Control System Automation Incidents: A Different Category from Cybersecurity
ACS documents the automation incidents that harm critical infrastructure, the ones misdiagnosed as equipment failures, not cyberattacks.

Where the incidents originate
ACS isn’t a vendor or a cybersecurity firm.
ACS is the originator of a new category, automation incident intelligence, built on the world’s largest record of the automation failures that actually harm critical infrastructure.
Automation vs. cybersecurity
Automation Incident
Sensors, actuators, control logic, calibration, and setpoints: engineering causes that change how the physical process behaves.
Engineering-led investigation
Network Cybersecurity Incident
Malware, ransomware, credentials, and remote access: unauthorized or malicious activity through networks.
Cyber incident response
Focused help for critical infrastructure.
Annual Service
Request informationAutomation incident intelligence, by sector.
Oil & Gas
Utilities
Water & Wastewater
Chemical
Manufacturing
Transportation
Nuclear
Food & Beverage
Pharmaceutical
Joe Weiss, Managing Partner, Applied Control Solutions.
Joe Weiss was among the first to name the automation-versus-cyber misclassification gap, the reason serious control system events are filed as equipment failures and never investigated as cyber. Over more than 20 years he built the incident dataset that documents it, working from the engineering realities of operational technology rather than an IT-security playbook. That perspective is what makes ACS’s authority founder-led, not certification-led.
How ACS differs from cybersecurity firms and SOAR vendors: an engineering-led perspective built on two decades of incident data.
Not a vendor
Not a product vendor or a cybersecurity firm, but engineering-led specialists in the automation incidents that harm critical infrastructure.
Engineering-led
Findings come from control system engineers who understand process behavior (sensors, actuators, control logic), not network generalists.
Largest dataset
Backed by 20+ years and the world's largest record of ICS automation incidents across critical-infrastructure sectors.
Non-punitive sharing
What we learn becomes trusted, non-punitive information sharing that lifts the whole sector.
Control system automation incidents, explained.

Most serious control system events are not cyberattacks. They are automation incidents: failures in sensors, actuators, control logic, calibration, setpoints, timing, and engineering decisions that change how a physical process behaves. ACS has tracked these for more than 20 years, across every critical-infrastructure sector, in what is now the world’s largest record of ICS automation incidents.
ICS safety vs. cybersecurity
Cybersecurity, SOAR, and incident-response programs are built to find unauthorized activity on networks: malware, ransomware, stolen credentials, remote access. That work matters, but it looks at the wrong layer for most control system harm. The events that injure people and take plants offline usually originate at Level 0 and Level 1, the sensors, actuators, and controllers below the IP network, where security monitoring rarely reaches. An event there can look identical to an equipment failure, so it is filed as one, and the cyber-related root cause is never found.
The scale is easy to underestimate. ACS’s incident research links control system events to more than 30,000 deaths and over $100B in direct impacts worldwide, with millions of devices connected directly to the internet. Very few were cyberattacks, which is exactly why they go unnamed.
Level 0 / Level 1 risk
Recognizing an automation incident is an engineering problem before it is a security problem. It takes people who understand process behavior: how a setpoint change, a mis-calibrated sensor, or manipulated control logic propagates into the physical world. ACS maps findings to the standards that govern them, ISA/IEC 62443 and NIST SP 800-82, and to reporting regimes such as CIRCIA and the EU’s NIS2, so the same event can be communicated to engineers, executives, and regulators.
This is what the Incident Identification Workshop teaches teams to do, and what the Annual Service keeps them current on across their sector. It is a different discipline from cybersecurity: automation incident intelligence. It is the category ACS created.
Common questions.
How is an automation incident different from a cyber attack?
An automation incident is a control system failure whose root cause is engineering (sensors, actuators, control logic, calibration, or setpoints), not an attacker on the network. A cyber attack is unauthorized activity through networks, credentials, or malware. Most control system harm comes from the former, and is routinely misread as equipment failure.
Why do organizations misclassify these incidents?
The operators who first notice a process anomaly have the domain knowledge to see something is wrong, but aren't trained to think “cyber.” Security teams are trained to think “cyber” but don't know what normal process behavior looks like. Naming an event “cyber” can also trigger reporting and restart delays, so the default is “equipment failure.”
What does the Incident Identification Workshop cover?
It's an on-site, train-the-trainers workshop that teaches cross-functional teams to recognize, classify, and communicate control system incidents that are actually cyber-related, working through real cases at Level 0 and Level 1, and mapping findings to standards like ISA/IEC 62443 and reporting regimes like CIRCIA and NIS2.
How much does the Annual Service cost?
Pricing is based on the size of your organization. Contact us for a quote. The Annual Service combines one on-site day identifying automation failures, the ACS annual incident report, industry and geographic benchmarking, quarterly reviews, and year-round availability by phone and video.
Does ACS replace our cybersecurity team?
No. ACS makes your engineering and security teams better at recognizing the control system incidents that are actually cyber-related. It complements your cybersecurity program; it doesn't replace it.
Is incident data shared confidentially and non-punitively?
Yes. ACS turns what it learns into trusted, non-punitive information sharing that helps the whole sector improve, without exposing the organizations involved.
Talk to an expert about your systems.
Objections resolved? Tell us a little about your organization and we’ll follow up with next steps.
