Tech Paper

Modernize Without Compromise

Published: 09/11/2026

Executive summary

The industrial world is modernizing. Operators of pipelines, power grids, refineries, water systems, oil and gas onshore fields and offshore platforms, upstream and midstream plants, and other facilities are connecting decades-old control systems to sensors, analytics, and AI to run more autonomously. This shift, powered by IIoT, with technologies that include Agora™ edge AI and IoT solutions, is no longer optional—it is becoming the basis of competitiveness across the energy and industrial sectors.

At the same time, the systems that run physical operations, IACS, SCADA, APC, and DCS, have become primary targets of cyberattacks. The threat has crossed a line—from data theft and espionage to the deliberate disruption of physical processes. Threat actors now pre-position inside critical infrastructure, map control loops, and in some cases disable the very devices operators rely on for visibility and control.

This creates a paradox. Connecting legacy control environments to cloud and AI multiplies their value, and simultaneously their attack surface. Modernization involves risk, and security bolted on too late leads to failure.Agora edge was built to resolve this paradox. It lets operators adopt IIoT and edge AI on top of their existing IACS, SCADA, APC, and DCS without rip-and-replace, while raising the security baseline of the environment it touches. It truly enables expand-and-extend, and therefore modernization without compromise. This white paper outlines the threat landscape driving the urgency, a practical strategy for secure modernization, and the specific strengths that make Agora edge a trusted solution. It is also honest about where it fits—the solution is not your entire security program, but the secure advantage that makes modernization safe, quick, and cost effective.

Why modernize now?

The pressure to modernize control environments is real and accelerating. The drivers are not primarily about technology, but about business outcomes:

  • Efficiency and margin: Real-time optimization, predictive maintenance, and automated control reduce downtime, energy use, and operating cost.
  • Resilience and autonomy: Edge AI keeps sites running and safe during connectivity loss, making remote and unattended operations viable.
  • A shrinking, aging workforce: Automation and remote operations offset the growing shortage of experienced field and control-room staff.
  • Obsolescence management: Legacy control systems require year-on-year increasing maintenance, negating the cost leadership principles.
  • Sustainability and reporting: Continuous emissions and process monitoring are increasingly required to meet environmental and regulatory goals.
  • The competitive clock: Operators who modernize pull ahead on cost and reliability–those who wait fall behind.

Modernization, in other words, is inevitable. The real question is whether it happens securely.

A threat landscape that has crossed the line

For most of their history, control systems were protected by obscurity and isolation—both physical and network. Those days are largely behind us. The following characteristics make IACS, SCADA, APC, and DCS environments both hard to change and hard to defend:

  • Long-lived equipment, often up to 30 years old, running legacy operating systems and unpatched firmware.
  • Industrial protocols such as Modbus, distributed network protocol 3 (DNP3), and open platform communications (OPC) that are largely unauthenticated and unencrypted.
  • Flat networks with weak segmentation between business, control, and safety systems.
  • Default, shared, or hardcoded credentials, and little or no multi-factor authentication (MFA).
  • Minimal native logging and monitoring inside the operational zone.

 

By the numbers

• Ransomware attacks on industrial organizations rose 87% in 2024 and a further 64% in 2025. [1,2]

• The number of ransomware groups targeting operational technology (OT) grew 49% from 2024 to 2025, collectively hitting roughly 3,300 organizations. [2]

• Of all OT ransomware incidents in 2024 which were responded to, 75% caused a partial shutdown and 25% a full shutdown—in 2025, the average dwell time for ransomware attacks in OT environments was 42 days. [1,2]

• Sites suffering with physical impact from cyberattacks jumped 146% in 2024, and nation-state attacks with physical consequences tripled. [4]

• More than 46,000 industrial devices remain exposed to the internet on just one legacy protocol (Modbus). [8]

• Fewer than 1 in 10 OT networks have monitoring able to detect an intrusion. [5]

These weaknesses are not theoretical—they are being exploited now. A few recent incidents show how directly attackers can now reach physical operations:

Incident (year)

What happened

Why it worked

Programmable logic controller (PLC) campaign (2026)[1]

Attackers manipulated PLC project files and falsified human-machine interface (HMI)/SCADA readings, causing operational disruption and financial loss.

Internet-exposed PLCs reachable with legitimate engineering tools. No exploit or authentication bypass required.

AI-assisted OT intrusion (2026) [2]

Commercial AI autonomously found the IT-OT gateway and built intrusion tooling; the IT network fell, the OT attack failed.

A compromised IT network with a weak path to OT; AI compressed the IT-to-OT timeline.

Power grid attack (2025) [3]

Wiper malware bricked OT devices; operators lost remote visibility and control of distributed sites.

Internet-exposed firewalls without MFA and default credentials.

Colonial pipeline attack (2021) [4]

The cybercrime group used a compromised password to launch a ransomware attack, forcing a proactive shutdown of the colonial pipeline’s primary fuel network for several days.

Leaked employee password, inactive VPN account that lacked MFA.


 

These build on a decade of escalation, from the Industroyer malware that blacked out part of Kyiv in 2016 to the 2017 TRITON attack that targeted a plant's safety system directly, the last line of defense against a physical disaster. [11,12]

Two shifts make today different. Firstly, intent—state-aligned groups have moved from stealing data to pre-positioning for physical disruption, methodically mapping control loops so they can act at a time of their choosing. [5] Secondly, scope—regional conflicts are spilling across borders into the critical infrastructure of non-combatant nations and cyberattacks have become instruments of statecraft and coercion. A recent dip in attacks that caused physical damage is misleading—nation-state and hacktivist activity doubled over the same period, and analysts expect the broader trend to resume climbing in the years ahead. [4,5] The defensive gap is stark—most operators simply cannot see an attacker inside their OT network, because the observability is not there.

This escalation has continued into 2026. A joint US government advisory warned that Iran-affiliated actors were actively disrupting internet-exposed PLCs at water, energy, and government sites amid regional hostilities, tampering with control logic and falsifying operator displays. [13] In a separate case, investigators documented the first AI-native intrusion, in which commercial AI models autonomously identified a utility's industrial gateway and built the tooling to attack it. [14] Taken together, these cases show adversaries starting to weaponize AI itself, compressing the path from an ordinary IT breach to a direct assault on operational technology.

The modernization paradox

This tension sits right at the heart of the matter. Everything that makes modernization valuable—connecting controllers to analytics, streaming data to the cloud, hosting edge AI—also enlarges the attack surface of environments that were never designed to be connected. Security cannot be an afterthought added once the project is live—by then the exposure already exists. To modernize safely, security must be a property of the modernization layer itself, designed from the silicon up.

A strategy for secure modernization

Secure modernization does not require ripping out working control systems. It requires inserting a trustworthy layer between those systems and the outside world, governed by a few durable principles, each of which closes a gap that attackers exploit today:

  • Anchor trust in hardware: Give every edge device an unforgeable identity and verify continuously that it has not been tampered with, not just once at install. This counters pre-positioning and physical tampering.
  • Make identity zero-trust everywhere: No shared or default passwords, authenticate and authorize every user, application, and machine, even at disconnected sites. That shuts down the single most common entry point.
  • Keep control systems off the open internet: Default to outbound-only, allow-listed connectivity, and never expose controllers or PLCs directly. This takes away the most common path to initial access.
  • Terminate legacy protocols at a secure edge: Terminating unauthenticated protocols such as Modbus at the edge gateway removes their internet-facing exposure, and re-publishes the data northbound over encrypted, authenticated channels. This is defense-in-depth, not end-to-end encryption of Modbus itself—the last-mile link from controller to gateway typically remains cleartext and must be protected by strict segmentation rather than direct exposure to external networks.
  • Control the update path: Deliver only signed, centrally managed updates and eliminate USB and local update mechanisms. This removes a favored route for malware and device bricking.
  • See everything, continuously: Upscale observability and maintain a live device inventory, attest device integrity, and monitor around the clock with OT-aware response. This closes the visibility gap that lets attackers dwell for months.
  • Use edge AI for resilience, not only efficiency: Local intelligence keeps sites safe and productive during connectivity loss and can flag anomalies where they occur.

Where Agora edge stands out

The distinction between Agora edge and other AI solutions is that controls are engineered together—from edge silicon to a managed security operations center—and delivered as one accountable solution. Its strengths are well-suited to a modernizing control environment:

  • Hardware-rooted trust, re-proven at every boot: Every certified gateway carries a hardware root of trust and uses measured boot with remote attestation, so integrity is re-verified each time the device starts and a tampered device can be detected and automatically quarantined. Unlike approaches that verify a device only once at onboarding, trust is re-proven at every boot for the life of the device, directly countering the pre-positioning seen in recent state-aligned campaigns.
  • Zero-trust identity, no shared passwords: The gateway federates authentication to the customer's corporate directory over OpenID Connect (OIDC)/security assertion markup language (SAML) and validates short-lived tokens, so access is governed by the organization's central identity policy—this includes MFA and role-based access, and no user passwords are stored on the device.
  • No local update path, by design: Production gateways have no local update interface—every update is signed and delivered centrally. This removes the USB and technician vector and the firmware-bricking technique used against distributed energy sites.
  • Nothing exposed to the internet: Connectivity is outbound-only, and allow-listed, control devices are never directly reachable. Legacy protocols are terminated at the gateway and re-published over encrypted, authenticated channels.
  • Workload isolation on an open foundation: A hardened, open-standard type-1 hypervisor isolates each workload on the gateway behind a per-application firewall and controls the gateway's northbound and southbound paths, so a compromised app on the gateway cannot pivot through it to controllers or other workloads. Where controllers share an OT switch or VLAN with other devices, this complements rather than replaces segmentation on that network, and it avoids locking customers into a proprietary stack.
  • Cutting-edge threat prevention at the edge: Through collaboration with Palo Alto Networks, a Palo Alto Networks next-generation firewall can run directly on the edge gateway, bringing deep packet inspection, intrusion prevention, and application-aware policy to the OT boundary. Security events can be fed to cloud management and the SLB cybersecurity operations center, so the industrial edge benefits from the continuously updated, AI-powered threat intelligence and ongoing innovation of a global cybersecurity leader. [6]
  • Security delivered as a managed solution: A secure-by-design development lifecycle, application screening for the marketplace, live compliance dashboard, and 24/7 monitoring through the SLB cybersecurity operations center gives operators the OT visibility and response that most environments lack today.
  • Deployment on your terms, with layered assurance: Deploy in public cloud, in-country, or sovereign regions, or fully on-premises. The solution is engineered to align with international society of automation (ISA)/international electrotechnical commission (IEC) 62443, the OT security benchmark—including its secure-development-lifecycle (62443-4-1) and component (62443-4-2) requirements—while its service and cloud controls are independently validated through service organization control 2 (SOC 2) type 2 attestation and regular third-party penetration testing.

Meeting critical-infrastructure regulations and standards

For critical-infrastructure operators, security and compliance are converging, and regulators increasingly expect demonstrable OT controls. Agora edge is built to accelerate, not replace, your compliance program, mapping its controls to the frameworks that matter, and supplying the following evidence auditors ask for:

  • ISA/IEC 62443: the cornerstone for industrial control system security. The solution’s architecture and secure development practices were guided and inspired by 62443-4-1 (secure development lifecycle) and 62443-4-2 (component technical requirements), covering authentication, secure communications, system integrity, and timely response to events.
  • National Institute of Standards and Technology (NIST) cybersecurity framework (CSF) and special publication (SP) 800-82 / 800-53: Solution controls and cryptography align with NIST cybersecurity framework and industrial-control guidance.
  • European Union (EU) network and information systems 2 (NIS2) directive and the Cyber Resilience Act: The solution helps operators of essential and important entities meet risk-management, supply-chain, and incident-reporting obligations.
  • US sector requirements and regional equivalents: It supports segmentation, access-control, monitoring, and reporting expectations behind North American Electric Reliability Corporation (NERC) critical infrastructure protection (CIP), Transportation Security Administration (TSA) security directives, Certified Information Systems Auditor (CISA) guidance, and similar national frameworks worldwide.

Crucially, the solution produces the artifacts that make audits faster, a continuous device inventory, attestation records, and audit trails, turning compliance from a periodic scramble into a continuous, evidence-based posture. Many SLB products have SOC 2 type 2 accreditation, and third-party penetration tests provide independent assurance that these controls operate as intended.

Where we fit: An honest scope

Agora edge is not a replacement for your control systems, nor for your entire security program, and it does not require you to rip out and replace working SCADA or DCS assets. What it does is provide a secure, trustworthy edge that lets you adopt IIoT and edge AI on top of what you already run, and in doing so raise the security baseline of the environment it touches. It complements your existing investments in OT monitoring, firewalls, and governance, and it fits into the architecture and standards you have already chosen. Put simply, we secure the modernization layer and strengthen the operations it connects to.

Conclusion

The case for modernizing industrial operations with IIoT and edge AI is no longer in question—the only question is whether it is done securely. The threat to IACS, SCADA, APC, and DCS environments has crossed from espionage into deliberate physical disruption, and it is driven by well-resourced, geopolitically motivated actors. Operators who connect legacy control systems without a security-first approach simply hand attackers a larger target. Agora edge offers a different path, secure by design, secure in deployment, and secure in operation, so that operators can modernize with confidence, meet their regulatory obligations, and extend intelligence safely from the control room to the edge. Modernize without compromise.



Sources

1. CISA, Advisory AA23-335A: Cyber Actors Exploit PLCs.
2. CISA, Advisory AA26-097A (Apr 7, 2026)
3. CERT Polska, Energy Sector Incident Report - 29 December 2025.
4. CISA, The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years
5. SLB, SLB and Palo Alto Networks expand collaboration to strengthen cybersecurity for the energy sector (Aug 19, 2024).