Which identities touched the line last night?
Your security stack keeps growing, yet IT tools and OT tools still do not see each other. None of them can tell you whether a vendor logging into a PLC, or a service account talking to a machine controller, is normal for that identity. That is where real risk lives on a converged plant floor.
AI for security is what every tool claims.
Security for the AI on your plant floor is the part most skip.
Your environment now runs copilots, predictive-maintenance agents, and autonomous systems that reason and access production at runtime. Can you even see them, and what they can reach? CINQUE makes them visible as personas with observed behavior, measured against what is normal for each.
| Persona | Entitled, per RBAC | Observed, per CINQUE | Variance |
|---|---|---|---|
| OEM remote engineer | Vendor jump host only | Control network reached | BOUNDARY CROSSED |
| MES service account | Line data, shift window | New scopes, off-shift | SCOPE DRIFT |
| Engineering contractor | Read unit drawings | Read and bulk export | NEW EXPORT PATH |
| Predictive-maintenance agent | Recommend work orders | Recommend and create | FOUR-EYES BREAK |
| Historian replication feed | Process data, continuous | Process data, continuous | RECONCILED |
Detection tells you what happened. Context tells you whether it was supposed to happen.
Four places manufacturers point it first.
The IT/OT boundary
Who, or what, is crossing from the corporate network onto the plant floor, reconciled against what its role asserts.
Vendors, integrators, and OEMs
What contracted identities actually touched, from the jump host to the controller and beyond it.
Non-human identities
Service accounts, engineering copilots, and the agents entering production workflows, each baselined as a persona of its own.
Evidence for the people who ask
Audits, insurers, customer security reviews, and CMMC assessors get correlated stories, not a pile of alerts.
IEC 62443 asks for inventory, boundaries, and monitoring.
CINQUE evidences all three from behavior.
Based on the ISA/IEC 62443 zone-and-conduit model for industrial automation and control systems, the working OT security standard across manufacturing. Defense-supply-chain manufacturers face a parallel deadline: CMMC 2.0 Phase 2 begins November 10, 2026.
CINQUE for Manufacturing security leaders
Which identities touched the line last night? IT and OT read together, so a vendor on a PLC or a service account talking to a controller is judged against what is normal for that identity.
- Asset inventory across every IEC 62443 zone and conduit, from behavior
- Who, or what, is crossing from corporate onto the plant floor
- Conduits monitored for abnormal behavior, not just signatures
- Evidence for audits, insurers, and customer security reviews; CMMC 2.0 Phase 2 begins November 10, 2026
Your data, handled like we mean it. You choose the export: limited, point-in-time, analyzed in an isolated environment, and deleted after your readout. Ask us for the data-handling summary; we are a security company and we expect the question.