{"kind":"atlas-fold-dated-history","notice":"Documentation research, not measured product performance. The first snapshot is a baseline, not a trend. Compare unchanged scope and rubric; research corrections are not product momentum.","segment":"ot-security","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"ot-security","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"industrial-visibility-detection","name":"Industrial visibility & detection","scope":"Commercial industrial asset visibility, communication monitoring and threat-investigation software. Exact local software scope is stated per offering; managed response, remote-access enforcement, medical-device specialty modules and broader exposure suites are excluded."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Completeness of the publicly documented operating model, not measured reliability, installed base or vendor size. Anchors are cumulative; missing evidence is unknown, never zero.","question":"How complete is the documented collection-to-investigation operating model?","anchors":["The evaluated offering explicitly has no collection or detection workflow.","A public product description identifies the collection or detection purpose.","The offering documents a collection path and alert generation.","Stage 2 plus alert-to-asset evidence context, explicit disposition controls and detection-tuning controls.","Stage 3 plus documented role permissions, audit of analyst or administrative actions, and collection-health monitoring.","Stage 4 plus independently evaluated repeatability of recovery and scaling procedures in the stated deployment."],"refinements":[{"base":2,"criteria":[{"id":"investigation-context","label":"Alert-to-asset and supporting-observation investigation context","weight":4},{"id":"disposition-controls","label":"Documented controls to disposition an alert or investigation","weight":3},{"id":"tuning-controls","label":"Documented controls to adjust detection or baseline handling","weight":3}]},{"base":3,"criteria":[{"id":"access-roles","label":"Documented operational role permissions","weight":3},{"id":"audit-actions","label":"Documented audit of analyst or administrative actions","weight":4},{"id":"sensor-health","label":"Documented collection or sensor health monitoring procedure","weight":3}]}]},{"id":"innovation","name":"Shipped innovation","description":"Documented shipped investigation mechanisms beyond this cohort’s ordinary workflow. AI branding, roadmap promises and effectiveness claims alone earn no extra credit. Anchors are cumulative.","question":"What inspectable, shipped investigation mechanism goes beyond the cohort baseline?","anchors":["The evaluated edition explicitly excludes detection and investigation.","The offering documents collection or inventory only.","The offering additionally documents alert analysis.","Current cohort baseline: industrial inventory, communication context, alerts and their investigation. Ordinary rules, behavioral models and alert correlation are baseline capabilities.","Stage 3 plus an additional shipped investigation mechanism with inspectable output, analyst controls and documented prerequisites or limits.","Stage 4 plus a second distinct mechanism satisfying the same requirements and independent evaluation of the claimed operator benefit."],"refinements":[{"base":3,"criteria":[{"id":"inspectable-output","label":"An additional investigation mechanism produces inspectable evidence or reasoning beyond ordinary alert correlation","weight":4},{"id":"analyst-controls","label":"Documented analyst controls to inspect, adjust or challenge that mechanism","weight":3},{"id":"scope-limits","label":"Its prerequisites, scope and operational limitations are documented","weight":3}]}]},{"id":"breadth","name":"Capability breadth","description":"Documented capabilities within the exact evaluated bundle. Adjacent products, subscriptions and managed services do not inherit credit. Anchors are cumulative.","question":"Which capabilities and deployment environments are evidenced within this bundle?","anchors":["The evaluated edition explicitly has no industrial visibility capability.","Asset inventory is described.","Stage 1 plus communication context or security alerts.","Stage 2 plus both communication views and alerts, and documented vulnerability or exposure context.","Stage 3 plus documented multiple collection methods, multisite operation and protocol or device limitations for the evaluated bundle.","Stage 4 plus an independent evaluation of coverage and blind spots across the stated industrial device families."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"How clearly public sources establish exports and integrations, their scope and operating requirements. A logo wall alone does not prove a working connector.","question":"What integration can an operator actually explain and configure from the reviewed evidence?","anchors":["The offering explicitly excludes exports and integrations.","An integration approach is described at a high level.","Stage 1 plus a documented export or API surface.","Stage 2 plus at least one named integration with its transferred data or action described.","Stage 3 plus procedural configuration, authentication and operational limitation details for the evaluated integration.","Stage 4 plus independently tested failure handling and preservation of investigation context across multiple external systems."]},{"id":"governance","name":"Governance & control","description":"Evidence for who can access data or change operations and how those actions are governed. Missing public access-control detail remains unknown.","question":"Which access and audit boundaries are documented for this exact deployment?","anchors":["The offering explicitly has no access control.","Authentication to the management interface is documented.","Stage 1 plus differentiated operator and administrator roles.","Stage 2 plus documented audit of analyst or administrative changes.","Stage 3 plus granular data/action scope, authentication safeguards and a documented recovery or revocation procedure.","Stage 4 plus independent validation of separation of duties, audit completeness and emergency access within the evaluated edition."]},{"id":"operations","name":"Operator enablement","description":"How far the available documentation helps an operator carry out an investigation and keep collection useful. This measures accessible operating evidence, not staffing quality.","question":"What repeatable investigation and maintenance tasks can an operator learn from the reviewed sources?","anchors":["The offering explicitly has no operator workflow.","Public material explains the workflow at overview level.","Stage 1 plus a documented operator task with concrete interface controls or steps.","Stage 2 plus an analyst investigation task and guidance for adjusting detection handling.","Stage 3 plus collection-health troubleshooting and a reproducible evidence-export or query procedure.","Stage 4 plus a documented training/lab path and tested restoration or recovery procedure for this deployment."]}],"assessments":[{"vendor":"dragos-platform","cohort":"industrial-visibility-detection","edition":"Dragos Platform: industrial visibility, threat detection and investigation software; separate services and newer portfolio extensions excluded","asOf":"2026-09-21","status":"research-preview","summary":"Industrial investigation context and playbooks are publicly described. Detailed permission, audit and maintenance procedures were not established in the reviewed public material.","dimensions":{"maturity":{"score":2.4,"confidence":"medium","rationale":"Collection and alerts establish stage 2. Asset-linked cases and response-playbook context earn 0.4; detailed disposition and tuning controls were not established, so the full stage-3 workflow is not claimed.","sourceIds":["dragos","dragos-response"],"refinement":{"base":2,"evidence":[{"criterion":"investigation-context","rationale":"Case management and response-playbook context connect an alert to investigation.","sourceIds":["dragos-response"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Asset context, detections and investigation playbooks meet the current industrial workflow baseline. New AI and expanded-portfolio descriptions are not credited as independently established, in-scope investigation mechanisms.","sourceIds":["dragos","dragos-response"]},"breadth":{"score":3,"confidence":"medium","rationale":"The platform describes industrial assets, network monitoring, detections and vulnerability context. The reviewed material does not provide the complete bundle-specific collection, multisite and protocol-limit evidence required for stage 4.","sourceIds":["dragos","dragos-network"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"The named ServiceNow integration transfers OT asset and vulnerability context, establishing an export/integration path. Reviewed sources do not establish its authentication and failure-handling procedures.","sourceIds":["dragos-snow"]},"governance":{"score":null,"confidence":"low","rationale":"The reviewed product and integration sources do not establish interface authentication, differentiated role permissions and audit procedures for this exact software scope. This is a public-evidence gap, not a claim that the controls are absent.","sourceIds":["dragos","dragos-response"]},"operations":{"score":1,"confidence":"medium","rationale":"The product page describes case and playbook concepts, but an accessible operator procedure with concrete controls was not established in this review. No higher operational-documentation stage is inferred from a services offer.","sourceIds":["dragos-response"]}},"constraints":["OT Watch, incident response SLAs and WorldView are excluded from software credit.","No automatic containment or new acquisition-derived feature is assumed to be included.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership."],"sources":[{"id":"dragos","title":"Dragos Platform capabilities","url":"https://www.dragos.com/cybersecurity-platform/","accessedAt":"2026-09-21","kind":"product"},{"id":"dragos-response","title":"Dragos investigation and response","url":"https://www.dragos.com/cybersecurity-platform/ot-incident-response","accessedAt":"2026-09-21","kind":"product"},{"id":"dragos-network","title":"Dragos network monitoring","url":"https://www.dragos.com/network-security-monitoring","accessedAt":"2026-09-21","kind":"product"},{"id":"dragos-snow","title":"Dragos and ServiceNow integration","url":"https://www.dragos.com/partner/servicenow","accessedAt":"2026-09-21","kind":"product"}]},{"vendor":"nozomi-guardian","cohort":"industrial-visibility-detection","edition":"Nozomi Guardian local sensor and analyst interface; Vantage, CMC, Arc and optional intelligence subscriptions excluded","asOf":"2026-09-21","status":"research-preview","summary":"Guardian exposes asset and alert context, analyst queries and historical snapshot comparison. The assessment keeps optional management and enrichment products outside the local-sensor scope.","dimensions":{"maturity":{"score":2.4,"confidence":"medium","rationale":"The overview documents collection and alerts; asset, network and query views support alert-to-evidence investigation (+0.4). Complete disposition and detection-tuning procedures were not verified in the selected sources, so stage 3 is withheld.","sourceIds":["guardian","guardian-ui","guardian-query"],"refinement":{"base":2,"evidence":[{"criterion":"investigation-context","rationale":"The user guide links alerts, assets, network observations and N2QL queries.","sourceIds":["guardian-ui","guardian-query"]}]}},"innovation":{"score":4,"confidence":"medium","rationale":"The baseline inventory, communications and alert-investigation workflow is supplemented by Time machine: users compare stored states, request differences, and exclude routinely changing fields. The documented prerequisite is saved snapshots; the comparison is evidence of change, not proof of attack.","sourceIds":["guardian","guardian-ui","guardian-time"]},"breadth":{"score":3,"confidence":"medium","rationale":"The overview documents assets, communication views, alerts and vulnerability context. Optional polling, central management and intelligence subscriptions are not combined into a broader stage-4 bundle without their exact entitlements and device limits.","sourceIds":["guardian","guardian-ui"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"The user and administration guides expose report/export and data-integration surfaces. They do not establish a named external connector’s transferred data and configuration in the reviewed scope.","sourceIds":["guardian-ui","guardian-admin"]},"governance":{"score":null,"confidence":"low","rationale":"Administration is privilege-gated and Users/Audit pages are listed, but the selected sources do not establish the actual role matrix and authentication workflow. Those menu names are insufficient to infer a governance stage.","sourceIds":["guardian-admin"]},"operations":{"score":2,"confidence":"medium","rationale":"The N2QL and snapshot documentation describes concrete analyst controls and query work. Complete detection-handling adjustment and maintenance procedures were not verified, so the cumulative stage-3 requirement is not claimed.","sourceIds":["guardian-query","guardian-time"]}},"constraints":["Snapshot availability and retention determine what historical comparison can show.","Public administration navigation is not proof of a tested permission or audit boundary.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership."],"sources":[{"id":"guardian","title":"Guardian overview","url":"https://technicaldocs.nozominetworks.com/guardian/latest/products/guardian/topics/intro/c_guardian.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"guardian-ui","title":"Guardian user guide","url":"https://technicaldocs.nozominetworks.com/guardian/latest/products/n2os/topics/sensors/c_n2os_sensors.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"guardian-admin","title":"Guardian administration","url":"https://technicaldocs.nozominetworks.com/guardian/latest/products/n2os/topics/administration/c_n2os_admin_page_guardian_html.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"guardian-query","title":"Guardian queries","url":"https://technicaldocs.nozominetworks.com/guardian/latest/products/n2os/topics/queries/c_n2os_queries.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"guardian-time","title":"Guardian Time machine snapshots","url":"https://technicaldocs.nozominetworks.com/guardian/latest/products/n2os/topics/time-machine/c_n2os_time-machine.html","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"claroty-ctd","cohort":"industrial-visibility-detection","edition":"Claroty Continuous Threat Detection on-premises; xDome SaaS and xDome Secure Access excluded","asOf":"2026-09-21","status":"research-preview","summary":"CTD describes several industrial discovery methods, communication zones and contextual alert timelines. Public product evidence supports the baseline; detailed console operations remain unverified.","dimensions":{"maturity":{"score":2.4,"confidence":"medium","rationale":"Discovery and threat detection establish stage 2. Contextualized alert timelines tied to industrial assets earn investigation-context credit (+0.4); concrete disposition and tuning controls were not verified.","sourceIds":["ctd","ctd-ds"],"refinement":{"base":2,"evidence":[{"criterion":"investigation-context","rationale":"The CTD description connects detections with asset, session and process context in alert timelines.","sourceIds":["ctd"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Industrial discovery, communication baselines, exposure context and threat investigation meet the current cohort baseline. Virtual Zones and detection-engine branding do not alone establish an additional inspectable workflow with documented controls and limits.","sourceIds":["ctd","ctd-ds"]},"breadth":{"score":3,"confidence":"medium","rationale":"CTD describes inventory, communication/zone views, exposure assessment and detection. Several discovery methods are named, but a complete evaluated-bundle multisite and protocol-limitation map was not established for stage 4.","sourceIds":["ctd","ctd-ds"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"The product description names Rockwell AssetCentre data-management integration and firewall/NAC enforcement paths. These establish transferred industrial context; auth and connector configuration procedures were not verified.","sourceIds":["ctd"]},"governance":{"score":null,"confidence":"low","rationale":"Public overview material does not establish CTD authentication, operator-role and audit behavior. On-premises deployment by itself is not evidence of these controls.","sourceIds":["ctd","ctd-ds"]},"operations":{"score":1,"confidence":"medium","rationale":"The accessible product and solution overview explain the workflow but do not supply a verified step-by-step operator task. A demo invitation is not counted as completed training.","sourceIds":["ctd","ctd-ds"]}},"constraints":["Virtual Zones describe a monitoring model; enforcement needs configured firewall/NAC controls.","Active discovery and AppDB prerequisites need equipment-specific approval.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership."],"sources":[{"id":"ctd","title":"Claroty Continuous Threat Detection","url":"https://www.claroty.com/industrial-cybersecurity/ctd","accessedAt":"2026-09-21","kind":"product"},{"id":"ctd-ds","title":"Claroty CTD solution overview","url":"https://web-assets.claroty.com/resource-downloads/ctd-overview-2024.pdf","accessedAt":"2026-09-21","kind":"product"}]},{"vendor":"tenable-ot-exposure","cohort":"industrial-visibility-detection","edition":"Tenable One OT Exposure 4.7 local OT analysis; Enterprise Manager and broader Tenable One modules excluded","asOf":"2026-09-21","status":"research-preview","summary":"The 4.7 event guide supplies concrete asset, controller-code and packet context with disposition controls. Controller support and collection method remain explicit pilot questions.","dimensions":{"maturity":{"score":3,"confidence":"medium","rationale":"The product documents collection and detections. The event guide links source/destination assets and supporting evidence, exposes Resolve and Exclude controls, and describes policy-linked event handling; together these establish stage 3. It does not establish the complete role/audit/health set for stage 4.","sourceIds":["ot-tenable","ot-tenable-events"]},"innovation":{"score":3.7,"confidence":"medium","rationale":"The baseline is supplemented by controller-code context: inspectable code elements (+0.4) and expandable blocks/rungs/tags (+0.3). A supported-controller and collection-prerequisite matrix for this mechanism was not verified, so the final 0.3 and stage 4 are withheld.","sourceIds":["ot-tenable","ot-tenable-events"],"refinement":{"base":3,"evidence":[{"criterion":"inspectable-output","rationale":"The Code tab exposes code evidence for listed controller activities.","sourceIds":["ot-tenable-events"]},{"criterion":"analyst-controls","rationale":"Operators can expand code-tree elements to inspect blocks, rungs and tags.","sourceIds":["ot-tenable-events"]}]}},"breadth":{"score":3,"confidence":"medium","rationale":"Product and event sources establish inventory, network context, alerts and exposure assessment. Additional collection, multisite and device-limit evidence for a precise bundle would be required for stage 4.","sourceIds":["ot-tenable","ot-tenable-events"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"The published GraphQL schema establishes an API surface. A named external connector with verified data mapping and authentication procedures was not established from this schema alone.","sourceIds":["ot-tenable-api"]},"governance":{"score":null,"confidence":"low","rationale":"Resolved-by and resolved-on event fields are useful case provenance, but do not establish differentiated console roles or a full action-audit control. Governance remains unknown for this review.","sourceIds":["ot-tenable-events"]},"operations":{"score":3,"confidence":"medium","rationale":"The Events guide explains investigation pivots, resolution and policy exclusions through named interface controls. Collection-health troubleshooting and a complete export/query procedure were not verified as a cumulative stage-4 package.","sourceIds":["ot-tenable-events"]}},"constraints":["The current public name is Tenable One OT Exposure; some URLs retain OT-security.","Controller-code detail is not assumed available for every vendor, protocol or collection method.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership."],"sources":[{"id":"ot-tenable","title":"Tenable One OT Exposure","url":"https://www.tenable.com/products/ot-security","accessedAt":"2026-09-21","kind":"product"},{"id":"ot-tenable-docs","title":"Tenable One OT Exposure documentation and versions","url":"https://docs.tenable.com/OT-security.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ot-tenable-events","title":"Tenable One OT Exposure 4.7 events","url":"https://docs.tenable.com/OT-security/4_7/Content/Events/Events.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"ot-tenable-api","title":"Tenable OT Exposure GraphQL API schema","url":"https://docs.tenable.com/OT-security/api/","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"single-plant","name":"One industrial site","description":"A plant needs a trustworthy inventory and an investigation handoff that preserves its physical process.","priorities":["breadth","operations","governance"],"questions":["Which devices and communication paths are observable without an active query?","Who confirms asset identity and authorizes a disruptive action?","Can an analyst reproduce the evidence and explain an uncertainty?"]},{"id":"disconnected-sites","name":"Disconnected facilities","description":"A utility evaluates local collection with controlled update and evidence-transfer paths.","priorities":["maturity","governance","ecosystem"],"questions":["What continues to work without internet connectivity?","How are updates and role changes applied to isolated sensors?","What evidence can be exported with its original timestamps?"]}],"researchNotes":["This is a public-evidence baseline dated 2026-09-21, not a historical trend or effectiveness ranking.","Stages are cumulative. A catalog profile or a product overview is not equivalent to verified administrator documentation. Missing evidence is null where a lower supported stage cannot be established.","The industrial baseline includes inventory, communications, alerts, exposure context and investigation. Extra innovation credit requires an inspectable additional mechanism, operator controls and explicit limits.","Equal positions are permitted. Decimal refinements use the same weighted criteria for every offering, totaling ten tenths, and are never added simply to separate marks.","The catalog includes Armis, Microsoft, Cisco and Fortinet alternatives; their absence from this initial cohort is not a negative evaluation.","FortiNDR for OT is a network-detection adjacency, not assumed equivalent to controller configuration visibility.","No current vendor receives high confidence from documentation alone."]},"changes":[]}]}