Solutions · Energy & Utilities

Which identities reached your control systems last night?

Your IGA knows who was entitled. Your OT monitoring knows a connection happened. Your historian knows a value changed. None of them can tell you whether that behavior was normal for that identity. The adversaries pre-positioning in critical infrastructure do not break in; they log in, with valid credentials, and wait.

Book a Discovery WorkshopGet the datasheet
The reconciliation no operator runs

Every barrel, molecule, and megawatt gets reconciled.
Access does not.

Entitlement is asserted in your role model; behavior is the only proof. CINQUE reads all five control points together and shows where the two disagree, without touching the tools your OT team will not let you touch.

PersonaEntitled, per RBACObserved, per CINQUEVariance
OEM remote engineerVendor jump host onlyControl network reachedBOUNDARY CROSSED
Meter data service accountMeter reads, nightly batchNew scopes, off-windowSCOPE DRIFT
Substation contractorRead one-line diagramsRead and bulk exportNEW EXPORT PATH
Reliability AI agentRecommend work ordersRecommend and createFOUR-EYES BREAK
Historian replication feedProcess data, continuousProcess data, continuousRECONCILED
Illustrative. Each variance sits below the triage threshold of the console that owns it. It exists only once all five control points are read together.

Detection tells you what happened. Context tells you whether it was supposed to happen.

Where energy operators point it first

Four places energy operators point it first.

The IT/OT boundary

Who, or what, is crossing from corporate toward control rooms, plants, and pipelines.

Vendors, integrators, and OEMs

What contracted identities actually touched, from the jump host to the operations network and beyond it.

Non-human identities

Service accounts, Shadow AI, and the agents entering operational workflows, each baselined as a persona of its own.

Reporting readiness

When a risk is real, the full journey is attached: the story a 24-hour incident report needs.

Mapped to what your regulators and assessors now expect

Evidence you can stand behind
at assessment, to your insurer, and to the board.

The expectation
Who is asking
What CINQUE gives you
A current, defensible inventory of critical systems, identities, and access
TSA SD Pipeline-2021-02 series · NERC CIP-002 / -004 · IEC 62443
Personas discovered from observed behavior, human, non-human, and agentic; current by construction, not by refresh date.
Evidence the IT/OT boundary holds in practice, not just on the architecture diagram
TSA SDs (segmentation) · NERC CIP-005 · IEC 62443 zones and conduits
Every identity's observed journey across the boundary, reconciled against what its role asserts.
Continuous monitoring and detection inside the operational network
TSA SDs · NERC CIP-015 (internal network security monitoring) · CISA guidance
Behavioral baselines per persona across all five control points, Shadow AI and rogue service accounts included.
Evidence you can stand behind at assessment, to your insurer, and to the board
Your TSA-approved plan's annual assessment · your insurer · your board
A short list of correlated, business-contextualized risks with the full journey attached.

TSA SD Pipeline-2021-02 series requires segmentation, access control, continuous monitoring and detection, and patching under a TSA-approved plan assessed annually; NERC CIP-015 (approved 2025) requires internal network security monitoring. References current as of August 2026; obligations vary by segment, the direction toward continuous behavioral evidence does not.

Datasheet

CINQUE for Energy & OT security leaders

Which identities reached your control systems last night? The adversaries pre-positioning in critical infrastructure log in with valid credentials and wait. Behavior is the only proof.

What it covers
  • The IT/OT boundary, evidenced in practice, not on the diagram
  • Vendors, integrators, and OEMs: what contracted identities actually touched
  • Non-human identities and Shadow AI baselined as personas of their own
  • Evidence mapped to TSA SD Pipeline-2021-02, NERC CIP-002/-004/-005/-015, IEC 62443

Your data, handled like we mean it. You choose the export: limited, point-in-time, analyzed in an isolated environment, and deleted after your readout. Ask us for the data-handling summary; we are a security company and we expect the question.

The CINQUE Discovery Workshop · complimentary

Bring your identity export.
Leave with your reconciliation.