Critical infrastructurethreat detection.
Six weeks from initial anomaly to attribution and containment. A pre-positioning operation on a national energy transmission operator's OT network — identified, contained, and removed with zero operational disruption.
“The difference between detecting a pre-positioning operation before it can be used, and detecting it after.”
— National energy transmission operator CISO
0
Operational disruption
91%
Attribution confidence
14
Substations confirmed clean
6 wk
Anomaly → containment
A coastal republic, a national energy operator's OT network.
Sector
Energy (transmission)
Asset exposed
SCADA mgmt workstation
Substations
14 in scope
Window
6–10 weeks pre-disruption
CISO's question
Pre-positioning, or benign?
A national energy transmission operator detected an anomalous pattern of outbound network connections from a SCADA management workstation. The pattern was subtle: a low-volume, encrypted connection to a destination classified as "uncategorized" rather than "known-bad." The workstation was inside the OT network's management plane, with logical access to 14 substations. The CISO described the situation as "we don't know if this is a benign misconfiguration, a compromised vendor laptop, or the first stage of a pre-positioning operation."
The Challenge
Four constraints, all severe.
01 / 04
Playbook assumed 4–6 weeks; CISO had 6.
The pattern was consistent with pre-positioning, and the pre-positioning window for a disruption event was 6–10 weeks out. The CISO could not afford the standard 4–6 week response.
02 / 04
IT/OT boundary must be crossed.
The CISO's IT team and the CISO's OT team had different tooling, different vocabularies, different escalation paths. The platform needed to operate across both in a way the existing org structure could absorb.
03 / 04
SCADA workstation could not be taken offline.
Doing so would have disrupted the operator's ability to monitor the 14 substations. The 14 substations could not be operated in "safe mode" without a multi-agency coordination process measured in weeks.
04 / 04
False positive would trigger national-level response.
A falsely-flagged OT incident, communicated to the regulator, would have triggered a national-level response and a measurable impact on the operator's reputation and on the energy market.
Six steps across IT and OT, in 6 weeks.
Day 0
Step 01 / 06
Anomalous outbound connection
Low-volume, encrypted connection from a SCADA management workstation to a destination the operator's existing network monitoring had classified as 'uncategorized' rather than 'known-bad'. Workstation inside OT management plane, with logical access to 14 substations.
Day 0–3
Step 02 / 06
Sovereign on-prem deployment
Platform deployed in the operator's secure NOC. 5-layer stack operationalized against an OT-specific detection model. Cyber, geospatial, and geopolitical layers integrated with operator + national CERT feeds.
Day 3
Step 03 / 06
91% attribution confidence
Anomaly detection engine identified the outbound connection pattern as a known tradecraft signature of a named state-aligned APT family. Cross-validated by 4 signals: infrastructure reuse, TTP fingerprinting, geopolitical context (12-week forecast), corroborating cyber signal (domain registration).
Day 3+
Step 04 / 06
Surgical containment plan
Isolate outbound at network layer. Rotate credentials. Deploy decoy to monitor implant behavior. Conduct 14-day hunt across 14 substations for lateral movement. Plan did not require taking the workstation offline.
Day 3–17
Step 05 / 06
14-day hunt
Platform produced a daily hunt product, delivered to CISO + OT team, narrowing the lateral-movement search space as the hunt progressed. By day 14, the platform had established high confidence that the implant had not moved beyond the original workstation.
Day 17–42
Step 06 / 06
Implant contained, removed
Pre-positioning implant identified, contained, and removed within the 6-week window. 14 substations confirmed clean. SCADA workstation reimaged; operational tempo not measurably affected. 91% attribution supported national-level response via energy regulator, national CERT, and ministry of foreign affairs.
Cyber Threat Intelligence
OT-tuned tradecraft signatures, named-APT family correlation.
Geospatial & Physical INT
Physical asset registry integration, location intelligence.
Multi-INT Fusion
OSINT + CYBINT + GEOINT + geopolitical in one graph.
Threat Detection & Attribution
91% attribution, 4 cross-validating signals.
Predictive Foresight
12-week forecast of increased CI targeting.
0
Operational disruption
91%
Attribution confidence
14
Substations confirmed clean
6 wk
Anomaly → containment
Engagement timeline
Six weeks, eight milestones.
D-0
Anomalous outbound connection
SCADA management workstation → uncategorized destination.
01 / 08
D-0–3
Sovereign deployment
5-layer stack wired to OT NOC + national CERT feeds.
02 / 08
D-3
91% attribution
4 independent signals. Named APT family identified.
03 / 08
D-3+
Surgical containment
Outbound isolation, credential rotation, decoy deployed.
04 / 08
D-3–17
14-day hunt
Daily product narrowed lateral-movement search.
05 / 08
D-17
Hunt completed
High confidence implant did not move beyond original workstation.
06 / 08
D-17–42
Implant contained, removed
Substations confirmed clean. Workstation reimaged.
07 / 08
D+
National-level response
Energy regulator, national CERT, ministry of foreign affairs.
08 / 08
Lessons learned
Three lessons from this engagement.
Lesson 01
In critical infrastructure, the detection-to-attribution window is the operational difference.
The platform's value was not in producing a better report; it was in producing a defensible attribution fast enough that containment could be achieved before the pre-positioning window closed.
Lesson 02
IT/OT integration is not a slogan.
The platform's ability to operate across the CISO's IT team and the CISO's OT team, in a single product, was the operational difference. Single-team tooling could not have closed the case in the available time.
Lesson 03
The geopolitical context is not optional.
The 12-week forecast of increased critical-infrastructure targeting — produced three weeks before the anomaly was detected — was what made the attribution defensible. The CISO could not have made the case for the 6-week response tempo on cyber signals alone.
Related
Related Sovereignty Infinium capabilities.
Pre-positioning detected before the operator was ready to use it.
The 91% attribution, the surgical containment plan, the 14-day hunt, the 14 substations confirmed clean — all in a confidential briefing tailored to your OT environment and the seams between IT and OT.
- 60 minutes · response within 1 day
- Under your security protocols