Provisional editorial research based on public documentation, not tested effectiveness.
First edition · Reviewed · Rubric 1.1
Six dimensions, each scored 0.0–5.0 in tenths. Gaps stay visible.
Commercial industrial asset visibility, communication monitoring and threat-investigation software. Exact local software scope is stated per offering; managed response, remote-access enforcement, medical-device specialty modules and broader exposure suites are excluded.
Each row is one 0.0–5.0 dimension. Every assessed offering has a consistent color, shape, and number. Numbers identify offerings, not rank. Unknown scores are omitted.
Separated marks connect to their exact positions. Separation does not change scores.
Momentum: building history. Numbers identify offerings, not rank; lines between dimensions are profiles, not time.
Missing evidence for this view
Unknown is not a low score. Select an offering above to inspect its evidence.
A position is only half the story
Momentum
Building history
Baseline recorded 2026-09-21. A second comparable review is needed to show movement.
Own movement is the score change. Relative movement subtracts the median change of matched peers, excluding this offering. Dimensions stay separate.
Dragos Platform· movement by dimension
Dimension
Own movement
Against peers
Operational maturity
Building history
Not available yetNo direction inferred
Shipped innovation
Building history
Not available yetNo direction inferred
Capability breadth
Building history
Not available yetNo direction inferred
Ecosystem & integration
Building history
Not available yetNo direction inferred
Governance & control
Building history
Not available yetNo direction inferred
Operator enablement
Building history
Not available yetNo direction inferred
History appears as a hollow earlier mark connected to the current solid mark in Unfold and Overview. Profile lines between dimensions do not show time. Numbers identify offerings, not rank.
Review history & what changed
The 2026-09-21 baseline incorporates the six-dimension review. Decimal calibration and research corrections are not product momentum. Unknowns stay unknown.
2026-09-21 · baseline · rubric 1.1 · Starting point; no movement inferred.
Tenable One OT Exposure (medium confidence) has the highest documented score (3.0) for Operational maturity among assessed offerings in this comparison group.
Guardian (medium confidence) has the highest documented score (4.0) for Shipped innovation among assessed offerings in this comparison group.
Unknowns and gaps
Unknown is not low quality. Marks are omitted where a required score is unknown.
Dragos Platform: Governance & control
Guardian: Governance & control
Continuous Threat Detection (CTD): Governance & control
Tenable One OT Exposure: Governance & control
Scenario lens
A scenario highlights priorities and validation questions only. It does not rewrite scores or claim eligibility.
Selected evidence
Dragos Platform · Dragos
Dragos Platform: industrial visibility, threat detection and investigation software; separate services and newer portfolio extensions excluded · Assessed 2026-09-21 · Research preview
Operational maturity
How complete is the documented collection-to-investigation operating model?
Completeness of the publicly documented operating model, not measured reliability, installed base or vendor size. Anchors are cumulative; missing evidence is unknown, never zero.
Industrial investigation context and playbooks are publicly described. Detailed permission, audit and maintenance procedures were not established in the reviewed public material.
Score2.4 / 5.0medium confidence
Comparison:
Rationale and sources
Collection and alerts establish stage 2. Asset-linked cases and response-playbook context earn 0.4; detailed disposition and tuning controls were not established, so the full stage-3 workflow is not claimed.
How this score is built
2.0 anchor + 0.4 credited progress = 2.4
Next anchor: 3 — Stage 2 plus alert-to-asset evidence context, explicit disposition controls and detection-tuning controls.
+0.4 · Alert-to-asset and supporting-observation investigation context
Case management and response-playbook context connect an alert to investigation.
Not credited: 0.3 · Documented controls to disposition an alert or investigation
Not established by this assessment; no credit. This does not establish absence.
Not credited: 0.3 · Documented controls to adjust detection or baseline handling
Not established by this assessment; no credit. This does not establish absence.
Weights are shared editorial rules for this dimension and anchor interval. They are not measured performance differences.
Constraints
OT Watch, incident response SLAs and WorldView are excluded from software credit.
No automatic containment or new acquisition-derived feature is assumed to be included.
Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership.
This is a public-evidence baseline dated 2026-09-21, not a historical trend or effectiveness ranking.
Stages are cumulative. A catalog profile or a product overview is not equivalent to verified administrator documentation. Missing evidence is null where a lower supported stage cannot be established.
The industrial baseline includes inventory, communications, alerts, exposure context and investigation. Extra innovation credit requires an inspectable additional mechanism, operator controls and explicit limits.
Equal positions are permitted. Decimal refinements use the same weighted criteria for every offering, totaling ten tenths, and are never added simply to separate marks.
The catalog includes Armis, Microsoft, Cisco and Fortinet alternatives; their absence from this initial cohort is not a negative evaluation.
FortiNDR for OT is a network-detection adjacency, not assumed equivalent to controller configuration visibility.
No current vendor receives high confidence from documentation alone.
How to read these scores
Scores use tenths from 0.0 to 5.0 against published anchors. Fractional scores credit documented requirements toward the next anchor; the inspector exposes the calculation. Equal evidence can still produce a tie. Null means unknown and is never treated as zero. Views never average or blend dimensions into an overall winner. Cohort membership is the only comparison boundary.
What this edition covers.
First edition · reviewed · rubric 1.1. Historical movement will require later dated assessments; no trajectory is inferred from this snapshot.
This is a public-evidence baseline dated 2026-09-21, not a historical trend or effectiveness ranking.
Stages are cumulative. A catalog profile or a product overview is not equivalent to verified administrator documentation. Missing evidence is null where a lower supported stage cannot be established.
The industrial baseline includes inventory, communications, alerts, exposure context and investigation. Extra innovation credit requires an inspectable additional mechanism, operator controls and explicit limits.
Equal positions are permitted. Decimal refinements use the same weighted criteria for every offering, totaling ten tenths, and are never added simply to separate marks.
The catalog includes Armis, Microsoft, Cisco and Fortinet alternatives; their absence from this initial cohort is not a negative evaluation.
FortiNDR for OT is a network-detection adjacency, not assumed equivalent to controller configuration visibility.
No current vendor receives high confidence from documentation alone.
Industrial visibility & detection
Commercial industrial asset visibility, communication monitoring and threat-investigation software. Exact local software scope is stated per offering; managed response, remote-access enforcement, medical-device specialty modules and broader exposure suites are excluded.