Nestack Agent Care
Industries / Manufacturing / OT security agent

Manufacturing AI agent · OT & ICS security

OT & ICS Security-Monitoring AI Agent

Inventory the OT estate without probing it, triage each advisory against the models actually installed and actually reachable, and hold every proposed change for a named controls engineer.

4–6 weeksTypical delivery
Your stackDeployment
Read-onlyEngineer signs
Agent CareAfter launch

What this agent does

Triages the advisory, not the device

In
01

A device appears in a passive capture, and it is added to the inventory with the record that saw it.

02

An advisory lands, and it is matched to the models installed, at the firmware vendor identification gives.

Reason
03

A matched advisory has no vendor fix, and it is flagged as such, with a compensating control drafted.

04

A device's exposure is read from firewall rules and documented conduits, never from a probe on a live segment.

05

An anomaly is seen, and it is correlated against the maintenance calendar before anyone calls it an intrusion.

Decide
06

A NIS2 duty is asserted, and it is read against Annex II of Directive (EU) 2022/2555 — not every plant is in it.

07

A change touches safety-related software, and it is drafted only; Regulation (EU) 2023/1230 applies 20 January 2027.

Out
08

A notification falls due, and the draft goes with its deadline to the accountable person who signs and sends.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent triages and drafts; a named controls engineer decides what changes, and the plant manager owns any halt to production.

Example workflow

One advisory, feed to disposition

AgentHuman
1Advisory receivedCISA ICS advisory, vendor bulletin, CVE feed or supplier notification
2Assets matchedModels, firmware, zone and reachability, each with the record it came from
3Exposure assessedAffected assets, the exposure path, any vendor fix and confidence
4Controls appliedInventory-freshness checks, zone and conduit rules, no-fix flags and confidence threshold
No human action required

Stages 1 to 4 run unaided, and nothing is touched at any of them — the agent is reading records, and the engineer's lane opens at the confidence gate.

5DecisionBranches at the confidence threshold
High confidence

Goes to the controls engineer to rule on.

Low confidence

Adds an OT security read first.

Engineer disposition

The case is held with its matched assets, its exposure path and the confidence.

Accept · Amend · Send to OT security review
Dispositioned — sent to change control
6Ticketing systems updatedOnly where write access and approval policy allow it
7Outcome evaluatedMatch accuracy, exposure findings, dismissed advisories and post-window corrections
Amendments

Every amendment made at disposition is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Writing to a controller, drive or safety device.
Active-scanning or probing a live OT segment.
Isolating a device, a cell or a network segment.
Deciding to halt or resume production.
Automation boundaryAgent acts unaided
Inventory OT assets from passive capture, exports and the CMDB.
Match each advisory to the model, firmware and zone on record.
Read exposure from firewall rules and documented conduits.
Flag what the engineer should weigh, and hold the case.
Any write happens inside the boundaries agreed at implementation, never against an OT device.
Signing the CRA report due from 11 September 2026.
Judging an incident significant under NIS2 Art. 23(3).
Accepting or waiving a documented exposure.
Changes to escalation criteria, zones or thresholds.

Example output

One advisory, annotated

Everything the agent triages is attached to the record it was drawn from.

Triage output · single advisoryIllustrative example
Advisory
Matched asset
Firmware on record
Exposure path
Confidence
Vendor fix
Vendor ICS bulletin
Two drives in Cell 4 match the affected model family
v2.011
Reachable from jumphost
89%
No vendor patch available
As receivedTaken from the passive capture and the vendor bulletin on file — nothing on this side is inferred by the agent.
Evidence used Passive capture record Engineering project file Firewall rule extract
Why this dispositionThe model is installed and reachable, and no fix exists and a person still decides.
ActionAcceptAmendSend to OT security review
What the score decidesBelow the configured threshold the case picks up an OT security read first.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every advisoryFrom the asset record
03Triage

Triage against the record

Draw on the passive inventory on file and the zones and conduits documented for the plant.

01Approved path

Looking can stop the line

Ordinary network traffic left two pump controllers unresponsive at Browns Ferry in 2006 — NRC Notice 2007-15.

02Human review

Rank by reach, not by severity

On Dragos's 2025 data most advisories warrant no immediate action, so the read starts where a device is reachable.

04Build an evidence trail

The advisory, the asset it was matched to and the engineer who ruled on it stay on the record.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

OT monitoringDragos · Claroty
Nozomi · Armis
Advisory feedsCISA ICS · CVE
Vendor PSIRT bulletins
Asset and config recordsCMDB · asset register
Engineering project files

Agent

OT & ICS security monitoring

Reads the estate
Triages the advisory
Holds for the engineer

Ticketing and responseServiceNow · Jira
SIEM · SOAR case tools
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers between the model and the plant

Each of the six wraps the one it contains. What none of them stops is set out in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeStep drafting back to asset listing when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt, escalation-criteria and zone-configuration changes.Track
L4TraceabilityRecord the assets, the advisory, the exposure path, the amendments and the disposition.Record
L3Engineer dispositionHold cases for the named engineer; it governs what is proposed, not whether the inventory is complete.Gate
L2Policy guardrailsTest cases against configured zones, conduits and no-fix rules; a failure returns the case.Restrict
L1Confidence thresholdsRoute low-confidence matches to an OT security read before the engineer sees them.Require review
Model coreCase drafted — matched assets, exposure path, any vendor fix and confidence
L1 – L2Test whether a case may stand
L3Puts the ruling in an engineer's hands
L4 – L5Keep the advisory and the asset behind it
L6Steps back to asset listing when signals degrade

How Nestack evaluates it

Evaluate the whole triage — not only the final disposition.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the case the engineer reads
Depth of coverage ▼
E1Final-output evaluationDid every matched asset trace back to an inventory record?
E2Step-level evaluationDid the agent use the right firmware, zone and conduit documentation?
E3Tool evaluationDid it read the correct asset record and the correct advisory?
E4Confidence calibrationDo low-confidence matches actually attract more amendments?
E5Slice evaluationHow does performance change across specific cells and zones?
E6Business outcomeHow many cases needed an amendment, or a correction after the window had closed?
Floor — the exposure the plant answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, placed at the stage each one originates.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
OT-03

Stale asset inventory

Models read from an export taken before the retrofit.

Stage gathersAsset records, advisories, zones and firewall rules
02 · Reasoning2 modes
OT-04

Banner-read firmware

A version parsed from a banner, not vendor identification.

OT-06

No fix read as no risk

An advisory without a patch is dismissed as not actionable.

Stage proposesMatched assets, the exposure path and confidence
03 · Tool / write2 modes
OT-02

Draft left unread

A queued notification sits past the deadline it carried.

OT-05

Duplicate zone name

Two sites share a cell name and the match lands wrong.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
OT-01

Anomaly read as a fault

An intrusion indicator is classified as a process fault.

Stage returnsThe case the engineer rules on and change control sees
05 · Change / Version1 mode
OT-07

Silent criteria drift

A tuning change quietly widens what the agent dismisses.

Stage tracksModel, prompt, escalation criteria and zone config
Sev-1 · agent touches a live OT device Sev-2 · a real exposure is ruled out Sev-3 · source degrades, case routes to review

Affected slices

Plant-wide coverage can hide one cell

A plant-wide patch percentage can look acceptable while a small number of cells carry most of the untriaged exposure. Nestack reports the amendment rate by slice, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Legacy cells with no capture9.6%3.7× Review
Remote-access endpoints6.8%2.6× Review
Vendor-managed skids4.4%1.7× Watch
Standard monitored cells2.4%0.9× Normal
Bar: amendment-rate lift vs. standard-cell baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

Nothing closes until a test exists

The loop shuts when the missed exposure is a regression case, not when it has been explained. That suite is what the next advisory triaged is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Amendment rate rises in a cell slice.

02Diagnose

The advisory that named a controller nobody could find is traced through records, never the wire, to one cause.

03Improve

Any change goes out numbered, and the advisories that caused it are attached.

04Verify

The release waits on the touched advisory cases clearing a second run.

05Learn

One case added to the suite, one line added to the asset record.

Learn → DetectThe return edge. The next advisory is triaged against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, triage workflow, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01OT asset discovery and monitoring boundary definition.
02Passive-source and feed assessment.
03Zone, conduit and escalation-criteria mapping work.
04Asset-record ingestion and normalisation.
05Advisory matching and exposure logic.
06Confidence scoring and case routing.
07Engineer disposition workflow.
08Monitoring and ticketing integration.
09Advisory and exposure cases.
10Guardrails and escalation controls.
11Asset-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne cell, one site ProductionProduction OT monitoring AdvancedMultiple sites / estates
Introduced at Pilot
Triage to your assets and zones
Engineer disposition
Inventory-coverage baseline
Introduced at Production
Reporting by cell
Disposition workflow in your systems
Approved ticket write-back
Passive-collector integration
Introduced at Advanced
Multi-zone segmentation rules
Multi-stage change approvals
High advisory volume
Multi-site segmentation controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your asset register and zone drawings Asset-record ingestion and zone mappingWeek 1
02Representative advisories already triaged Triage baseline, exposure logic and asset bindingWeek 2
03Your written escalation criteria Zone, conduit and escalation-rule mappingWeek 1
04Access to relevant APIs, feeds or exports Passive-source and feed assessment, then integration setupWeek 2
05Exposures you would not want dismissed Incident cases and failure-mode testingWeek 4
06What no triage may assume Confidence scoring, case routing, guardrails and escalation controlsWeek 3
07A named controls engineer to rule on cases Engineer disposition workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

The chart follows the plant rather than the slide, so evaluation and pilot both land in week 5.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1OT discovery, zone mapping and the automation boundary W2Passive-source integration and the triage baseline W3Triage workflow, confidence logic and disposition controls W4Evaluation suite, exposure checks and failure-mode testing W5Ticketing integration, pilot advisories and targeted corrections W6One patch window run under the controls engineer, then Agent Care handover
Reading the bandEach band covers only the weeks its work is named in. The week 5 overlap is real, not padding.
At the end of W6Once the window validates, Agent Care owns the running agent.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Manufacturing AI agent

Build an OT triage agent around your controls engineer's authority.

In OT, looking can stop the line, so nothing here touches a device. Show us your cells, your advisory backlog and the engineer who signs a change, and we'll set the boundary.

Nestack Agents · OT & ICS security monitoringAGT-MFG-15 · Agent Care available after launch