Built in · Ozari Defend in early access
Cyber defence built into the control plane
Every Ozari deployment carries its own identity, audit and hardening. Ozari Defend adds sovereign, AI-native defence for the wider OT estate: AI agents triage at machine speed, and people authorise every response.
12 hours
Deadline to report a significant cyber incident on Australian critical infrastructure.
In every deployment
Security that is part of the system, not added to it
These controls are part of Ozari Grid. They are not add-ons.
Identity
Role-based access, TOTP multi-factor authentication, OIDC single sign-on and per-account lockout.
Authenticated reads
In production, every read needs a session, including the live data stream.
Tamper-evident audit
A SHA-256 hash-chained, write-once log, streamed to your security analytics platform as syslog or CEF.
Encrypted field links
TLS and mutual TLS between the control plane and the protocol gateway.
Short supply chain
Zero third-party Go dependencies in the core, a software bill of materials and signed images.
Fault isolation
Vendor protocol stacks run outside the control plane, so a failing stack cannot stop it.
Fail-closed
With a broken audit chain, a full disk or stale data, Ozari stops and says why.
Offline licence
No call-home, so Ozari keeps working if you isolate the OT network.
Zones and conduits
Conforms to ISA/IEC 62443
Ozari conforms to the requirements of ISA/IEC 62443, built on zones and conduits, and is aligned to the control intent of NERC CIP. An evidence map lets your assessor trace each requirement to a test, a file or a setting.
- ozari+ is designed to sit in the OT DMZ, fed by a one-way data diode.
- The control plane never speaks raw field protocols. Gateways do, in their own zone.
- The enterprise link is one-way: telemetry goes up, control never comes down it.
Ozari also follows NIST SP 800-82 for OT security, IEC 62351 for protocol security and secure-by-design practice. See every standard and practice.
Early access
Ozari Defend: sovereign, AI-native defence for OT
Defend runs in your environment, reads OT context and keeps a person in charge of every response. It learns from every confirmed incident.
- Ingest Events from OT and IT sources.
- Normalise To OCSF 1.8, including an OT event class.
- Detect With rules mapped to MITRE ATT&CK for ICS.
- Triage Four AI agents weigh indicators, context and a local language model.
- Check Every proposed action passes a fixed policy gate.
- Respond With CACAO playbooks. A person approves any OT action.
- Learn Confirmed indicators and findings flow back into detection and triage.
- Record Every decision on a Merkle-chained log.
Ozari Defend ships as a single-container appliance, with no cloud service needed at run time. The Ozari Base platform adds advisory OT threat detection, mapped to MITRE ATT&CK for ICS, and sends its findings to Defend in OCSF.
Where Defend is heading
Defence that improves itself, with people in charge
Plans, not promises. Each one keeps the same rule: the AI can propose, only people can approve.
Roadmap
Improvement agents
AI agents that propose new detections and playbooks as reviewable changes. People approve each one.
Roadmap
Defence at the edge
Small-model triage at the plant, with store-and-forward when links drop.
Roadmap
Federated learning
Share what was learned across sites without sharing raw data.
Roadmap
Post-quantum cryptography
Hybrid post-quantum key exchange and signatures, behind a crypto-agile layer.
Roadmap
Continuous attestation
Signed evidence for each control, mapped to NIST 800-53, IEC 62443 and Australian frameworks such as the ISM and Essential Eight.
Australian obligations
The rules, in plain English
Ozari cannot make you compliant. It can make the evidence easier to produce and the control room easier to isolate.
SOCI Act and CIRMP
Energy assets need a risk management program that meets a named cyber framework, such as the AESCSF. CISC guidance.
Incident reporting
Report significant cyber incidents on critical infrastructure to ASD within 12 hours, and relevant ones within 72 hours. CISC fact sheet.
Ransomware payments
Payments must be reported to ASD within 72 hours, under the Cyber Security Act 2024. Summary.
CI Fortify
ASD asks operators to be able to isolate vital OT for three months. On-premise, offline-licensed systems help. ASD guidance.
Start safely
Begin with a read-only shadow pilot
Ozari runs beside your current systems, sees the same data and issues no commands. You measure the value with your own data before anything changes.