Incident Identification Workshop: recognize the control system incidents you've been writing off as equipment failures.
Licensed PE · 20+ years tracked
An on-site, train-the-trainers workshop that helps your operations and security teams recognize, classify, and communicate control system incidents that are actually cyber-related, delivered by control system experts, not network-security responders.

Urban Utility and the Hidden Risk of Non-IP ICS Failures
Background
An important urban utility with a strong reputation for reliability contacted ACS after its largest plant shut down because of an electronic connection to one of its vendors. The utility's vendor required the connection to maintain its warranty on critical infrastructure and also to address the security requirements of the North American Electric Reliability Corporation's (NERC's) Critical Infrastructure Protection (CIP). The utility needed a practical way to resolve the immediate issue while strengthening reliability and security policies across both electric and water operations.
The Challenge
The broader challenge was not simply an IP-network cybersecurity problem. ACS, led by Joe Weiss, brought specialized expertise in non-IP industrial control system (ICS) failures: events in which control systems or the physical processes they manage are affected unrelated to the kinds of IP-network cyberattacks that dominate most security and safety thinking and planning. Weiss has tracked these incidents for more than 20 years. He has catalogued control-system and process-impacting events causing tens of thousands of fatalities and more than $100 billion in damage, while showing that virtually all of the most consequential incidents did not involve the IP-network attack paths on which industry and government have focused so much attention.
This created a strategic insight for the utility and for the industry more broadly: organizations had been investing heavily in the visible problem of network cybersecurity while missing the engineering-based, physics-based, non-IP failure modes that create real-world consequences. In short, the industry was solving the wrong problem, or at least a very incomplete one.
ACS Approach
ACS helped the utility as a subject matter expert develop security and safety policies for its electric and water operations and reframe the problem around operational impact rather than network exposure alone. Working with a division of the Department of Defense, ACS helped establish a joint working relationship with BWP on a class of control-system risk with damaging physical effects not present in conventional IP-network attacks. This collaboration evolved into the utility becoming one of only two utility test sites in the United States and later expanded into a control-system security and safety testbed.
ACS worked collaboratively with the utility to encourage its vendors to test their products at the site. This helped move the discussion beyond compliance and into practical validation of control-system behavior under realistic operating conditions. ACS also supported the utility in addressing supply-chain and assurance concerns when software for a new distribution SCADA system originated from outside the traditional Western software ecosystem.
Results and Impact
The collaboration produced results well beyond the utility's immediate operational needs. It contributed to industry awareness of this persistent class of control-system risk through press coverage, presentations at ICS conferences, and a television special. More importantly, the work demonstrated how utilities can use engineering expertise, operational testing, and control-system incident history to identify risks that conventional cybersecurity programs overlook.
Key Lesson
The experience of this utility illustrates why ICS cybersecurity must include more than IP-network defenses. The most consequential failures arise instead from control logic, instrumentation, timing, vendor dependencies, engineering assumptions, physics-layer behavior, and other non-IP pathways. ACS helped this utility address these risks by applying more than two decades of control-system incident analysis to their real operational environment. The result was a stronger, more realistic view of security: one grounded not only in networks, but in the physical systems that keep critical infrastructure running.

What this service is.
Most organizations have already had control system incidents; they were just diagnosed as equipment failures. The Incident Identification Workshop is an on-site, train-the-trainers engagement that helps cross-functional teams recognize when a control system event is actually cyber-related, at Level 0 and Level 1, below the IP network layer where most monitoring never reaches.
It's delivered by control system experts who identify incidents as cyber-related, not network-security responders. Working through real cases involving sensors, actuators, control logic, calibration, setpoints, and HMI behavior, your team learns to separate automation incidents from network cybersecurity incidents and to find the root cause.
Findings are connected to the standards and reporting frameworks that govern them: ISA/IEC 62443, NIST SP 800-82, and regimes such as CIRCIA and the EU's NIS2, so the same event can be communicated to engineers, executives, and regulators without being lost in translation.
How it works.
Intro Call
Understand your scope, systems, and the events prompting the engagement.
Scoping & Scheduling
Agree the agenda, participants, and on-site dates; finalize the engagement plan.
On-site Delivery
A hands-on, train-the-trainers day working through real incidents with your team.
Report & Recommendations
Documented findings, root-cause patterns, and the gaps to close.
Follow-up
Availability for questions as your team applies what they learned.
ACS isn't a cybersecurity vendor. We're engineering-led specialists in the automation incidents that actually harm critical infrastructure, and this workshop puts that perspective directly in your team's hands.
Not a vendor
Not a product vendor or a cybersecurity firm, but engineering-led specialists in the automation incidents that harm critical infrastructure.
Engineering-led
Findings come from control system engineers who understand process behavior (sensors, actuators, control logic), not network generalists.
Largest dataset
Backed by 20+ years and the world's largest record of ICS automation incidents across critical-infrastructure sectors.
Non-punitive sharing
What we learn becomes trusted, non-punitive information sharing that lifts the whole sector.
Where the Incident Identification Workshop fits.

Industry & compliance pain points
Serious control system events are routinely misclassified as equipment failures, so the cyber-related root cause is never found, and never reported. That leaves organizations exposed to repeat incidents and out of step with reporting obligations such as CIRCIA and NIS2, because you can't report what you never identified.
Why this matters for critical infrastructure sectors
In Oil & Gas, Utilities, Water, Chemical, and other critical-infrastructure sectors, the consequences are physical: safety, uptime, equipment, productivity, and public services. Recognizing automation incidents protects the process, not just the network.
Methods & standards referenced
The workshop draws on ISA/IEC 62443 and NIST SP 800-82, maps findings to reporting frameworks including CIRCIA and NIS2, and focuses on Purdue Levels 0–1: sensor and actuator integrity, control-logic and setpoint manipulation, calibration, and HMI behavior.
Incident Identification Workshop by sector.
Questions about this service.
How long does the workshop take, and what does delivery look like?
It's delivered on-site as a train-the-trainers session with a cross-functional group from operations and security, working through real incidents together.
What affects the cost?
Scope drives it: plant size, number of systems, participants, and travel. Contact us for a quote tailored to your site.
Does this replace our existing cybersecurity team?
No. The workshop makes your operations and security people better at recognizing control system incidents that are actually cyber-related. It complements your cybersecurity function; it doesn't replace it.
How is the workshop different from the Annual Service?
The workshop is a one-time, on-site training engagement. The Annual Service is a yearlong subscription that adds the ACS annual incident report, industry benchmarking, quarterly reviews, and year-round availability.
Ready to talk about the Incident Identification Workshop?
Tell us a little about your organization and we’ll follow up with next steps.
