Critical national infrastructure monitoring

Monitoring for the estates the UK runs on: battery sensors that transmit one way over licence-free radio, need no power or network at the point of measurement, and cannot be reached over the air.

IoT Technologies monitors critical infrastructure estates across the UK: distributed, hardened, often unmanned sites where the equipment that matters frequently signals only locally. Readings arrive on a live dashboard independent of site IT, OT and cellular infrastructure, with a timestamped event and acknowledgement record behind every alert.

Illustrative critical national infrastructure monitoring panel showing asset protection, nationwide coverage, resilience, real-time alert, battery life and reporting tiles beside a telecoms mast above a fenced equipment compound.

CNI monitoring

Visibility across the estate, without adding an attack surface.

No inbound attack surface

The sensor transmits and never receives, so there is nothing to reach, reconfigure or interfere with over the air, and nothing to patch in the field.

Independent of site networks

No IP networking at the sensor and no connection to site IT or OT. Licence-free 433/868 MHz operation, independent of cellular and site infrastructure.

Reads from hardened positions

Basements, cabinets, compounds and mast sites report for years on a battery, with nothing needed at the point of measurement.

Evidence behind every alert

Timestamped events, acknowledgement trails and escalation by site, zone and severity, ready for incident review.

Critical national infrastructure monitoring is the continuous observation of the sites, equipment and assets whose loss would compromise essential services. Its job is to tell the operator of a distributed, hardened estate what state that estate is in — without weakening the thing it watches.

The UK designates thirteen sectors as critical national infrastructure — among them energy, water, communications, transport, health and emergency services — and the National Protective Security Authority (NPSA) is the UK's protective-security authority for the organisations that run them. Operationally, those estates share a shape: sites distributed across the country, hardened by design, often unmanned for weeks, and full of equipment that signals only locally. A pressure gauge in a compound, an alarm panel in a plant room and a door on a remote cabinet all know their own state; nobody else does until someone attends.

For a CNI operator, the first question about any monitoring system is not what it can see but what it exposes. Our answer is architectural: the sensor transmits and never receives. There is no inbound path by which it can be reached, reconfigured or interfered with over the air, no radio interface listening in the field, and nothing at the sensor to patch. There is no IP networking at the point of measurement — a tag cannot be scanned, addressed or enumerated, because there is nothing to connect to.

The same design keeps the monitoring layer off the networks that matter. Nothing joins site IT, and nothing touches the OT systems in control of the process. Readings travel over licence-free 433 MHz and 868 MHz radio to a dedicated gateway, independent of cellular coverage and of the site's own infrastructure, so the monitoring layer keeps working during the incident it exists to report.

The positions are hostile by nature: basements, plant rooms, steel cabinets, compounds, mast sites with no supply for miles. Delivery assurance is the engineering focus — reads arrive from those positions over sub-GHz radio chosen for penetration, with years of life on a battery. The one powered element is the gateway, which runs from mains, a DC feed or solar where no supply exists.

Operations run on the record as much as the alert. Every event is timestamped as it arrives; every alert carries who was notified and who acknowledged it; escalation follows site, zone and severity, so a door event at an unmanned compound and a suppression fault at a staffed site reach different people at different speeds. When an incident is reviewed, the sequence of what happened and what the response was is already written.

This is deployed, not proposed. IoT Technologies equipment is live today at national scale across UK critical infrastructure estates. The nature of those estates means we do not name clients, sites or numbers.

This page describes monitoring and operational visibility, provided on a best-endeavours basis. It does not guarantee prevention of failure, intrusion or loss, and it does not replace certified alarm systems, protective-security assessment, regulated life-safety signalling, guarding, policing or statutory obligations.

01

One-way by design

A sensor that cannot be reached is a sensor that cannot be turned.

One-way operation is a security property before it is a radio choice. In the field it means no credentials at the edge, no firmware exposure to manage across thousands of points, no configuration interface to find in a compound, and no visit needed to keep any of that true. The device does one thing — reports state — and offers nothing else to anyone.

02

Perimeters and access

Know when a boundary or a controlled point changes state.

Fence lines, gates, doors and compounds produce clean, high-value events. Perimeter intrusion detection covers long unpowered boundaries, and perimeter and site security monitoring covers compounds and secure sites, with PIR, door-state and fence-line sensing feeding the same escalation and evidence model as the rest of the estate.

03

Unmanned structures

Structures report their own condition between inspections.

Masts, towers and exposed structures stand for years between visits. Mast and tower monitoring reports sway, vibration, wind and weather from the structure itself, so engineering attention goes where the readings say it should rather than where the rota says it is due.

04

Cabinets and remote sites

The smallest sites are the hardest to keep visible.

Street cabinets, cabins and unmanned remote sites hold equipment whose failure is invisible until a service drops. Cabinet and site monitoring brings temperature, power, door and environment onto one dashboard, so critical asset visibility does not depend on a drive-by.

05

Silent safety equipment

Suppression systems that alarm locally can report nationally.

A suppression system in an unmanned equipment room protects assets nobody is standing next to. Fire suppression monitoring reports discharge events, cylinder pressure and fault states in real time, as a complementary visibility layer alongside the certified systems that remain in charge.

06

Escalation and evidence

Route each event to the person who owns the response.

Infrastructure resilience monitoring only earns its place if the right person hears about the right event at the right speed. Alerts route by site, zone and severity, acknowledgements are recorded, and the resulting record supports incident review, regulator conversations and insurance without anyone reconstructing a timeline from memory.

Deployment approach

Prove it at representative sites, then extend to the estate.

CNI estates are too varied to assume coverage: a survey at representative sites establishes what the radio environment actually does before anything is committed.

We assess the estate and its asset classes, survey RF behaviour at representative sites, commission tags and gateways with thresholds and routing agreed against the response arrangement, verify delivery end to end from the worst positions, and then extend the proven pattern across the estate under the site's own governance.

Assess

Establish the estate shape: site types, asset classes, existing alarm arrangements, response owners and the constraints that govern deployment.

Estate scope

Survey

Survey RF behaviour at representative sites — enclosures, basements, compounds — and place gateways for coverage before anything is committed.

RF proof

Commission

Fit tags to the equipment, commission gateways, and set thresholds, escalation routes and acknowledgement rules against the response arrangement.

Site fit-out

Verify

Raise controlled events and confirm end-to-end delivery from the hardest positions on the site, not just the convenient ones.

Delivery proof

Extend

Roll the proven pattern across the estate at national scale, with device health, battery state and gateway condition monitored throughout.

National scale

Bring the site types, the asset classes that only signal locally and the constraints that rule other systems out. We will scope secure remote monitoring for critical sites around them.

Scope a CNI deployment

Applications

Where critical infrastructure monitoring has to work.

Energy and utilities estates

Substations, compounds and distribution assets where equipment state, access events and environmental conditions need remote visibility.

Water infrastructure

Treatment sites, pumping stations and below-ground chambers where readings must arrive from positions that defeat conventional connectivity.

Communications estates

Masts, exchanges, street cabinets and equipment rooms distributed at national scale, monitored on one platform.

Transport infrastructure

Lineside assets, depots, plant rooms and remote equipment across rail and highways estates, reporting between inspections.

Emergency services estates

Stations, towers and equipment sites where availability matters and staffing is committed elsewhere.

Government and public estates

Distributed public-sector sites where independent, low-footprint monitoring adds visibility without touching existing systems.

FAQ

Frequently asked questions

What counts as critical national infrastructure (CNI) in the UK?

The UK designates thirteen sectors as critical national infrastructure: chemicals, civil nuclear, communications, defence, emergency services, energy, finance, food, government, health, space, transport and water. The term covers the facilities, systems, sites and networks whose loss or compromise would have a major impact on essential services. The National Protective Security Authority (NPSA) is the UK authority for protective security advice to the organisations that run them.

How do you monitor infrastructure without adding a cyber attack surface?

By using sensors that transmit and never receive. There is no inbound radio path to the sensor, so it cannot be reached, reconfigured or interfered with over the air; there is no IP networking at the point of measurement, so there is nothing to scan, address or patch in the field. Readings travel one way over licence-free radio to a gateway and on to the platform, and the monitoring layer never joins the networks it watches.

Does this connect to site IT or OT networks?

No. The sensors carry no IP networking and do not join any site network. They report one way over licence-free 433 MHz and 868 MHz radio to a dedicated gateway, and the gateway backhauls to the platform independently of the site's IT estate and of the OT systems in control of the process.

Can this operate on unmanned or unpowered sites?

Yes. The sensor tags are battery-powered with years of field life and need no power, wiring or network at the point of measurement, so they suit compounds, cabinets and structures that stand unmanned for long periods. The one powered element is the gateway, which runs from mains, a DC feed or solar where no supply exists, and the radio layer is engineered so reads arrive from basements, steel enclosures and remote positions.

Is this a certified security or life-safety system?

No. It is a monitoring and operational visibility layer, provided on a best-endeavours basis. It complements certified alarm systems, protective-security arrangements and regulated life-safety signalling by adding independent remote visibility of site and equipment state; it does not replace them, and no certification or accreditation is claimed.

See the estate
without exposing it.

Tell us about the estate: the site types, the equipment that only signals locally, the response arrangement and the constraints that rule other systems out. We will scope a monitoring layer that adds visibility without adding an attack surface.

Location

Venator House, 15-17 St Stephen's Road, Bournemouth

Dorset BH2 6LA · VAT GB 409644484

CNI monitoring enquiry

Tell us about the sites, asset classes, alert routing and constraints you need monitoring to work within. Please keep enquiries at a public-safe level of detail.

No mailing lists. No spam. We reply directly to your enquiry.