OT Resilience
Show disturbances in a controlled way without endangering real infrastructure
The resilience demo changes only simulation and presentation state. It shows how a factory remains controllable when connections are lost, the historian is unavailable or proposals are invalid: degrade, buffer, restore, validate, prove.
01
NORMAL
All connections healthy, telemetry flows without backlog.
02
CONNECTION LOST
Broker, historian, OPC-UA connection or edge gateway fail in the simulation.
03
EDGE DEGRADED MODE
Edge buffers locally, keeps allowed local logic running and closes unnecessary return paths.
04
BUFFERING
Samples are counted and replayed reproducibly later.
05
BACKFILL
After reconnection, data is backfilled and validated.
06
VALIDATION
The system checks gaps, order, timestamps and production impact.
07
NORMAL
Recovery complete; ideally Data Loss remains 0.
Resilience Lab
Controlled disturbances can be triggered on the start page. They serve as evidence of architecture behaviour: not as a chaos test against real plants, but as a reproducible simulation for discussion, acceptance and training.
- MQTT Broker disconnect: shows buffering and recovery without direct controller access
- Historian unavailable: shows local continuation and later backfill
- OPC-UA connection lost: shows asset status, degraded mode and alerting
- Invalid AI proposal: shows policy rejection before any execution
- Machine offline: shows production impact and restart metrics
Metrics for recovery
Outage duration
visible in resilience state and audit context
Buffered samples
visible in resilience state and audit context
Replayed samples
visible in resilience state and audit context
Lost samples
visible in resilience state and audit context
Recovery time
visible in resilience state and audit context
Production impact
visible in resilience state and audit context
Demo target state: restart with traceable effect and ideally Data Loss = 0.