Gap Analysis / Continuous OT Evidence & Assurance
Know what your water plant can prove. Find what it cannot.
Water plant / evidence surface
Illustrative architecture
Water treatment plant, digital control and IQAI evidence assurance
A simplified water process connects intake, treatment, pumping and distribution to sensors, PLCs, SCADA, network and cyber controls. These evidence sources feed IQAI Gap Analysis, which separates established facts from unknowns and evidence requests before human review.
PHYSICAL PROCESS
Intake raw water
Treatment process
Pumping delivery
Distribution network
DIGITAL CONTROL
Sensors
PLC
SCADA
Historian
CYBER / OPERATING CONTEXT
Asset inventory
OT monitoring
Remote access
Engineering
IQAI
Evidence
Assurance
known
unknown
request
review
PHYSICAL IQAI LENS
OBSERVED Plant process
INFERRED None required
UNKNOWN Evidence context not yet inspected
01 Plant
02 Control
03 Cyber
04 Evidence
Physical water process
Intake, treatment, pumping and distribution create the operating context that must ultimately be understood and protected.
01 / PHYSICAL
The plant comes first.
Intake, treatment, pumping and distribution define the real-world consequence.
02 / CONTROL
The plant has a digital nervous system.
Sensors, PLCs, SCADA and historian records observe and control the process.
03 / CYBER
Security adds another evidence surface.
Asset inventory, monitoring, remote access and engineering records shape what can be assessed.
04 / EVIDENCE
IQAI asks what all of it actually proves.
Known, inferred and unknown stay separate. Missing proof becomes a request, not an assumption.
All systems
Spatial
Trace
Diagnostics
Advanced Intelligence
Risk
Gap Analysis
Why it is needed
Visibility is not the same as understanding.
Device seen ≠ Asset identified
Signal captured ≠ Signal understood
Control documented ≠ Control verified
Alert available ≠ Conclusion established
Before teams can mitigate risk, they need to know what the available evidence actually establishes.
What Gap Analysis does
Turn blind spots into evidence requests.
Evidence workflow Synthetic example
01 Evidence captured
→
02 Unknown explicit
→
03 Request targeted
→
04 Review recorded
Captured evidence 01 / 04
A value was captured.
Test what that observation actually establishes.
A captured display is evidence that something was shown. It is not proof of physical meaning or equipment condition.
Water plant example
One observation. Several unanswered questions.
OBSERVED
Pump 04
RUN = 1
09:42 capture
→
UNKNOWN
Identity
signal meaning
source time
network relationship
→
EVIDENCE NEEDED
Tag dictionary
asset mapping
source timestamp
network record
→
FINDING
BLOCKED
until evidence is sufficient
Then
Verify mapping → assess exposure → confirm controls → prioritize mitigation
Illustrative example. A gap does not prove a vulnerability. It shows what must be verified before a risk or mitigation decision can be relied on.
Where IQAI sits
Above the evidence. Alongside the security stack.
Physical plant process + assets
Operational evidence telemetry + historian + records
Existing OT security discover + monitor + detect
IQAI Evidence Assurance provenance + states + requests + sufficiency
Human decision verify + prioritize + mitigate
01 / Physical plant
Start with the real operating environment.
The evidence only matters in relation to the physical process, assets and consequences the team is responsible for.
IQAI role Context boundary
Cybersecurity value
Expose what must be verified before mitigation.
GAP Asset identity unresolved
→
REQUEST Asset + network mapping
→
VERIFY Exposure + control context
→
ACTION Prioritize mitigation
GAP Control evidence incomplete
→
REQUEST Configuration + approval record
→
VERIFY Coverage + authority
→
ACTION Remediate or accept
Illustrative cybersecurity paths. IQAI does not treat an evidence gap as a detected threat or vulnerability.
Why the layer is different
OT security observes. IQAI controls the evidence-to-conclusion path.
OT SECURITY discover · monitor · detect
Combine layers
IQAI provenance · sufficiency · review
TOGETHER Evidence-informed action
Assessment
OT security platform
IQAI Evidence Assurance
Primary job Assess Observe / detect / score Control evidence → conclusion
Telemetry visibility Limited Core strength Consumes evidence
Threat detection No Core strength Not the role
Evidence provenance Variable Product specific Core control
Known / inferred / unknown Variable Product specific Explicit state
Missing evidence Follow-up Workflow dependent Structured request
Finding sufficiency Reviewer Product dependent Explicit gate
Human disposition Report Workflow dependent Preserved state
Generalized category comparison. IQAI is designed to sit above and alongside mature OT security, not replace discovery, monitoring or threat detection.
Retained demonstration
The workflow has been exercised, not only diagrammed.
67 gap propositions
21 outstanding evidence requests
0 candidates passed sufficiency
Recurring model
Not a report. A living assurance loop.
01 Capture
→
02 Assess
→
03 Request
→
04 Verify
→
05 Review
↺
01 One plant
→
02 OT assets
→
03 Facilities
→
04 Portfolio assurance
Who uses it
One evidence layer. Different responsibilities.
OPERATIONS What is actually known about the plant?
CYBERSECURITY What blind spots affect risk assessment?
ENGINEERING Which mappings and records are missing?
ASSURANCE What evidence supports the conclusion?
Current maturity
Working, demonstrated and still to validate.
WORKING
Evidence links
Unknown register
Evidence requests
Review history
Finding gate
Ledger export
DEMONSTRATED
Captured public water-monitoring evidence workflow
Retained review and replay evidence
TO VALIDATE
Additional connectors
Additional domains
Production-scale deployment
Authenticated approval authority
Bring us one unresolved operational question.
Start with the gap.