AetherMIP White Paper — Security & Isolation | Marando Industries
How AetherMIP applies intelligence to production data while making inbound access to the plant floor physically impossible, with Integrity Watch verifying every output.
Executive Summary
AetherMIP delivers useful, on-premise machine intelligence while remaining physically incapable of writing to a PLC or serving as a pathway into the control network. Isolation is not achieved through software rules, firewalls, or configuration settings. It is enforced by hardware.
This paper explains how AetherMIP is designed, what it can and cannot do, and why its architecture directly addresses the security and liability concerns that prevent many manufacturers from adopting plant-floor AI.
1 · The Real Risk Most Plants Face
Manufacturers increasingly recognize the value of AI for troubleshooting, knowledge retention, and operational insight. At the same time, most are unwilling to connect external systems to their PLCs in ways that create new risk.
Traditional approaches often require bidirectional communication or place software on the same network as the controller. Once a system can write to a PLC — or can be compromised into doing so — it becomes part of the attack surface. Even well-intentioned tools can introduce liability if they are capable of changing machine behavior.
Guidance from CISA, the FBI, and other agencies consistently emphasizes reducing exposure to the control layer and improving the ability to detect unauthorized changes. Yet most plants still lack an independent way to notice if PLC logic, safety-related tags, or critical data structures have been altered.
The result is a difficult trade-off: useful intelligence on one side, unacceptable exposure on the other. AetherMIP was built to eliminate that trade-off.
2 · How AetherMIP Achieves Isolation
AetherMIP was designed from first principles around a single requirement: the system must be able to observe the machine while remaining architecturally incapable of controlling it. Three design decisions enforce that requirement.
- Hardware data diode — Data flows in one direction only: from the PLC to AetherMIP. There is no electrical or protocol path that allows traffic to travel back to the controller. This is a physical constraint, not a software policy.
- Read-only by construction — The software stack contains no write commands, credentials, or interfaces capable of acting on the PLC. Even if the application layer were compromised, the hardware boundary prevents any write activity from reaching the machine.
- Minimal network dependency — AetherMIP's core functions do not require broad access to the plant LAN. Where notifications are used, they are handled through an isolated path that keeps recipient information and outbound messaging separated from the main system.
3 · Integrity Watch: Detection When Prevention Is Not Enough
Access controls and network segmentation are essential, but they are not perfect. If an attacker or an unauthorized change reaches the PLC, most plants have no independent system watching the live data stream for signs of trouble.
AetherMIP includes Integrity Watch — a continuous monitoring layer that observes the PLC data feed for conditions such as:
- Loss of communication or diode link problems
- Widespread stale or frozen data
- Sequence anomalies that may indicate replay or manipulation
- Safety-tag anomalies
- Changes in data structure or layout that can signal reprogramming
When these conditions are detected, alerts can be generated. Critically, Integrity Watch can only observe and notify. It has no ability to write to the PLC or alter machine behavior. This provides a form of visibility that is missing in the majority of industrial environments today.
4 · What AetherMIP Explicitly Cannot Do
Clarity about limitations builds more trust than broad claims of capability. AetherMIP cannot:
- Write to the PLC
- Change setpoints, logic, or configurations
- Issue commands to the machine
- Serve as a pivot point or pathway into the control network
- Move machine data into the cloud as part of its core operation
These restrictions are not optional settings. They are fundamental to the architecture.
5 · Comparison at a Glance
| Capability | Typical networked or cloud AI | AetherMIP |
|---|---|---|
| Access to live PLC data | Yes | Yes (one-way only) |
| Ability to write to the PLC | Often possible | Physically impossible |
| Machine data leaves the plant | Commonly | No |
| Independent integrity monitoring | Rare | Yes |
| Introduces new inbound attack surface | Yes | No |
6 · Practical Security Outcomes
For the plant, the architecture delivers several concrete results:
- AI assistance can be introduced without violating policies that prohibit bidirectional connections to controllers.
- Liability exposure associated with write-capable systems is avoided by design.
- An independent observation layer remains available even if portions of the broader network are compromised.
- The system aligns with established OT security principles of least privilege, segmentation, and continuous monitoring.
7 · Closing Perspective
Useful intelligence does not have to come at the cost of control-system exposure. AetherMIP was built so that the two requirements — insight and isolation — are met simultaneously.
By combining a hardware data diode with continuous integrity monitoring, the system provides plant-floor intelligence that remains firmly on the safe side of the control boundary. The result is a practical tool that operators, technicians, and managers can use, while security and leadership teams retain confidence that the machine itself stays under their control.
Intelligence for the plant floor. Exposure for no one.