Security built for pipelines and plants
See whether an attack reached operational systems before you stop the pipeline.
Directives
| Directive | Measure | ARRTECH evidence |
|---|---|---|
| TSA Pipeline-2021-01 | Report to CISA within 24 hours. | A signed case timeline. → |
| TSA Pipeline-2021-02 | Continuous monitoring and detection. | Correlation at the IT/OT boundary and Detection baselines. → |
| TSA Pipeline-2021-02 | Segmentation so OT runs if IT is hit. | Logs from the conduit: firewalls and jump hosts. → |
| HSE OG86 | Records of periodic security log monitoring. | Scheduled reports and signed logs. → |
| Havtil, 2025 | Central logging with anomaly detection. | ARRTECH SIEM and Cyberdroid AI Detection. → |
TSA Pipeline-2021-02
See whether an attack reached OT
TSA Security Directive Pipeline-2021-02 requires owners to separate IT from OT and monitor for attacks. ARRTECH links VPN, firewall and remote access events at the boundary, so you can see whether an attacker reached OT.
Safety first
Monitor pipelines without touching safety systems
Touching a safety system during an incident creates new risk. ARRTECH never connects to controllers or safety systems; it reads the logs your boundary systems send.
TSA Pipeline-2021-01
Report to CISA within 24 hours
TSA Security Directive Pipeline-2021-01 requires reporting cybersecurity incidents to CISA within 24 hours. Each ARRTECH SIEM case keeps the full timeline from the first alert.
Remote sites
Watch remote compressor and pump stations
Compressor and pump stations often sit on remote links. ARRTECH SIEM alerts when any station stops reporting, and the agent catches up when the link returns.
By rule
HSE OG86
Records of periodic security log monitoring. ARRTECH: Scheduled reports and signed logs.
Havtil, 2025
Central logging with anomaly detection. ARRTECH SIEM and Cyberdroid AI Detection.
Questions
Can you see the safety system?
No. ARRTECH never connects to a controller or safety system. It reads what your boundary systems and site computers log.
What about remote stations?
The agent holds logs when a link drops and sends them later, and an alert shows when a station stops reporting.
Who decides a shutdown?
The control room. ARRTECH SOAR emails a person up to five options and waits.
What stays with you?
Your TSA plans and reports, and API 1164 reporting. Cyberdroid AI Detection reports about once an hour and never blocks.
Sources
Guide
What do TSA pipeline security directives require?
Report incidents to CISA within 24 hours, segment IT from OT, and run continuous monitoring and detection.
What is API 1164?
API Standard 1164 is the pipeline industry standard for control system cybersecurity.
How do you know if an attack reached OT?
Correlate VPN, firewall and remote access logs at the IT/OT boundary.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.