Passive observability across Purdue Levels 0–3 at a speciality chemicals plant
Correlating batch anomalies to ERP events without placing a single agent on a controller.
The situation
Operating teams at the continuous-synthesis chemicals facility faced constant friction between plant safety and IT observability. Whenever batch deviations occurred, operators took an average of five hours to diagnose whether the root cause originated in control loops, programmable logic controllers, network drops, or upstream MES recipe changes.
Traditional IT agents and active polling scanners were categorically prohibited by plant process safety guidelines, as uncontrolled packets on legacy fieldbuses could induce controller faults or emergency shutdown trips.
What constrained the design
Industrial control networks have strict deterministic requirements and zero tolerance for jitter:
- —No software or agent could be installed on any Level 0–2 PLC, RTU, or safety instrumented system.
- —Tapping hardware had to be completely electrically and logically passive with zero ability to inject packets.
- —Legacy proprietary protocols (Modbus serial, PROFINET RT, proprietary vendor extensions) had to be parsed in real time.
- —Data egress from the industrial demilitarized zone (IDMZ) had to be strictly unidirectional and encrypted.
What we deployed
Vizor was connected via optical SPAN taps at the core switch mirrors of Purdue Levels 1 and 2. Operating completely out-of-band, Vizor activated 41 protocol decoders to continuously inspect command-response cycles, timing jitter, register state changes, and session anomalies without sending a single frame onto the operational network.
Extracted telemetry was correlated with MES batch identifiers and SAP transaction logs through an encrypted unidirectional gateway, establishing a unified time-synchronized topology spanning physical reactors to executive dashboards.
What it cost to run
Mean time to identify (MTTI) cross-boundary anomalies dropped from over 300 minutes to just 11 minutes. The entire deployment passed rigorous internal and third-party process safety audits on the first evaluation cycle.
Where it stands now
Following the 45-day pilot success, the manufacturer standardizing on Vizor across all four manufacturing facilities nationwide, establishing an automated compliance record aligned with ISA/IEC 62443 requirements.
Publications behind this deployment
Client identities held under strict non-disclosure.
StamBH · Enterprise integrity protocol
Every metric published across our engineering dossiers was generated by the client’s own operational instrumentation, reviewed jointly under bilateral NDA, and cleared for anonymised release. Technical architecture blueprints and direct peer reference calls with engineering leadership are available to verified counterparties under matching NDA terms.
Production performance figures captured directly from client cloud monitoring and verified against SLA targets.
Direct peer briefings with enterprise CTO, VP Engineering, or Security leadership arranged under bilateral non-disclosure.
Unredacted component topologies, schema definitions, and migration playbooks available for qualified in-house review.
Engagement Dossier Facts
Start small. Scale with confidence.
StamBH · 2-hour workshop, 5 days to something live
- ◆2-hour architecture mapping workshop
- ◆Production-grade functional slice in 5 business days
- ◆100% client-owned source code & assets; zero vendor lock-in
- ◆Edge-native performance with zero proprietary runtime bloat
