Technical Deep Dive

Architecture, protocols, platforms, and methodology behind CyberFabric's OT Security Operations Center. This page is for security architects, OT engineers, and technical evaluators.

SOC Architecture

CyberFabric operates a three-tier SOC model purpose-built for OT/ICS environments:

TierFunctionSLAStaffing
Tier 1AI-driven automated triage and containment. Multi-source correlation (SIEM, NDR, UEBA, TIP). False positive elimination.<200msAutomated + ML
Tier 2Human investigation of escalated incidents. OT-context analysis. Playbook execution.5 minOT analysts (ex-plant engineers)
Tier 3Critical incident command. Cross-functional coordination. Forensic investigation.15 minSenior incident commanders

Proactive operations include weekly threat hunting (behavioral analytics, ICS YARA rules, APT TTPs), monthly deep sweeps, and continuous threat intel correlation against customer-specific asset inventories.

Detection Platform: Stellar Cyber Open XDR

CyberFabric's default SecOps engine when customers don't have an existing stack:

Core Capabilities

Supported Industrial Protocols

Modbus TCP/RTU    DNP3           OPC-UA          OPC-DA
BACnet            PROFINET       EtherNet/IP     S7comm
IEC 60870-5-104   IEC 61850      HART-IP         CIP
GOOSE             MMS            GE-SRTP         Emerson ROC

Detection Performance

MetricValueMethodology
Mean Time to Detect (MTTD)8× faster than manual SOCAutomated correlation + ML triage
False Positive Reduction90%+Multi-Layer AI with OT context
Analyst Productivity80%+ improvementAutomated triage, enrichment, and case management
Auto-Containment<200msSOAR-driven with OT-safe guardrails

Infrastructure: Ixian Decentralized Platform

CyberFabric's infrastructure layer for data transport, device identity, and audit integrity:

Architecture

Why Decentralized for OT?

Cloud-based OT security creates three risks that decentralized architecture eliminates:

Open-source and auditable: github.com/ixian-platform

Forward-Deployed Engineer (FDE) Model

The FDE model is CyberFabric's primary deployment and customer success methodology. Each FDE is a senior OT security specialist with direct ICS/SCADA experience.

Deployment Timeline

PhaseDurationActivities
ImmersionWeek 1–2On-site environment mapping, asset inventory, protocol identification, safety system assessment, existing tool evaluation, stakeholder interviews
DeploymentWeek 3–6Sensor placement, platform configuration, behavioral baseline collection, custom detection rule development, integration with existing tools
SOC IntegrationWeek 7–12Live SOC onboarding, playbook development with operators, threshold tuning, first tabletop exercise, initial threat hunt
OptimizationOngoingMonthly detection reviews, baseline recalibration, new asset onboarding, staff training, quarterly posture assessments

FDE Qualifications

Tool-Agnostic Integration

CyberFabric integrates with existing customer security and OT tools. The SOC normalizes, correlates, and operates across heterogeneous stacks.

Supported Integrations

CategoryPlatforms
SIEMSplunk, IBM QRadar, Microsoft Sentinel, Elastic SIEM, LogRhythm
EDR / XDRCrowdStrike, SentinelOne, Microsoft Defender, Carbon Black
Network SecurityPalo Alto Networks, Fortinet, Cisco, Check Point
OT SecurityNozomi Networks, Claroty, Dragos, OTORIO, Armis
Cloud / IdentityAWS, Azure, GCP, Okta, Active Directory
Threat IntelMITRE ATT&CK for ICS, Mandiant, Recorded Future, ICS-CERT

Compliance Mapping

SOC operations map directly to regulatory framework controls:

FrameworkScopeSOC Mapping
IEC 62443Industrial automation securityZones, conduits, monitoring, incident response
NIST SP 800-82ICS security guideContinuous monitoring, access control, audit
NIS2 DirectiveEU critical infrastructureIncident reporting, risk management, supply chain
NERC CIPNorth American bulk electricElectronic security perimeter, monitoring, IR
MITRE ATT&CK ICSICS threat frameworkDetection coverage mapped to all 12 tactics
ISA-95 / PurdueOT network segmentationLevel-aware detection and response policies
← Back to cyberfabric.co