We’ve Been Solving the Wrong Problem in Industrial Safety
For 20+ years, ACS has documented over 30,000 deaths and $100B+ in damage from ICS automation incidents — failures where a computer is involved, but hardly any are a cyber attack. These incidents cause far more harm than cyber events, yet most organizations don’t even know how to identify them.

Joe Weiss
ACS isn’t a vendor or a cybersecurity firm.
ACS is the originator of a new category — automation incident intelligence — built on the world’s largest record of the automation failures that actually harm critical infrastructure.
The world’s largest ICS automation incident dataset
20+ years of longitudinal records across all critical infrastructure sectors.
Annual sector reports that redefine industrial risk
The only authoritative analysis showing that automation incidents — not cyber attacks — cause most ICS harm.
Train-the-trainer workshops
ACS teaches organizations how to identify automation incidents, perform meaningful RCA, and contribute to trusted, non-punitive information sharing.
Incidents that are too often mislabeled as cyber.
Much of it originating at Level 0 and Level 1 — below the IP network layer. Source: ACS incident research.
Not every control system event is a cybersecurity incident.
Distinguishing automation incidents from network cybersecurity incidents.
Many serious events are better understood as automation incidents. Understanding the difference helps organizations investigate the right causes and involve the right teams.
Automation incident
The root cause lies in sensors, actuators, control logic, calibration, setpoints, timing, maintenance, or engineering decisions that affect the physical process.
Engineering-led investigation
Network cybersecurity incident
Unauthorized or malicious activity through networks, credentials, malware, ransomware, remote access, or communications pathways.
Cyber incident response
Blended incident
Both a cyber pathway and automation behavior — for example, a compromised engineering workstation used to change controller logic.
Both disciplines

Why these incidents go unnamed.
The operators who first notice a process anomaly are rarely the people who classify it as a cyber incident. Operations staff have the domain knowledge to recognize when something is wrong — but aren’t trained to think “cyber.” Cybersecurity staff are trained to think “cyber” — but don’t know what normal process behavior looks like.
The people best positioned to detect the problem are structurally prevented from naming it.
Naming an event “cyber” can also trigger regulatory scrutiny, reporting, and restart delays — so organizations default to “equipment failure.” ACS exists to close that gap.
A consequence-focused perspective.
Rather than treating cybersecurity as a purely IT data problem, ACS focuses on system impacts — the engineering realities of operational technology, where incidents can directly affect safety, uptime, equipment, productivity, and public services.
How we support organizations
- Assessments
- Strategic guidance
- Training
- Incident-informed analysis
- Executive-level communication
Focused help for critical infrastructure.
Incident Identification Workshop
An on-site, “train-the-trainers” workshop that helps your team recognize control system incidents that are actually cyber-related — and close the gaps.
Learn moreAnnual Service
A yearlong subscription: an on-site day identifying automation failures, the annual incident report, and year-round availability for questions.
Learn moreUnderstand control system safety incidents before they become headlines.
Practical insight from Joe Weiss into real-world incidents at Level 0 and Level 1 — below the IP network layer. No spam, unsubscribe anytime.
