Different rules apply
Corporate IT telemetry assumes reliable bandwidth, hosts that accept software, and protocols that speak HTTPS. Operational environments break all three assumptions. A production line talks Modbus and OPC UA. A vehicle fleet connects intermittently over cellular. A substation has a change window measured in months. Installing an agent is often forbidden by the equipment vendor's support terms, and shipping raw traffic to a cloud analytics platform is either too expensive or too slow to be useful.
Principles
Observe, do not install. A span port or network tap gives a collector full visibility into protocol traffic without placing anything on the controller.
Decode locally. Raw packets are not events. A CyberAIX Pipeline universal collector parses industrial protocols into structured records: which device sent which command to which target, with what values.
Learn what normal looks like, per device. Command sets, peer relationships, and polling cadence are remarkably stable in operational networks. A baseline built over two weeks catches almost everything that matters afterward.
Forward exceptions and summaries, not everything. A controller that reports the same register value every hundred milliseconds does not need every reading in a SIEM. It needs the reading that changed when nothing should have. Steady state becomes a periodic rollup.
Survive disconnection. Buffer locally, replay on reconnect, and never lose an event because the uplink dropped for six hours.
Carry IT context. An operational anomaly is far more useful when the collector has already tagged it with the engineering workstation involved and the account signed in on it. That makes the join with IT telemetry trivial downstream.
Deployment shape
One lightweight collector per site or network segment, each receiving its policy from the central CyberAIX control plane and forwarding reduced, enriched events inward. Site operators see a local view. The security operations center sees the consolidated one. A new rule reaches every plant in one change.
The first two weeks
Pick one site. Put a collector on a span port. Do nothing but baseline. Then compare the volume of raw protocol traffic with the volume of anomalies and summaries the collector would have forwarded. That ratio is your business case, and it is usually large.
See this on your own telemetry
Book a 30-minute demo. We connect a real source and show reduction, enrichment, and routing live.