Product segment / OT / CPS

Operational technology & cyber-physical security

Understand industrial and connected physical systems while preserving safety, availability, and operational context.

8 product profilesResearch reviewed

The job to be done

Identify important devices and suspicious activity so engineering and security teams can agree on a safe response.

Operational technology controls or observes physical processes: production lines, water treatment, building systems and medical infrastructure. OT security begins with understanding those processes and the devices that support them. Visibility and detection products help teams discover assets, interpret industrial communications and investigate changes. Response must account for safety, availability and engineering approval; a technically valid block can still stop an essential process. Start with a bounded visibility pilot and a jointly owned investigation workflow.

What goes in

  • Approved network observations and industrial protocols
  • Engineering inventory and process context
  • Asset exposure and maintenance information

What should come out

  • Device and communication inventories
  • Investigable industrial alerts
  • Prioritized engineering actions and supporting evidence

Inside the segment

These capabilities answer different questions. Use the distinction to define the work before assembling a shortlist.

Industrial asset visibility

Identify devices, relationships and relevant firmware or exposure context.

Boundary: Passive traffic cannot reveal every dormant, serial or disconnected asset; enriched fields need validation.

Industrial threat detection

Investigate unusual commands, communications and process-related changes.

Boundary: An anomaly is evidence to examine, not proof of compromise or permission to stop a process.

Segmentation and remote access

Control which systems and people may reach industrial assets.

Boundary: Monitoring, firewall enforcement and remote-access control may be separate products or modules.

Medical and building systems

Apply connected-device security to patient-support and facilities environments.

Boundary: Specialized device support and clinical or facilities ownership must be verified independently.

How the work flows

  1. Map the process

    Document the physical function, responsible engineer and consequences of lost communication.

  2. Agree collection boundaries

    Choose approved mirror points, passive observation and any device-specific active queries. Record traffic that cannot be observed.

  3. Validate the inventory

    Reconcile observed assets and firmware claims with engineering records and maintenance owners.

  4. Investigate with context

    Compare the alert, process state and change record. Preserve the difference between an observation and a hypothesis.

  5. Approve and verify response

    Have the process owner approve a reversible action, verify the operational outcome and update the baseline.

The environment changes the question

Use these scenarios to adapt the evaluation to your organization. They describe operational concerns, not a determination of compliance.

Finance ↗

A bank’s data-center cooling controller makes a new connection during facilities maintenance.

Evaluate: Confirm the facilities owner and service impact before changing a network rule.

Utilities ↗

An engineering station contacts a substation device outside an approved work window.

Evaluate: Coordinate the investigation with grid operations and preserve process availability.

Manufacturing ↗

A production-cell controller shows a code-transfer event during a shift change.

Evaluate: Reconcile the event with engineering change records before assuming malicious logic.

Healthcare ↗

A hospital building controller communicates with a clinical-network address.

Evaluate: Involve facilities and clinical engineering, protect patient operations and validate device scope.

What drives the operating cost

  • Sensors, licensed assets or throughput and the number of separate industrial sites.
  • Traffic mirroring infrastructure, rugged hardware, storage and disconnected-site maintenance.
  • Optional intelligence, central management, remote access and staffed incident-response services.

Questions worth asking

  1. Which devices and protocols are actually visible from the selected collection points?
  2. Can an alert be explained in terms an engineer can validate?
  3. Which response actions could affect the physical process?

Common assumptions to check

Agentless monitoring is automatically risk-free.

Passive collection and active device queries differ. Validate each collection method and the effect of any response with the process owner.

A detected vulnerability should always be patched immediately.

Equipment support, safety testing and operating windows shape remediation; compensating controls may be necessary.

A visual zone boundary enforces segmentation.

A monitoring view describes communications. Enforcement requires a configured control and a tested policy.

APPLY THE IDEA / EVALUATION PLAN

Make the outcome observable.

Use an isolated industrial simulator and a known device inventory. Review a harmless configuration change and document a response that preserves the simulated process.

  1. Prove visibility

    A reconciled inventory and traffic map that explicitly name dormant, non-IP and unmirrored gaps.

  2. Walk a safe investigation

    A lab alert linked to its source observation, process owner, work order and documented disposition.

  3. Test operational ownership

    A tabletop response with approval, rollback and physical-process verification; no production disruption required.

Use synthetic data and an authorized test environment. Record scope, product edition, permissions, results, and recovery behavior.

Vendors & products

8 profiles

An editorial selection of relevant offerings, with documented scope and practical evaluation questions. Atlas Fold provides a separate provisional documentation assessment for selected offerings; inclusion in this directory is not a ranking.

Dragos / Industrial visibility and threat detection

Dragos Platform

Evaluate the asset visibility, threat detection and investigation software explicitly quoted. OT Watch, incident-response services, WorldView intelligence and newer platform extensions have separate scope; a platform purchase does not establish a staffed response commitment.

Nozomi Networks / Industrial visibility and threat detection

Guardian

This profile covers Guardian and its local analyst functions. Vantage cloud management, Central Management Console, Arc host sensors, Threat Intelligence and Asset Intelligence subscriptions must be scoped separately.

Claroty / Industrial visibility and threat detection

Continuous Threat Detection (CTD)

CTD is evaluated separately from xDome SaaS and xDome Secure Access. Passive monitoring, Active discovery and AppDB collection are different methods with different prerequisites; approve the method for each equipment class.

Armis / OT and IoT asset context and monitoring

Armis Centrix for OT/IoT Security

SaaS and on-premises offerings have different deployment boundaries. This profile covers OT/IoT security; Medical Device Security, vulnerability prioritization and remote-access offerings require their own entitlement checks.

Tenable / Industrial visibility and exposure monitoring

Tenable One OT Exposure

The public 4.7 guide is the technical baseline. OT collection, active queries, Enterprise Manager and broader Tenable One exposure features need an explicit deployment and license map; names from earlier OT Security documentation remain in some URLs.

Microsoft / Industrial network monitoring

Microsoft Defender for IoT (OT monitoring)

OT monitoring is distinct from Enterprise IoT features associated with Defender for Endpoint. The legacy on-premises management console retired in January 2025; individual air-gapped sensors remain supported. The documented Defender portal experience is preview, so this profile uses the Azure portal and sensor workflow.

Fortinet / Network detection for industrial environments

FortiNDR On Premises for OT

This profile concerns the on-premises OT deployment described in the data sheet. FortiNDR Cloud is a distinct deployment. FortiGate, FortiNAC, FortiAnalyzer and FortiSOAR integrations do not imply that those products are included.

Cisco / Industrial network visibility and security

Cisco Cyber Vision

Evaluate the sensor and Center configuration for the actual hardware and software release. Current product material also describes segmentation and remote access; validate the relevant hardware, entitlement and enforcement components separately.

Search this segment ↗

Build the vocabulary

Find your next idea.

Tip: press / to open search. Escape closes this window.