Complete, Automated Visibility Across Every Layer of Your OT Environment — Analog, Fieldbus, Serial, and IP
The Problem
Critical infrastructure environments, water treatment facilities, electric substations, pipeline networks, and government operational systems, run on a mix of technology generations. Modern IP-connected controllers sit alongside legacy field equipment communicating over serial links, analog signals, and fieldbus protocols, much of it decades old and never designed to be discovered or monitored the way IP devices are.
Water treatment facilities, electric substations, and pipeline networks across the country still rely on decades-old serial and analog communications to control the physical processes that keep essential services running. RS-232, RS-485, current loop, and other serial, analog, and fieldbus physical-layer communications occupy a distinct layer of the environment, one that remains in widespread use at Level 0 (sensors, actuators) and Level 1 (PLCs, RTUs, IEDs) of the Purdue Model and was never designed to traverse an IP network.
The result for most operators is an incomplete asset inventory. IP-based discovery tools can enumerate what is on the network, but the RTUs, PLCs, protective relays, sensors, and actuators communicating over non-IP mediums, the equipment operating pumps, breakers, and valves , often go entirely undocumented. Security teams end up making risk decisions, compliance filings, and incident response plans based on a partial picture of their own infrastructure.
The Solution
Cynalytica’s AnalytICS Engine Asset Discovery tool closes that visibility divide with passive, protocol-native discovery across the full spectrum of ICS/OT communications:
- Analog & Fieldbus — Identifies field instrumentation and control equipment communicating over current loop (4–20mA), voltage-based analog signals, and fieldbus protocols at Level 0 of the Purdue Model
- Serial — Discovers and profiles devices communicating over RS-232, RS-485, and RS-422 links, extracting protocol-specific detail from Modbus RTU, DNP3 serial, and proprietary vendor protocols
- IP — Correlates findings with IP-based industrial network traffic, feeding normalized asset and communications data into a single shared visibility layer
AnalytICS Engine applies behavioral analytics and anomaly detection across these non-IP data streams, generating a unified asset inventory and communications baseline that spans Level 0 through Level 3 of the Purdue Model. Discovery is entirely passive and out-of-band, there is no active polling of field devices, no changes to existing control system configurations, and no new network paths introduced into the operational environment, preserving the fail-safe posture that water and electric utility environments require.
The Benefit
- One Complete Asset Inventory — Identifies field instrumentation and control equipment communicating over current loop (4–20mA), voltage-based analog signals, and fieldbus protocols at Level 0 of the Purdue Model
- Visibility Down to Level 0/1 — Extends discovery to RTUs, PLCs, IEDs, sensors, and actuators that conventional IP-based tools were never built to see
- Zero Operational Risk — Passive, non-intrusive monitoring introduces no latency, polling, or risk to live control processes
- Stronger Compliance Posture — Supports documentation and reporting aligned with NERC CIP, AWWA, and other sector-specific regulatory frameworks by evidencing visibility across the full operational technology stack
- A Foundation for Full-Spectrum Security — Establishes the asset and communications baseline that powers correlated threat detection across your entire environment, including as part of Cynalytica’s integration with the Dragos platform for unified IP and non-IP threat detection