TOPGEAR: Organizational Risk Intelligence for Critical Infrastructure

Identify adversarial influence in critical infrastructure — automatically, at scale, before it becomes a national security problem.
Technology No. CW-25-44
Overview

TOPGEAR is an intelligence automation platform that maps the organizational relationships surrounding critical infrastructure — uncovering how foreign investment, mergers and acquisitions, and adversarial business practices create risk to the facilities that power, fuel, and sustain national operations. Where manual analysis takes weeks and misses critical connections, TOPGEAR builds and interrogates adversarial sociotechnical networks in hours, enabling analysts to focus on judgment rather than data collection.

Built for the analysts, lawyers, underwriters, and regulators who must make high-stakes decisions about infrastructure ownership and transactions, TOPGEAR transforms fragmented public records — SEC filings, infrastructure asset databases, corporate registries — into actionable intelligence. The result is a clear, geospatially grounded picture of who controls what, how that control has changed over time, and where the risks lie.

Core Capabilities

  • Automated data ingestion
    • Ingests SEC EDGAR filings, DOE infrastructure databases, CrunchBase, and OpenCorporates via an Apache Airflow pipeline — eliminating manual data gathering and ensuring reproducible, auditable results across every analysis run.
  • Adversarial network construction
    • Iteratively builds Adversarial Sociotechnical Networks (ASTNs) linking organizations, people, and infrastructure facilities — surfacing indirect ownership chains and hidden relationships that manual review consistently misses.
  • Graph-theoretic risk analysis
    • Applies network complexity metrics — degree distribution, reachability, community detection, and temporal analysis — to quantify organizational influence and flag concentration risk across infrastructure portfolios.
  • Automated reasoning engine
    • Encodes historically-attested adversarial business tactics as inference rules, enabling systematic, repeatable detection of acquisition strategies, asset stranding, and single points of organizational failure — modeled on the structure of MITRE ATT&CK for ICS.
  • Geospatial intelligence dashboard
    • Visualizes organizational influence from national down to county level via interactive heatmaps and facility drill-downs — giving stakeholders immediate situational awareness across their region of interest.
  • Organizational profiles
    • Delivers on-demand structured profiles for any entity in the network — aggregating ownership history, regulatory filings, and infrastructure relationships into a single, analyst-ready view.

Who It Serves

  • CFIUS reviewers and national security analysts — Accelerate transaction reviews under FIRRMA by rapidly mapping foreign investment exposure across specific infrastructure lifecycle stages, reducing review cycles from weeks to hours.
  • CFIUS legal counsel — Build evidentiary-quality organizational maps for M&A filings and voluntary notices, backed by traceable, reproducible data pipelines rather than manual research.
  • Infrastructure insurance underwriters — Quantify organizational risk at the facility level, informing premium decisions and coverage terms with data-driven assessments of ownership concentration and adversarial exposure.
  • Utilities and energy operators — Evaluate the organizational risk profile of facility designs and vendor relationships, particularly for emerging assets like Battery Energy Storage Systems (BESS) and EV charging infrastructure where ownership complexity is high.
  • Federal counterintelligence agencies — Monitor adversarial business behavior patterns over time across geographic regions of interest, with a structured threat catalog that organizes tactics by adversarial intent and operational impact.
  • State energy offices and regulators — Identify organizational risk in state infrastructure portfolios, supporting DOE technical assistance programs and informing regulatory action before transactions close
Why It Matters
  • Scale without adding headcount. TOPGEAR automates the network construction and analysis tasks that previously required teams of analysts, enabling the same team to cover more transactions, more facilities, and more regions simultaneously, with consistent methodology every time.
  • Catch what manual review misses. Indirect ownership chains, shell company relationships, and time-shifted acquisition strategies are invisible to traditional research. TOPGEAR surfaces them systematically, by design.
  • Earlier risk identification. By tracking organizational changes across infrastructure lifecycle stages, TOPGEAR flags risk indicators before transactions close or operational impact materializes — shifting the analysis from reactive to proactive.
  • Reproducible, auditable analysis. Every network and finding is traceable to its source data and reproducible on demand, critical for regulatory review, legal proceedings, and interagency coordination.
  • Purpose-built for infrastructure context. Unlike general supply chain illumination tools, TOPGEAR aligns risk indicators to infrastructure lifecycle stages, so findings are directly relevant to the regulatory and operational context of each review, not just a data dump.
  • Extensible to new domains. The ontology-driven pipeline adapts to new infrastructure types, data sources, and adversarial tactics without re-engineering, protecting the investment as the threat landscape evolves.

Licensing and Access

TOPGEAR is copyrighted software available under a commercial license. Licensing is required for all commercial, government, and research deployments. Contact our licensing team to discuss deployment options, integration requirements, and pricing.

To inquire about licensing, click Contact Us.

  • expand_more mode_edit Authors (3)
    Gabriel A Weaver
    Mary S Klett
    Steven M Hall
  • expand_more cloud_download Supporting documents (0)
Questions about this technology?