Wardhelm · OT Critical-Conduit Governance

Know which cyber actions can cause physical harm —
and whether anything actually stops them.

Hospitals, water, power and pipelines run on control paths that were never built to be attacked. Wardhelm passively maps your most dangerous OT operations to real-world consequence and shows exactly where your existing controls leave gaps — then hands you signed evidence you can verify yourself, offline, without trusting us. Air-gapped, off-path, human-governed. We never touch the wire.

Passive
Off-path by default
Air-gapped
On-prem, no cloud
Human-governed
Your engineers review and sign off
Signed
Evidence with provenance
The gap nobody closes

Knowing a controller is vulnerable is not the same as knowing what it does.

Your visibility tools can tell you a PLC exists, that Modbus is talking, that a CVE applies. None of them answer the question that actually decides patient or plant safety: which commands can cause physical harm, and whether anything really stops them.

What does this register control?

Not "holding register 40102" — the medical-gas setpoint, the chiller command, the generator mode. Physical and clinical meaning, in engineering units.

Which write paths were actually seen?

Graded honestly, per control point: observed during the capture window · inferred from device capability · not determinable from a passive read. A mirror port can't see a serial leg or a vendor's dial-in — we name those blind spots rather than let a map imply coverage it doesn't have.

Which control covers it — and is it verified?

What's the worst-case consequence, which existing safeguard actually prevents it, and has anyone proven that it does? Usually, no one has.
Wardhelm Conduit · how it works

Observe → understand → establish consequence → prove coverage → sign.

Conduit reads a passive copy of your traffic — a mirror port or a capture file, taken off to the side. It is not an inline bump-in-the-wire device. When Conduit is offline, your traffic is unaffected, because it was never in the path.

01

Observe, passively

Ingest a SPAN mirror or a PCAP you provide. Nothing inserted into the path, nothing touched, no write ever sent to a controller.
02

Understand the operation

Decode every write-capable function code and resolve it to the logical point it targets — across all the paths that reach it.
03

Establish consequence

Map each dangerous write to its physical / clinical effect and worst case — the register-consequence map your biomedical engineer red-lines — corrections welcome, and expected.
04

Prove control coverage

Show which existing safeguard actually covers each path — and where the gap is that nothing prevents today.
05

Sign the evidence

A tamper-evident, independently verifiable assessment: every finding is hash-chained and signed, so any change after delivery is detectable — offline, by you, without trusting us.

AI where it's safe

AI assists analysis offline, on your captured traffic. Humans ratify and sign — every conclusion in the report is a human decision.
The Critical-Conduit Assessment

What you walk away with.

A fixed-fee, few-weeks engagement on one selected conduit — HMI↔PLC, BMS↔controller, engineering workstation↔industrial controller. Off-path throughout — we never transmit on your network. One clear, signed deliverable your team owns.

Register-consequence map

Every dangerous write, its physical meaning, and the worst case if abused.

Write-path coverage matrix

Which function codes reach each critical point — and which are covered.

Compensating-control assessment

What your existing stack actually prevents, and where it doesn't.

Per-register fail-mode sheet

A signed, explicit "fail-safe vs fail-open" decision for each critical device.
Methodology & trust

Off-path by architecture. Honest about how it fails.

Not an inline device

Conduit does not sit in the mandatory packet path and does not originate control commands. The assessment observes and nothing else — it never originates a control command, and nothing we run sits in the packet path.

How it fails

When Wardhelm is offline, your traffic is unaffected — we're off-path. Nothing we run sits in the packet path, so a failure on our side changes nothing about how your control network behaves.

Evidence, not assertion

Every finding is labelled by how we know it — KNOWN · INFERRED · ASSERTED · UNKNOWN — and backed by capture hashes, a signed model version and a hash-chained report.
Standards alignment

Supports your program — it doesn't certify it.

Israeli MoH cyber circularINCD guidanceIEC 62443 NERC CIP-015NIS2MITRE ATT&CK ICS

Wardhelm maps to these frameworks and supports the customer's program; it is not a certification and does not replace your audit or regulatory submission.

No rip-and-replace — and no pretending we're alone here

What the assessment adds to your existing stack.

You already haveIt gives youThe assessment adds
Asset discovery (Claroty & co.)What exists on the networkWhat each control point physically does
Protocol visibilityThat a write happenedWhich write paths can reach a critical point
Vulnerability / CVE dataThat a flaw existsThe real-world consequence of an actual operation
Firewalls / NAC / segmentationRules you're afraid to enforceWhich rule would be safe — and what it would have interrupted
SOC alerts & reportsNoise to triageEvidence you can verify yourself, without trusting us

Where we overlap, we say so: platforms including Claroty already offer approval-routed, time-boxed vendor access windows. We are not claiming to invent that. Two things are genuinely ours — passive off-path observation that doesn't depend on your sensor vendor, and an evidence package you can verify offline, yourself, years later, without us.

Start with one critical conduit. Prove the exposure first.

Medical gas, BMS, power, chillers — pick one. We observe it passively, map consequence with your engineering and biomedical teams, prove what your current controls cover, and hand you a signed picture of the one gap that matters most. No infrastructure change.