Cybersecurity & Control Isolation
The plant's control systems are isolated so that a cyber intrusion cannot become a loss of power.
Control as an attack surface
A grid-forming, software-defined plant has a control system that is, in principle, an attack surface. Cybersecurity for Aegis is about ensuring that no external network path can reach the systems that keep the plant running, so that a cyber event cannot become a physical outage.
Isolation and segmentation
The control architecture is segmented: operational-technology networks that run the machine are isolated from business and external networks, with tightly controlled, monitored boundaries between them. Critical protective functions run locally and can act without the supervisory network, so losing higher-level control does not lose the plant. Redundant control paths avoid a single compromised node taking the unit.
- Operational-technology networks isolated from external ones
- Monitored, minimal, controlled network boundaries
- Local protective functions independent of supervisory control
- Redundant control paths; no single point of compromise
Resilience by local autonomy
The design principle is that the safest control is the least connected. Grid-forming droop lets units share load without a central master on the critical path, so the island survives loss of the controller network. This local autonomy is a cybersecurity property as much as a control one.
This page is deliberately high-level and public; it states the philosophy — isolation, segmentation, and local autonomy of the functions that keep the plant alive — without any sensitive implementation detail that could aid an attacker. The guiding rule is that any function whose loss would drop the mission must be able to run without a network connection, so connectivity is treated as an enhancement to operations, never a dependency of survival.