No single operator can take down a grid, a network, or a pipeline.
Power grids, telecom backbones, and water treatment plants run on decades-old SCADA stacks where a stolen admin password can cascade into national-scale outages. DPSM enforces hardware-bound identities and quorum approval for every consequential command — Colonial Pipeline-class incidents become structurally impossible.
Where Critical Infrastructure breaks today
Cascading failures from stolen credentials
A single compromised SCADA login can issue dozens of breaker-open commands in seconds, faster than any human reviewer.
$4.4M — Colonial Pipeline ransom · DOJ, 2021
Vendor maintenance backdoors
Dial-in support channels and unverified vendor toolchains remain the leading initial-access vector for OT incidents.
62% — of OT intrusions begin via vendor remote access · Mandiant M-Trends, 2024
Insider command spoofing
Operators with legitimate access can issue catastrophic commands that look identical to routine work in unsealed logs.
NIS2 · NERC CIP — explicitly require non-repudiable command logging
Three patents, deployed against this industry's threat model
Each of Axowl's three filed patents maps to a specific structural failure mode in Critical Infrastructure. Together they form a single, end-to-end defense.
Hierarchical Distributed Trust Fabric — Substation (L1) · Regional SCADA (L2) · National HQ (L3)
Every breaker, every router, every pump carries a PUF identity at L1. Regional control rooms serve as L2; national operations and the regulator-mirrored archive serve as L3. A cascade-class command (e.g. open multiple substation breakers in coordinated fashion) requires k-of-n agreement, so a single compromised control room cannot trigger national impact.
Transition-Sealed Integrity System — Every breaker, every routing change, sealed
Each consequential transition — breaker open/close, BGP route change, voltage setpoint adjustment — is sealed in real time. Forensic teams can answer "who issued this command, from which device, when" with cryptographic certainty, replacing log-chain reconstruction that today takes regulators weeks.
Pre-grant LLM Conflict Verification — Toxic permission combinations blocked at grant time
A grant such as "operator A + close-all-breakers + bypass-confirmation" is detected as a toxic combination by the LLM gate and refused before it reaches a roster. Pre-commit conflict detection neutralizes the entire class of "single-operator catastrophic action" scenarios.
Deployment that fits the threat model
Most utility deployments begin at the Defense tier (TPM-anchored, software watchdog) and transition to Iron for the largest national operators where regulator-grade integrity is mandatory.
Recommended tier: T2 · Defense → T3 · Iron
Deployment path: AWS Nitro Enclave for control rooms · F2 (FPGA) for substation gateways
Operational detail: Day-1 deployment of the IRON sealed chain runs on AWS Nitro Enclaves in regional control rooms. Substation-side gateways receive F2-class FPGA appliances on a 72-hour cycle, with custom ASIC available for hardened field deployment.
Three concrete deployments
Power grid command authority
A breaker close-open command must be co-signed by an L2 regional supervisor and at least one L3 national observer, eliminating single-operator cascades.
Telecom BGP route protection
Each BGP advertisement at the edge is sealed by the router's L1 PUF; spoofed routes from a compromised admin workstation are rejected at the carrier core.
Water treatment safety interlocks
Chemical dosing setpoints carry a sealed grant chain. A poisoned-input scenario (e.g. Oldsmar 2021) is structurally blocked because the dosing PLC will not accept any setpoint without a fresh k-of-n authorization.
Versus what's deployed today
Today — SCADA + bastion-host VPN
Once an attacker reaches the bastion, command authority is delegated by trust, not by hardware. Logs are kept on the same systems an attacker has compromised.
With DPSM — Axowl DPSM
Authority is never delegated by trust — it is enforced by hardware quorum. Logs are sealed at IRON grade and mirrored to a regulator-readable L3 region the operator cannot reach.
Standards & regulatory frameworks aligned
- NERC CIP-005 / -007 / -013
- FERC Order 706
- EU NIS2
- TSA Pipeline SD02C
- IEC 62351
- ENISA OT Guidelines