If you can't trust what you measure, you have no safety or cybersecurity: The need for Immutable Situational Awareness

If you cannot trust what you measure, you cannot trust your situational awareness

Resilience, safety and cybersecurity all depend on accurate situational awareness. If you cannot trust what you measure or what is displayed to the operator, there is no reliable situational awareness and, consequently, no assurance of safety, reliability or resilience.

Process sensors are engineering devices. Most have no cybersecurity, authentication or cyber-forensic capabilities, and their measurements are inherently trusted by the control systems that use them. The default is trust.

I have been involved with process sensors for more than 40 years, and with the cybersecurity of process sensors for almost 30 years. In the early 1990s, my focus on process-sensor problems was driven by unintentional erroneous measurements that affected operator decisions in nuclear plants, and that resulted in significant consequences. I have become increasingly concerned about a fundamental gap in critical-infrastructure reliability, safety and cybersecurity: erroneous process-sensor data, whether caused by unintentional failures or malicious manipulation, can produce erroneous displays for operators and erroneous inputs to control systems. The result can be incorrect operator actions or direct damage to field equipment.

Real cases

In the mid-1970s, a manufacturing-line flaw in nuclear safety process sensors created a failure mode that could not be detected by the testing then being performed. Sensors containing the flaw contributed to significant nuclear-safety problems. The failure mode could have been identified by independently monitoring the physics of the sensor, but that technology did not yet exist.

In 2008, erroneous sensor readings contributed to a SCADA system’s providing control signals that overfilled a reservoir and led an earthen dam to collapse. Independent monitoring of the process sensors could have identified a change in sensor response. In this case, a failure of the sensor attachments caused the level sensors to provide erroneously low-level readings that were acted upon by the SCADA system.

In 2010, Stuxnet employed a man-in-the-middle technique to provide operators with misleading process information while the physical process was being manipulated. Independent monitoring of the process sensors could have identified a discrepancy between the actual process measurements and the information being presented to the operators.

In 2022, we conducted a productivity study at a billion-dollar manufacturing facility after plant personnel reported that they did not trust the information displayed on their HMIs. The study found that the HMIs did not identify multiple sensor failures or malfunctioning main feed pumps. The sensor and feed-pump problems were associated with an estimated 3% loss in net productivity. The work was subsequently documented in IEEE Computer, “Using Machine Learning to Work Around the Operational and Cybersecurity Limitations of Legacy Process Sensors.”

More recently, the problem has become even more apparent. In April 2026, a nuclear plant experienced frozen turbine control system displays and suppressed alarms while pressure was increasing, ultimately leading to a forced shutdown.

Water systems present the same fundamental problem. In one recent incident, a water SCADA system froze while reporting that a storage tank was full. The actual tank level continued to fall, but the control system did not recognize the change and therefore did not start to replenish the tank. The tank eventually reached a level that caused the plant to shut down, resulting in loss of water pressure and a boil-water notice.

On Aug. 18, 2026, CISA's Matthew Rogers stated that threat actors cyberattacking water systems were actively modifying PLC project files to disable alarms in ways that might not be immediately apparent to operators. It remains unclear how many water SCADA systems have experienced compromised displays or otherwise unreliable operator information. Good cyber hygiene will not restore trust in operator displays that are wrong.

The common thread: incorrect situational awareness

In these cases, monitoring the process sensors at the physics level could have identified that the reported process condition did not agree with the actual physics which would have been an indication that the control system or operator displays could no longer be trusted.

It is not technically feasible to prevent every cyberattack, equipment failure, configuration error, communications failure or other unintentional SCADA incident. The critical question is therefore not simply whether the network is secure, but whether the operator can determine the actual condition of the physical process when the control system itself may be unreliable.

This is particularly important because process-sensor inputs to PLCs are inherently trusted. A PLC can execute its logic exactly as designed and still produce an unsafe result if the sensor information provided to it is wrong. There have been multiple water-system failures in which erroneous sensor readings caused PLCs to take inappropriate actions that resulted in inadvertent damage.

The same fundamental issue exists with protective relays monitoring electric equipment.

Independent process ground truth

Immutable Situational Awareness, LLC has developed process-sensor monitoring technology specifically to address this gap.

Get your subscription to Control's tri-weekly newsletter.

The Immutable Situational Awareness technology independently monitors process sensors at the physics level and provides an independent representation of the physical process. It has been demonstrated for years at one of the most sensitive government industrial facilities, providing independent situational awareness without relying on the facility's control system communications.

Following a pilot project, the technology is now being deployed in electric and water utilities associated with the environment in which Volt Typhoon activity was first identified. This approach provides independent situational awareness regardless of whether Volt Typhoon, Salt Typhoon, another cyberattack, equipment failure or an unintentional control-system problem is responsible for the loss of trustworthy process information.

The Immutable Situational Awareness monitoring system is not connected to the OT network. It therefore does not depend on the availability or trustworthiness of the OT network, HMIs, historians, PLC communications or other control-system communications. Instead, it provides an independent ground-truth reference against which the control system's representation of the physical process can be compared.

This creates a fundamentally different layer of defense. The objective is not to replace existing process sensors, PLCs, protective relays, or OT cybersecurity. It is to independently determine whether the process information being presented to the operator and used by equipment remains trustworthy. The technology is software-based and can be applied across multiple critical infrastructure sectors. Because it does not require connection to the OT network, it can be deployed without modifying field equipment, control system networks, or existing operator interfaces.

A particularly important application is testing the system under conditions that can defeat conventional cybersecurity assumptions: Manipulated PLC or IED logic, suppressed alarms, erroneous sensor values, process-sensor communication failures and other conditions in which the operator's displayed process information becomes unreliable.

Process-sensor integrity remains a significant gap in existing government and industry cybersecurity guidance. Network security can protect communications, but it cannot independently determine whether pressure, temperature, flow, level or other physical measurements are correct or whether the information being presented represents the physical process. Most process sensors do not authenticate the measurements they produce, and the equipment using those measurements generally has no independent means of determining whether they are correct.

Similarly, consequence-based approaches to cybersecurity do not by themselves provide an independent measurement of whether the physical process agrees with the information presented by the control system.

Seeking end-users

Immutable Situational Awareness is seeking critical-infrastructure end-users interested in deploying and evaluating this technology under normal operating conditions and against controlled scenarios involving compromised or malfunctioning control systems.

A pilot deployment can monitor approximately five to seven process sensors for 90 days. The objective is to demonstrate independent process ground truth under actual operating conditions and establish a repeatable methodology for rapid deployment across the critical-infrastructure community.

Summary

The fundamental issue is simple: If you cannot trust what you measure, you cannot trust your situational awareness. Without trustworthy situational awareness, there can be no assurance of safety, reliability, resilience or cybersecurity. Russia, China and Iran understand this. Cyber defenders and reliability and safety engineers need to understand it too.

About the Author

Joe Weiss

Cybersecurity Contributor

Joe Weiss P.E., CISM, is managing partner of Applied Control Solutions, LLC, in Cupertino, CA. Formerly of KEMA and EPRI, Joe is an international authority on cybersecurity. You can contact him at [email protected]

Sign up for our eNewsletters
Get the latest news and updates