Security built for power systems, not retrofitted from IT

See every device on your grid. Catch attacks before the lights go out.

GridHawk passively monitors your OT network — substations, SCADA, solar and wind plants, battery storage — and understands the protocols they actually speak. Asset inventory, threat detection, and NERC CIP evidence from a single SPAN port. No agents. No downtime. No outsourcing your visibility.

Open live demo How it works
Days, not hours
How long a ransomware'd control site stays locked out. Colonial Pipeline shut down 5,500 miles of pipeline for six days.
$1M / day
Maximum NERC CIP penalty — per violation, per day. Audit evidence is a full-time job utilities don't have staff for.
20+ year old
Typical age of deployed SCADA equipment. It was never designed to be on a routable network — and now it is.

One sensor. Three jobs.

GridHawk deploys as a passive sensor on a SPAN/tap port inside your OT network. It never transmits onto the control network — it only listens.

Asset inventory

Know what's actually on the wire

Passive discovery of every PLC, RTU, IED, HMI, and historian — vendor, model, firmware, and known CVEs — without scanning. Active scans crash 20-year-old controllers; listening doesn't.

Threat detection

Protocol-aware, grid-specific

Deep inspection of Modbus, DNP3, IEC 61850, and ICCP. GridHawk baselines who commands what, then flags unauthorized writes, rogue masters, new devices, and the lateral-movement and encryption patterns that precede ransomware lockout.

Compliance

NERC CIP evidence on autopilot

The same telemetry doubles as audit evidence: BES cyber asset lists (CIP-002), electronic security perimeter monitoring (CIP-005), and configuration change records (CIP-010) — exportable, timestamped, continuous.

Built for inverter-based resources too

Solar, wind, and battery storage sites run on the same fragile protocols as substations — with leaner staff and more remote connectivity. GridHawk covers the whole fleet from the same sensor.

Solar & wind plants

Plant controllers to trackers

Passive inventory and monitoring for plant controllers, inverters, met stations, and trackers speaking SunSpec Modbus and DNP3 — plus the vendor VPNs and cloud SCADA links that connect them to the outside world.

Battery storage

BESS-aware baselining

Battery management systems and power conversion systems have tight, regular command patterns. GridHawk baselines dispatch traffic and flags out-of-band writes to setpoints before they become a safety event.

CIP Low Impact

Evidence without the headcount

Most renewable sites are CIP-003 Low Impact — light on requirements, lighter on staff. GridHawk generates the asset lists, access monitoring, and transient-cyber-asset records auditors ask for, automatically.

A platform you own, not a service you rent

The incumbent model for renewable OT security is outsourcing — managed security and network operations billed as an ongoing service. GridHawk takes the opposite bet: give operators the visibility directly.

Managed security services GridHawk
Who sees your network The vendor's SOC — you get reports Your team, live, in one dashboard
Deployment Weeks of onboarding and scoping calls Passive sensor on a SPAN port — first alert in under a day
Cost model Recurring per-site service fees that scale with headcount Per-sensor platform pricing that scales with your fleet
Compliance evidence Assembled by consultants at audit time Generated continuously from live telemetry
When the contract ends The visibility leaves with the vendor The sensor, the data, and the baselines stay yours

Have an MSSP you like? GridHawk exports alerts over syslog and webhooks — it makes a managed SOC better, it doesn't require one.

How it works

From rack to first alert in under a day — with zero risk to operations.

Step 1 — Tap

Mirror the traffic

Connect the GridHawk sensor to a SPAN port or network tap at the substation or control center. Read-only by construction: the capture interface has no IP address on the OT network.

Step 2 — Learn

Baseline the process

For the first days, GridHawk maps devices and conversations: which master polls which outstation, which registers get written, on what cadence. Grid traffic is highly regular — that's the defender's advantage.

Step 3 — Watch

Alert on what matters

Deviations from the baseline — a write from a new source, a cold-restart command, an encryption burst on the HMI subnet — surface as ranked alerts with the affected asset, the protocol evidence, and the ATT&CK for ICS technique.

Why now

Four forces are converging on utility operators at once.

Ransomware moved to OT

Crews that used to encrypt file servers now target the systems that keep sites running — because operators pay when production stops.

IT/OT convergence opened the door

Remote access, cloud historians, and vendor VPNs connected networks that were designed to be air-gapped. The isolation assumption is gone.

Regulators are escalating

NERC CIP audits are getting stricter, and internal network security monitoring (CIP-015) is now on the books. Continuous monitoring is becoming table stakes, not best practice.

Insurers demand proof

Cyber insurance for critical infrastructure increasingly requires demonstrated OT monitoring and asset inventory — or premiums become untenable.

The market is wide open. So is your network.

Walk through a live incident in the demo environment — no signup required.

Open live demo

Request a pilot

A 30–60 day paid pilot: one passive sensor, first asset inventory inside two weeks, NERC CIP evidence pack at close-out. Tell us about your site and we'll come back with scope and timing.

We'll only use this to reply about a pilot. No newsletter, no sharing.