

Full integration, data, and timeline detail for each use case in this scenario: UC 13.1 · UC 13.2 · UC 13.3
For Your Operators and Dispatchers
Where you will see it and how you say yes

The Approve button you just clicked in the demo above is the real workflow. This is what it looks like on the screen of the OT security architect in the GridCORTEX console:

GridCORTEX ConsoleSigned in: the OT security architect
Notifications
Threat model refresh: 10 attack paths outside current CIP controls; top path reaches the EMS via a vendor remote-access chain
Daily model refresh complete; all connected feeds healthy
Recommendation
Accept the ranked OT mitigation plan: 10 uncovered attack paths
  • The top 3 paths all traverse one shared vendor jump host
  • Fixing that host removes 6 of the 10 modeled paths
  • Est. risk reduction is 4x the next-best control
✓ Accept mitigation planModifyDecline
After you approve: Ranked mitigations open as change tickets in the security team's tracking system, implemented by engineers under existing change control, and an audit entry records who approved it and why.
Computed from data as of 17:42:10 local; every card shows the timestamp of the data behind it.

What happens when you hit approve

Accepting opens the ranked mitigations as draft change tickets in the security team's own tracking system, in pending status. Your engineers implement them under existing change control with their own tools; GridCORTEX touches no OT configuration.

How you tell it what it cannot see

The model builds automatically from connected security and configuration feeds. An asset or vendor connection the scanners cannot see can be added through a short console form.

Live data, not stale data

Topology and configuration data refresh on the cadence your security team approves, typically nightly; each finding shows the as-of timestamp of the data behind it.

Where it lives day to day

The threat model lives in the GridCORTEX console, restricted to the security team; a new high-severity path emails the CISO's team. The console runs in a browser beside your existing screens on day one; embedding into your own systems is a roadmap step once the read-only phase has earned trust. Approve, Modify, and Decline are all captured in an audit trail your compliance team can pull, and GridCORTEX never blocks or overrides anything in the systems you run today.

The Gap: Why Your Existing Systems Don't Already Do This

The fair question from any CISO: "We have a SIEM, an OT security vendor, firewalls between every Purdue level, and a clean CIP audit, what's new here?" Here's the honest answer.

What you own keeps doing its job

  • The SIEM, remains the system of record for events and the CIP evidence trail; the models feed it, not replace it.
  • OT security platforms (Dragos/Claroty-class), keep their asset inventory and threat-intel roles; behavioral analytics runs alongside, on the same passive taps.
  • Segmentation and firewalls, remain the enforcement layer; detection tells them where to look.
  • Your security and operations teams, every isolation, credential action, and report is their call. The AI flags and drafts; people decide.

The gap GridCORTEX fills, above them, not instead of them

  • Signatures catch what's been seen before; dwell lives in what hasn't. GPU-scale behavioral baselining (Morpheus-class) learns every device's normal (who it talks to, when, how often, with what command mix) and flags deviation in hours. The engineering workstation polling RTUs at 2 AM matched no signature. It just wasn't normal.
  • OT alerting drowns the one alert that matters. Correlation across the vendor-access logs, the workstation's history, and the RTU polling pattern turned three low-severity events into one high-confidence incident, ranked, explained, and ready for a human decision in minutes.
  • Containment usually costs operations. The response plan was computed against the live operating state: isolate the workstation and rotate the credentials, EMS links untouched, zero operational impact. The alternative discovered months later rarely gets that choice.
  • CIP-008 under pressure is where good responses go bad. Classification, the reporting clock, evidence preservation, notification drafts, ops briefings; the copilot runs the checklist so the humans can run the incident.
  • Compliance maps controls; the threat model maps paths. The vendor remote-access route was ranked #3 on the modeled attack-path list before the incident. After it: MFA hardening, jump-host enforcement, and a new monitoring rule, the ranking became a closed gap, and the tabletop schedule got its next scenario.
Accent, don't replace: GridCORTEX listens passively to the OT network your platforms already tap · learns normal, flags the 2 AM conversation that isn't, computes the containment that costs operations nothing, and drafts the CIP-008 paperwork · and your security team makes every call. Dwell time in hours, not months, that's the entire business case.
Under the Hood: What GridCORTEX Took Into Account in This Scenario

When someone asks "what did it actually calculate?", this is the list. In the simulation these factors drive the storyline; in a pilot they are computed from your passive network captures and logs, read-only, always.

👂 The Behavioral Baseline

  • 30 days of passive OT traffic modeled per device: peer sets, timing rhythms, protocol mix, command-class distribution (DNP3/ICCP-aware)
  • Deviation scoring per conversation (not per packet) so one workstation's new 2 AM habit outranks a thousand routine alerts
  • Read-only taps and span ports only; nothing is ever injected into the OT network

🔗 Correlation & Triage

  • Vendor remote-access session logs joined with workstation behavior and field-device polling patterns
  • Confidence build-out over time: watch → elevate → recommend containment, each step human-approved
  • Asset criticality context: which RTUs, which feeders, what an unauthorized command COULD affect, informing urgency without touching anything

🚧 Containment Without Casualties

  • Response options computed against live operating state: what can be isolated with zero operational impact, in what order
  • Credential rotation and access-path suspension sequenced with operations on the bridge line
  • Forensic preservation started before containment, the evidence survives the response

📋 The Paperwork That Protects You

  • CIP-008 classification and the notification clock tracked from minute zero; E-ISAC reporting draft prepared for review
  • Every detection, decision, and action Relay-traced, the audit sees the reasoning, not a reconstruction
  • Post-incident: threat-model rank #3 closed (MFA + jump-host + new monitoring rule), lessons fed to the next tabletop

Presenter's one-liner: "The network already knew what normal looked like, so the workstation that started polling fourteen RTUs at 2 AM stood out like a shout in a library. Flagged in four hours, contained without touching a single EMS link, CIP-008 clock run properly, and the attack path the threat model had ranked #3 got closed for good. The grid never noticed. In this business, the best incident story is no story."

GridCORTEX Live Scenario Demo · Synthetic data throughout; Cedar Ridge Utility is fictional; no real incident, actor, or technique is depicted · Passive, read-only OT monitoring; humans decide every action · SoftServe + NVIDIA · Created by Ronnie Mauldin, NVIDIA Solutions Director, Power & Utilities, SoftServe · JUL 2026