Which identities reached your control systems last night?
Your IGA knows who was entitled. Your OT monitoring knows a connection happened. Your historian knows a value changed. None of them can tell you whether that behavior was normal for that identity. The adversaries pre-positioning in critical infrastructure do not break in; they log in, with valid credentials, and wait.
Every barrel, molecule, and megawatt gets reconciled.
Access does not.
Entitlement is asserted in your role model; behavior is the only proof. CINQUE reads all five control points together and shows where the two disagree, without touching the tools your OT team will not let you touch.
| Persona | Entitled, per RBAC | Observed, per CINQUE | Variance |
|---|---|---|---|
| OEM remote engineer | Vendor jump host only | Control network reached | BOUNDARY CROSSED |
| Meter data service account | Meter reads, nightly batch | New scopes, off-window | SCOPE DRIFT |
| Substation contractor | Read one-line diagrams | Read and bulk export | NEW EXPORT PATH |
| Reliability AI agent | Recommend work orders | Recommend and create | FOUR-EYES BREAK |
| Historian replication feed | Process data, continuous | Process data, continuous | RECONCILED |
Detection tells you what happened. Context tells you whether it was supposed to happen.
Four places energy operators point it first.
The IT/OT boundary
Who, or what, is crossing from corporate toward control rooms, plants, and pipelines.
Vendors, integrators, and OEMs
What contracted identities actually touched, from the jump host to the operations network and beyond it.
Non-human identities
Service accounts, Shadow AI, and the agents entering operational workflows, each baselined as a persona of its own.
Reporting readiness
When a risk is real, the full journey is attached: the story a 24-hour incident report needs.
Evidence you can stand behind
at assessment, to your insurer, and to the board.
TSA SD Pipeline-2021-02 series requires segmentation, access control, continuous monitoring and detection, and patching under a TSA-approved plan assessed annually; NERC CIP-015 (approved 2025) requires internal network security monitoring. References current as of August 2026; obligations vary by segment, the direction toward continuous behavioral evidence does not.
CINQUE for Energy & OT security leaders
Which identities reached your control systems last night? The adversaries pre-positioning in critical infrastructure log in with valid credentials and wait. Behavior is the only proof.
- The IT/OT boundary, evidenced in practice, not on the diagram
- Vendors, integrators, and OEMs: what contracted identities actually touched
- Non-human identities and Shadow AI baselined as personas of their own
- Evidence mapped to TSA SD Pipeline-2021-02, NERC CIP-002/-004/-005/-015, IEC 62443
Your data, handled like we mean it. You choose the export: limited, point-in-time, analyzed in an isolated environment, and deleted after your readout. Ask us for the data-handling summary; we are a security company and we expect the question.