Sectors / Critical Infrastructure

Resilience decisions and NIS2 evidence from the same source.

Utilities, water authorities, and critical facility operators already have the data an incident requires: OT telemetry, IT security events, an asset register, and a stack of procedures. What they rarely have is a model of how those assets depend on each other — so correlation happens in a bridge call, and the reporting evidence is reconstructed afterwards from memory and screenshots.

The problem NIS2 exposed: OT reality and IT records disagree

NIS2 (Directive (EU) 2022/2555) did not create the resilience problem — it created a deadline for proving you have solved it. Article 21 requires risk-management measures including incident handling, supply-chain security, and asset management. Article 23 requires an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. Article 20 puts that obligation on management bodies personally.

The operational difficulty is not the reporting template. It is that the asset register, the OT historian, the vulnerability scanner, and the incident ticketing system each describe a different version of the same substation, pumping station, or plant. When three alarms fire across those systems, deciding whether they are one cascading event or three unrelated ones is human archaeology performed under time pressure.

Answering it afterwards is worse: the 72-hour notification asks what was affected and what the impact was, and that answer has to hold up months later when a supervisor asks how it was reached.

Dependency modelling: the step most tooling skips

NeuroCluster models the estate as an operational ontology before any AI reasons over it — Asset, System, Location, Dependency, Vulnerability, Incident, Control, and Owner as first-class objects with stable identity, resolved from the systems that already hold them.

The dependency edges are the point. Once a shared power feed, network path, or control system is modelled as a dependency rather than described in a diagram, correlation stops being interpretive: three incidents that share an upstream dependency are one candidate event with a named blast radius, and a vulnerability sitting on that dependency is not the same priority as an identical CVE on an isolated asset.

  • Identity resolution across the asset register, OT historian, GIS, and ticketing system, so one physical asset is one object.
  • Dependency edges — power, network, control, and process — that make cascade paths queryable rather than tribal knowledge.
  • Control coverage mapped onto assets, so a gap is a property of a specific system with a named owner rather than a line in a spreadsheet.
  • Temporal history retained: what the estate looked like at the moment of an incident, not only how it looks today.

Correlation and containment, with the duty officer in authority

With that model in place, event correlation, dependency analysis, vulnerability prioritisation, and scenario modelling operate against one representation of the estate. A typical output: isolate the shared dependency behind three correlated incidents before it cascades further.

That recommendation goes to the resilience duty officer, not to an actuator. Containment procedures on critical infrastructure are exactly the class of action that must not execute on model confidence alone — so the platform's job is to compress the diagnosis, show the evidence and the affected dependency path, and then wait for a named human to authorise the procedure. The authorisation, the reasoning behind it, and the recovery plan are recorded as one linked record.

Scenario modelling runs the same machinery ahead of time: what fails if this dependency is lost, which controls cover it, and how long recovery took when something comparable happened before.

Reporting evidence as a by-product, not a project

Because every correlation, recommendation, approval, and containment action is recorded deterministically, the 24-hour early warning and 72-hour notification draw on a record that already exists — affected assets and dependencies, the timeline, who authorised what, and which controls were in force at the time.

The same record answers the questions that come later: recovery time and residual exposure measured against the control set. This is the difference between resilience reporting as a documentation exercise and resilience reporting as an export.

Deployment: OT segmentation and disconnected operation

Critical infrastructure operators cannot solve a correlation problem by shipping OT telemetry to a general-purpose cloud AI API, and network segmentation between OT and IT zones is not a constraint to work around — it is the control.

NeuroCluster runs on infrastructure the operator chooses: a dedicated European tenant, on-premises, or fully air-gapped, with models, retrieval, and agent runtime inside the same boundary. Reasoning can sit in the IT zone against replicated OT data, or inside the OT zone entirely, without a dependency on outbound internet access.

Frequently asked questions

Does using AI make NIS2 compliance harder?

It depends entirely on whether the AI produces evidence. A general-purpose assistant used informally by operators creates an unlogged decision path, which is a supervision problem. A governed platform where every correlation, recommendation, and human approval is recorded produces exactly the incident-handling and asset-management evidence Article 21 asks for. The technology is not the deciding factor — the runtime controls around it are.

Are we an essential entity or an important entity?

NIS2 classifies entities by sector and size: energy, drinking water, waste water, transport, banking, health, and digital infrastructure among others, with essential status generally applying to large entities in Annex I sectors and important status to medium entities and Annex II sectors. The distinction matters because supervision is proactive for essential entities and reactive for important ones, and maximum fines differ. Confirm classification with your national competent authority — several member states, the Netherlands among them, transposed the directive after the October 2024 deadline, so the national scoping detail is what binds you.

Can this run without connecting OT networks to the internet?

Yes. The platform deploys on-premises or air-gapped, with the models, vector store, and agent runtime inside your boundary. Nothing in the reasoning layer requires outbound connectivity, so OT/IT segmentation stays intact rather than being punctured to reach a hosted API.

Would an AI system supporting containment decisions be high-risk under the EU AI Act?

AI intended for use as a safety component in the management and operation of critical infrastructure falls under Annex III of the AI Act, so treat it as a high-risk candidate until a formal classification says otherwise. That is a reason to deploy it inside a runtime that already enforces human oversight, logging, and technical documentation — not a reason to avoid it, since those obligations apply either way.

How do we start?

A scoped assessment: we map one dependency chain that has caused real incidents, connect the systems that describe it, and show the correlation and evidence output on your own data before any commitment to a wider rollout.

Keep evaluating

Bring us one operational problem.

You do not need a finished brief. Bring the problem — we will work out the next step together.

Or book a call with the team