Idaho National Laboratory is developing TOPGEAR, a platform intended to show how corporate relationships and individual influence can create risk around critical infrastructure. The name stands for Technology, Organization and Person of Interest Graph Extraction, Analysis and Reporting.
Looking beyond a conventional cyberattack
Traditional assessments often concentrate on software vulnerabilities, network boundaries and physical hazards. TOPGEAR instead connects information about organizations, people and infrastructure assets. The objective is to reveal how investments, acquisitions, board positions or supplier relationships could create influence over facilities such as substations and data centers without a malware incident.
Industrial Cyber reports that the platform draws on public sources including regulatory filings and energy data, then represents the information across social, infrastructure and cross-layer networks. Analysts can examine how an entity is connected to an asset and identify concentrations that may deserve additional review. The output is an aid to analysis, not proof that a relationship is malicious.
A broader resilience model
The project illustrates why critical-infrastructure protection requires ownership, supplier and governance data as well as technical telemetry. Organizations adopting similar methods should record source provenance, confidence and update dates so that old or ambiguous relationships do not become false accusations. TOPGEAR adds another perspective to security intelligence by treating organizational influence as a cyber-physical dependency.

Leave a Reply