Support

CIP-015 / INTERNAL NETWORK SECURITY MONITORING

CIP-015 / Network Anomaly Detection

When something changes on your OT network, know what it means before it becomes a finding.

Industrial Defender turns internal network monitoring into a job you can get done:  
• Establish what's normal
• Catch what isn't
• Decide what matters
• Prove you handled it right

Watch the Brief DemoTalk to a Compliance Engineer
INTERNAL NETWORK SECURITY MONITORING

Why It's Different

1

Asset Context Prioritizes What Matters

Network visibility becomes more actionable when deviations are tied to asset criticality, risk, impact, anomaly type, and unknown or unauthorized devices.

2

Asset-centric, built into IDCM

Network anomalies are reviewed alongside the asset information, risk, events, baselines, and reporting workflows customers already use.

3

The full CIP-015 workflow, end to end

Monitor network activity, detect deviations, evaluate what needs action, and retain/protect the evidence needed to support compliance — not just pieces of it.

HOW IT WORKS

One Workflow, End to End

1
Scope

Define what must be monitored.

2
Baseline

Establish expected network behavior.

3
Detect

Identify deviations from normal.

4
Evaluate

Turn anomalies into prioritized decisions.

5
Retain

Retain the complete record.

CIP-015 requires documented processes for risk-based network data feeds, anomaly detection, and anomaly evaluation — with anomalous network data retained until the associated action is complete, protected against unauthorized deletion or modification, and generally retained for three calendar years.

The Industrial Defender Approach

The Job Isn't “Collect More Network Data.” It Answers Three Questions, Fast.

CIP-015 asks utilities to do more than watch traffic.

You need to define what should be monitored and why, notice when communication deviates from normal, decide whether that deviation is expected, benign, or a real problem, and keep a defensible record of how you handled it.

Most tools stop at detection. Analysts are left to manually chase down which asset this is, whether it's authorized, and whether it even matters.

That's hours per anomaly, multiplied across every substation and plant in your environment.

PROOF, NOT PROMISES

Why Utilities Choose Industrial Defender

85%
Reduction in NERC CIP audit prep time for one renewables leader
80%
Less compliance documentation effort for one Midwest utility
99%
Customer renewal rate
<10 weeks
Typical deployment, at less than half the cost of comparable platforms
The Industrial Defender Approach

Three Jobs Your Team is Hired To Do. One Workflow that Does All Three.

Network monitoring isn't the goal -- it's the input.

The real jobs are deciding what's worth attention and proving the decision was sound.

Industrial Defender builds all three into a single, asset-centric workflow inside IDCM, so your team isn't switching tools to get the job done.

Go Deeper

The Three Jobs

Monitor What Actually Matters

Learn normal asset-to-asset communication across ports, protocols, and traffic patterns, so you have a real baseline instead of a guess.

Prioritize What's Worth an Analyst's Time

See every deviation next to the asset's criticality, risk score, and configuration history, so you triage by consequence, not by alert volume.

Prove it Was Handled Correctly

Retain the anomaly, the reviewer, the rationale, and the disposition, so audit season is an export, not a scramble. Engineered by the team with decades of experience streamlining compliance  

The Industrial Defender Approach

One Path, From Learning Mode to Evidence.

Scope the assets and segments that need monitoring. Learn expected communication over a defined baseline period.

Detect new connections, unexpected ports or protocols, and unknown devices. Evaluate each deviation against asset criticality, configuration history, and vulnerability data to decide what it actually means.

Retain the complete, audit-ready record, from first detection through final disposition.

Five stages, one workflow, zero new tools to log into.

Go Deeper

Built on Active OT Collection, Not Guesswork

Network baselining is only as good as the visibility underneath it. Industrial Defender reaches Purdue Level 1 through native industrial protocols, so the baseline reflects what your assets are actually doing, not just what a span port happens to see.  

Choose the collection method that fits each environment, and mix them across your fleet without changing how anomalies are reviewed or reported.

Passive Monitoring

Traditional network taps and span ports for continuous, non-intrusive traffic visibility.

Active Collection (IDC)

Agentless, protocol-native queries that reach devices passive monitoring alone can't see.

Agent

A persistent, sub-1% CPU footprint for the deepest asset-level detail, with a portable option for air-gapped assets.

  See the Full Deployment Methodology →  
Before and After

From Alert to Answer

Most network monitoring tools can tell you something changed.  
Fewer can tell you whether that change is a problem worth your team's attention.

Without Asset Context

A new connection fires an alert. An analyst opens a second tool to identify the asset, a third to check its risk history, and a fourth to log the decision.  

By the time it's resolved, the moment that mattered has passed, and the evidence trail lives in four different places that someone has to reassemble come audit time.

With Industrial Defender

The same connection appears already linked to the asset's criticality, configuration history, and vulnerability status.  

The analyst sees what changed and what it means in one screen, and the decision, along with the reviewer, timestamp, and rationale, is retained automatically as part of the same record.

Before and After

See the Job Get Done

Real utilities, real environments, real audit cycles.
Here's what the workflow looks like once it's live in production.

Renewable Energy Leader Cuts Audit Prep Time by 85%

How one generation operator turned months of manual evidence-gathering into a repeatable, audit-ready process, without adding headcount to its compliance team.

Read the Case Study →

Midwest Utility Reduces Compliance Documentation by 80%

How a college-town utility standardized network and asset evidence across its entire CIP fleet, cutting the manual work behind every audit cycle.

Read the Case Study →
Details Matter

Go Deeper on the Details

Bring these into your next planning conversation with engineering or compliance.

Network Anomaly Detection for CIP-015

The full workflow, from baseline learning to audit-ready evidence, in one solution brief built for compliance and engineering stakeholders alike.

Read the Solution Brief →

Data Collection Methods Explained

How passive monitoring, active collection, and agents work together to reach Purdue Level 1, and how to choose the right mix for your environment.

Read the Solution Brief →

See How Other Utilities Are Getting This Job Done

Hear directly from peers tackling internal network monitoring, compliance, and OT visibility at our annual user summit, and see how they're putting this workflow to work in their own control rooms and substations.

Schedule a Live Demo