OT / CPS / Cisco

Cisco Cyber Vision

Cisco Cyber Vision can collect OT observations using sensors embedded in supported network equipment or other deployment options. Learners can follow industrial traffic from the collection point to asset, flow and event context in Cyber Vision Center, then consider how that context informs network policy.

Industrial network visibility and securityResearch reviewed

What you are evaluating

Evaluate the sensor and Center configuration for the actual hardware and software release. Current product material also describes segmentation and remote access; validate the relevant hardware, entitlement and enforcement components separately.

A useful evaluation context

Teams designing OT visibility around supported industrial networking infrastructure.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Sensors inspect industrial traffic and send identified assets, flows and security events to Center.
  • Supported passive mirroring and Active Discovery provide different collection paths.
  • The sensor guide states TCP and UDP inspection limits and named industrial protocols.

Where it fits in the work

  1. Check that the proposed switch or router supports the intended sensor release.
  2. Validate a mirrored lab conversation in Center and compare it with the known equipment inventory.
  3. Use the observed flow to propose a policy, then test its impact before enforcement.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

A plant has Cisco access switches and a non-Cisco legacy cell. Design how each cell supplies observable traffic, using supported embedded or external collection paths.

Evidence to look for

Produce a coverage map with explicit blind spots. Explain why a Center asset map does not establish that every serial or non-IP process is visible.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which sensor deployment supports this site’s existing equipment?
  2. What traffic falls outside the documented TCP/UDP inspection scope?
  3. Which current features require additional hardware, modules or external enforcement?

Find your next idea.

Tip: press / to open search. Escape closes this window.