Annual Service: stay current on the automation incidents shaping risk across your sector.
Licensed PE · 20+ years tracked
A yearlong subscription combining one on-site day identifying automation failures, the ACS annual incident report, and year-round availability for questions and event notifications.

Identifying Automation Incidents Behind a 3% Productivity Opportunity at a Major Industrial Facility
Overview
A large industrial processing facility, representing approximately $1B in annual output, undertook a project to better understand unexplained downtime, inconsistent throughput, and recurring equipment issues. This engagement revealed that the most significant sources of operational loss were ICS automation issues, not cyberattacks.
Automation incidents are control system failures where the electronic communication from a computer or digital device is involved. These issues include out-of-calibration, inoperable sensors, misconfigured valves, and operator-interface blind spots. ACS data shows that across all critical infrastructure sectors, these incidents account for far more deaths, damage, and financial loss than cyberattacks, yet they are rarely identified or addressed systematically.
This project demonstrated that automation incidents can produce major operational losses, including an identified 3% degradation hit in net productivity at this billion-dollar facility.
Background: Hidden Weaknesses in Legacy Instrumentation
The facility relied on legacy process sensors and Windows-based HMIs, technologies common across critical infrastructure. As documented in industry research, these devices have known limitations:
- Many field instruments lack authentication, making them vulnerable to accidental misconfiguration, malicious manipulation, or spoofed sensor signals.
- Sensors frequently operate out of calibration or with incorrect zero/span settings, due to routine maintenance errors or sensor drift.
- HMIs refresh too slowly to detect fast-moving anomalies, meaning operators cannot see short-duration disruptions or high-frequency vibration patterns.
- Network-based monitoring cannot detect issues originating before data is converted to Ethernet packets.
These weaknesses create fertile ground for automation incidents: failures that look like "equipment problems" but are actually instrumentation and field device problems.
The Project: Raw Sensor Monitoring + Machine Learning
The facility deployed a monitoring system that tapped directly into raw, unfiltered electrical sensor signals, before they were converted into network packets or displayed on the HMI. Machine-learning models were trained to recognize normal operating behavior across pumps, valves, and process sensors.
During the learning period, the system immediately began flagging issues that had not been visible to operators:
- Sensors inoperable
- Sensors not calibrated
- Improperly ranged instruments
- Controller tuning errors
- Short-duration disruptions (<1 minute)
- Pressure drops indicating equipment degradation
- Air addition and other process anomalies missed by traditional logs
These findings aligned with broader industry observations that sensor drift, miscalibration, and maintenance mistakes are not commonly identified when monitored through traditional OT monitoring alone.
Operational Impact
Within hours of going live, the monitoring system began to identify multiple previously undetected issues affecting throughput, including sensor wiring problems, calibration issues, controller tuning errors, and pump-related disruptions.
The analysis found that these automation-incident drivers accounted for approximately 3% lost production opportunity at this facility producing around $1B annually. This identified opportunity represented tens of millions of dollars in potential additional output, not through capital expansion, but by addressing avoidable automation-incident losses. Field-related issues, which are typically instrument failure or improper ranging of scale, could also reduce nuisance alarms by 50%.
Cybersecurity Impact
Although the project focused on operations, it also strengthened cybersecurity:
- The raw-signal monitoring system detected spoofed HMI readings during a simulated man-in-the-middle attack, similar to Stuxnet.
- Because the system operated offline from IT/OT networks, it could continue functioning even when the Windows-based SCADA system experienced outages.
- The approach provided a physics-based validation layer, ensuring that network-level cybersecurity tools were not protecting untrusted or incorrect data.
This reinforced a key insight: automation-incident detection improves cybersecurity by ensuring the integrity of the physical signals themselves.
Key Takeaways
- Confirmation once again that most industrial harm comes from automation incidents, not cyberattacks. Joe's dataset of 30,000+ deaths and $100B+ in damage confirms this industry-wide reality.
- Legacy sensors are a major blind spot. They are often misconfigured or even offline, drift over time and lack authentication, creating silent failures.
- Machine learning on raw sensor data exposes issues operators cannot see. HMIs and historians miss fast anomalies and instrument drift.
- Identifying automation incidents revealed substantial financial upside. The project found a 3% production opportunity at this $1B facility, showing that these initiatives can uncover value, not just prevent loss.
- Operational reliability and cybersecurity are intertwined. Ensuring sensor integrity improves plant performance, maintenance, and cyber resilience.

What this service is.
The ACS Annual Service keeps critical-infrastructure operators current on the control system automation incidents that actually cause harm, the ones misdiagnosed as equipment failures across the industry. It combines hands-on, on-site work with year-round intelligence.
Each year includes one on-site day identifying automation failures in your critical infrastructure, the ACS annual incident report, and a view of how your organization compares to incidents in your industry and geography, plus notifications on incidents, responses, vendors, regulators, and insurers as they emerge.
It's grounded in the same engineering-led perspective as our workshop and in 20+ years of incident data, with reference to standards and reporting frameworks such as ISA/IEC 62443, NIST SP 800-82, CIRCIA, and NIS2, so your team can act on, and communicate, what the data shows.
How it works.
Intro Call
Understand your scope, systems, and priorities for the year.
Scoping & Onboarding
Set the engagement plan, on-site dates, and reporting cadence.
On-site Day
One on-site day identifying automation failures in your critical infrastructure.
Annual Report & Benchmarking
The ACS annual incident report, with how you compare to incidents in your industry and geography.
Quarterly Reviews
Regular check-ins that keep you current as new incidents and responses emerge.
Notifications & Availability
Year-round notifications and availability by phone and video for questions.
ACS isn't a cybersecurity vendor. We're engineering-led specialists in automation incidents, and the Annual Service turns 20+ years of incident data into a year-round advantage for your team.
Not a vendor
Not a product vendor or a cybersecurity firm, but engineering-led specialists in the automation incidents that harm critical infrastructure.
Engineering-led
Findings come from control system engineers who understand process behavior (sensors, actuators, control logic), not network generalists.
Largest dataset
Backed by 20+ years and the world's largest record of ICS automation incidents across critical-infrastructure sectors.
Non-punitive sharing
What we learn becomes trusted, non-punitive information sharing that lifts the whole sector.
Where the Annual Service fits.

Industry & compliance pain points
Automation incidents cause far more harm than cyber attacks across critical infrastructure, yet most organizations have no way to see them coming or to know how their own risk compares. Point-in-time assessments miss the pattern; the threat keeps moving.
Why this matters for critical infrastructure sectors
Across Oil & Gas, Utilities, Water, Chemical, and other sectors, the Annual Service benchmarks your exposure against real incidents in your industry and geography, so risk decisions reflect what's actually happening, not just what's been publicized.
Methods & standards referenced
Reporting and analysis reference ISA/IEC 62443, NIST SP 800-82, CIRCIA, and NIS2, and focus on Level 0–1 automation behavior: sensors, actuators, control logic, and setpoints, the layer where most incidents originate.
Annual Service by sector.
Questions about this service.
What's included over the year?
One on-site day identifying automation failures, the ACS annual incident report, industry and geographic benchmarking, quarterly reviews, and year-round notifications and availability by phone and video.
What affects the cost?
The subscription is scoped to your organization and systems. Contact us for pricing and to get started.
Does this replace our existing cybersecurity team?
No. It gives your engineering and security teams incident intelligence they can't get anywhere else; it complements your cybersecurity program rather than replacing it.
How is the Annual Service different from the workshop?
The workshop is a one-time training engagement. The Annual Service is an ongoing subscription that adds the annual report, benchmarking, quarterly reviews, and year-round availability.
Ready to talk about the Annual Service?
Tell us a little about your organization and we’ll follow up with next steps.
