
Sentinel CPV
Cyber-Physical Verification platform for industrial OT environments. Verifies control actions against P&ID topology, work permits, and sensor physics.
Informazioni su questo modello
1. Product Overview
Sentinel CPV is a passive OT security verification overlay. It watches what your operations layer already produces — Modbus register writes, historian telemetry, work orders and Management-of-Change (MOC) permits — and verifies every control action across four deterministic layers: protocol conformance, semantic binding to your P&ID, operational authorization, and physical response. The result is a short queue of Evidence-Chain alerts you can act on, and silence where authorized maintenance should be silent.
It is an overlay, not a replacement: Sentinel CPV maximises the ROI of the sensors, historians and network monitoring you already run, and never interferes with the process.
2. The Problem Sentinel CPV Solves
Industrial plants drown in alerts that don't mean anything:
- The 99 % false-positive engine. Up to 99 % of raw alerts from unsupervised network anomaly detectors in industrial environments are false alarms — the overwhelming majority of anomalies are legitimate maintenance, tuning, calibration and startups.
- Valid packets, hostile intent. Targeted ICS attacks (PIPEDREAM, TRITON) use perfectly valid protocol framing and authorized function codes. Packet inspectors see nothing.
- Statistical blindness. Incumbent platforms baseline process values statistically but never ask whether the action was authorized (MOC/permit) or whether the plant physically complied — so plant changes trigger nuisance alarms while stealthy setpoint manipulation inside the "normal" envelope sails through.
- The encryption horizon. CIP Security, S7comm-plus TLS and OPC UA SignAndEncrypt are erasing raw payload visibility at SPAN ports — platforms that must read plaintext registers are approaching obsolescence.
- Compliance pressure. NERC CIP-015-1, TSA SD-02, NIS2, IEC 62443 and NCA OTCC-1 all demand continuous OT monitoring with audit-grade evidence.
Sentinel CPV answers the three questions nobody else asks together: what does this write mean, was it authorized, and did the plant physically respond?
3. How It Works
Every observation traverses the same deterministic path. Nothing is sampled, learned or guessed: identical input always produces an identical verdict, so any alert can be replayed and audited years later.
4. Key Capabilities
- Semantic register binding — raw Modbus offsets beco
Caratteristiche principali
Casi d’uso
- Refinery and chemical continuous-process setpoint integrity
- Pipeline and pumping station unauthorized valve command detection
- Power generation and turbine cyber-physical anomaly monitoring
- Water treatment plant operational context and maintenance verification
- Industrial regulatory compliance audits (NERC CIP, NIS2, IEC 62443)
Piani tariffari



