OT / CPS / Claroty

Continuous Threat Detection (CTD)

Claroty CTD is an on-premises industrial security platform. Its asset, session and process context supports investigation of unexpected communications. Virtual Zones illustrate a useful distinction for learners: recognizing that a conversation crosses a boundary does not itself install a firewall rule.

Industrial visibility and threat detectionResearch reviewed

What you are evaluating

CTD is evaluated separately from xDome SaaS and xDome Secure Access. Passive monitoring, Active discovery and AppDB collection are different methods with different prerequisites; approve the method for each equipment class.

A useful evaluation context

Operators that prefer on-premises industrial monitoring and need to connect discovery with boundary-policy design.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Passive, Active and AppDB discovery contribute complementary industrial inventory evidence.
  • Virtual Zones organize communications and support cross-zone violation alerts.
  • Exposure and threat views connect observed activity with assets and alert timelines.

Where it fits in the work

  1. Select a supported discovery method and reconcile the resulting inventory with engineering records.
  2. Group the process-cell assets into Virtual Zones and review unexpected inter-zone traffic.
  3. Send a proposed segmentation change to the network and process owners for simulation and approval.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

Use a fictional factory diagram to place a historian, engineering station and controller in zones. Review an unexpected historian-to-controller conversation against the maintenance record.

Evidence to look for

Deliver an allowed-communications table, the evidence supporting the exception and a proposed change test. Keep monitoring and enforcement responsibilities distinct.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which discovery methods are approved by the equipment manufacturer?
  2. Which firewall or NAC connector actually enforces a suggested boundary?
  3. Is secure remote access included or a separately entitled integration?

Find your next idea.

Tip: press / to open search. Escape closes this window.