Built in · Ozari Defend in early access

Cyber defence built into the control plane

Every Ozari deployment carries its own identity, audit and hardening. Ozari Defend adds sovereign, AI-native defence for the wider OT estate: AI agents triage at machine speed, and people authorise every response.

30+

Wind and solar farms hit in one day in Poland in December 2025.

CERT Polska, 2026

46

New vulnerabilities found in products from three leading solar inverter vendors.

Forescout, 2025

49%

Rise in ransomware groups targeting industrial organisations in 2025.

Dragos, 2026

12 hours

Deadline to report a significant cyber incident on Australian critical infrastructure.

CISC, SOCI obligations

In every deployment

Security that is part of the system, not added to it

These controls are part of Ozari Grid. They are not add-ons.

Identity

Role-based access, TOTP multi-factor authentication, OIDC single sign-on and per-account lockout.

Authenticated reads

In production, every read needs a session, including the live data stream.

Tamper-evident audit

A SHA-256 hash-chained, write-once log, streamed to your security analytics platform as syslog or CEF.

Encrypted field links

TLS and mutual TLS between the control plane and the protocol gateway.

Short supply chain

Zero third-party Go dependencies in the core, a software bill of materials and signed images.

Fault isolation

Vendor protocol stacks run outside the control plane, so a failing stack cannot stop it.

Fail-closed

With a broken audit chain, a full disk or stale data, Ozari stops and says why.

Offline licence

No call-home, so Ozari keeps working if you isolate the OT network.

Zones and conduits

Conforms to ISA/IEC 62443

Ozari conforms to the requirements of ISA/IEC 62443, built on zones and conduits, and is aligned to the control intent of NERC CIP. An evidence map lets your assessor trace each requirement to a test, a file or a setting.

  • ozari+ is designed to sit in the OT DMZ, fed by a one-way data diode.
  • The control plane never speaks raw field protocols. Gateways do, in their own zone.
  • The enterprise link is one-way: telemetry goes up, control never comes down it.

Ozari also follows NIST SP 800-82 for OT security, IEC 62351 for protocol security and secure-by-design practice. See every standard and practice.

Early access

Ozari Defend: sovereign, AI-native defence for OT

Defend runs in your environment, reads OT context and keeps a person in charge of every response. It learns from every confirmed incident.

  • Ingest Events from OT and IT sources.
  • Normalise To OCSF 1.8, including an OT event class.
  • Detect With rules mapped to MITRE ATT&CK for ICS.
  • Triage Four AI agents weigh indicators, context and a local language model.
  • Check Every proposed action passes a fixed policy gate.
  • Respond With CACAO playbooks. A person approves any OT action.
  • Learn Confirmed indicators and findings flow back into detection and triage.
  • Record Every decision on a Merkle-chained log.

Ozari Defend ships as a single-container appliance, with no cloud service needed at run time. The Ozari Base platform adds advisory OT threat detection, mapped to MITRE ATT&CK for ICS, and sends its findings to Defend in OCSF.

Where Defend is heading

Defence that improves itself, with people in charge

Plans, not promises. Each one keeps the same rule: the AI can propose, only people can approve.

Roadmap

Improvement agents

AI agents that propose new detections and playbooks as reviewable changes. People approve each one.

Roadmap

Defence at the edge

Small-model triage at the plant, with store-and-forward when links drop.

Roadmap

Federated learning

Share what was learned across sites without sharing raw data.

Roadmap

Post-quantum cryptography

Hybrid post-quantum key exchange and signatures, behind a crypto-agile layer.

Roadmap

Continuous attestation

Signed evidence for each control, mapped to NIST 800-53, IEC 62443 and Australian frameworks such as the ISM and Essential Eight.

Australian obligations

The rules, in plain English

Ozari cannot make you compliant. It can make the evidence easier to produce and the control room easier to isolate.

SOCI Act and CIRMP

Energy assets need a risk management program that meets a named cyber framework, such as the AESCSF. CISC guidance.

Incident reporting

Report significant cyber incidents on critical infrastructure to ASD within 12 hours, and relevant ones within 72 hours. CISC fact sheet.

Ransomware payments

Payments must be reported to ASD within 72 hours, under the Cyber Security Act 2024. Summary.

CI Fortify

ASD asks operators to be able to isolate vital OT for three months. On-premise, offline-licensed systems help. ASD guidance.

Start safely

Begin with a read-only shadow pilot

Ozari runs beside your current systems, sees the same data and issues no commands. You measure the value with your own data before anything changes.

Secret Link