GridHawk passively monitors your OT network — substations, SCADA, solar and wind plants, battery storage — and understands the protocols they actually speak. Asset inventory, threat detection, and NERC CIP evidence from a single SPAN port. No agents. No downtime. No outsourcing your visibility.
GridHawk deploys as a passive sensor on a SPAN/tap port inside your OT network. It never transmits onto the control network — it only listens.
Passive discovery of every PLC, RTU, IED, HMI, and historian — vendor, model, firmware, and known CVEs — without scanning. Active scans crash 20-year-old controllers; listening doesn't.
Deep inspection of Modbus, DNP3, IEC 61850, and ICCP. GridHawk baselines who commands what, then flags unauthorized writes, rogue masters, new devices, and the lateral-movement and encryption patterns that precede ransomware lockout.
The same telemetry doubles as audit evidence: BES cyber asset lists (CIP-002), electronic security perimeter monitoring (CIP-005), and configuration change records (CIP-010) — exportable, timestamped, continuous.
Solar, wind, and battery storage sites run on the same fragile protocols as substations — with leaner staff and more remote connectivity. GridHawk covers the whole fleet from the same sensor.
Passive inventory and monitoring for plant controllers, inverters, met stations, and trackers speaking SunSpec Modbus and DNP3 — plus the vendor VPNs and cloud SCADA links that connect them to the outside world.
Battery management systems and power conversion systems have tight, regular command patterns. GridHawk baselines dispatch traffic and flags out-of-band writes to setpoints before they become a safety event.
Most renewable sites are CIP-003 Low Impact — light on requirements, lighter on staff. GridHawk generates the asset lists, access monitoring, and transient-cyber-asset records auditors ask for, automatically.
The incumbent model for renewable OT security is outsourcing — managed security and network operations billed as an ongoing service. GridHawk takes the opposite bet: give operators the visibility directly.
| Managed security services | GridHawk | |
|---|---|---|
| Who sees your network | The vendor's SOC — you get reports | Your team, live, in one dashboard |
| Deployment | Weeks of onboarding and scoping calls | Passive sensor on a SPAN port — first alert in under a day |
| Cost model | Recurring per-site service fees that scale with headcount | Per-sensor platform pricing that scales with your fleet |
| Compliance evidence | Assembled by consultants at audit time | Generated continuously from live telemetry |
| When the contract ends | The visibility leaves with the vendor | The sensor, the data, and the baselines stay yours |
Have an MSSP you like? GridHawk exports alerts over syslog and webhooks — it makes a managed SOC better, it doesn't require one.
From rack to first alert in under a day — with zero risk to operations.
Connect the GridHawk sensor to a SPAN port or network tap at the substation or control center. Read-only by construction: the capture interface has no IP address on the OT network.
For the first days, GridHawk maps devices and conversations: which master polls which outstation, which registers get written, on what cadence. Grid traffic is highly regular — that's the defender's advantage.
Deviations from the baseline — a write from a new source, a cold-restart command, an encryption burst on the HMI subnet — surface as ranked alerts with the affected asset, the protocol evidence, and the ATT&CK for ICS technique.
Four forces are converging on utility operators at once.
Crews that used to encrypt file servers now target the systems that keep sites running — because operators pay when production stops.
Remote access, cloud historians, and vendor VPNs connected networks that were designed to be air-gapped. The isolation assumption is gone.
NERC CIP audits are getting stricter, and internal network security monitoring (CIP-015) is now on the books. Continuous monitoring is becoming table stakes, not best practice.
Cyber insurance for critical infrastructure increasingly requires demonstrated OT monitoring and asset inventory — or premiums become untenable.
Walk through a live incident in the demo environment — no signup required.
Open live demoA 30–60 day paid pilot: one passive sensor, first asset inventory inside two weeks, NERC CIP evidence pack at close-out. Tell us about your site and we'll come back with scope and timing.