What you are evaluating
Evaluate the asset visibility, threat detection and investigation software explicitly quoted. OT Watch, incident-response services, WorldView intelligence and newer platform extensions have separate scope; a platform purchase does not establish a staffed response commitment.
A useful evaluation context
Teams that need industrial investigation context and a defined handoff between security analysts and plant engineers.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Industrial network monitoring supplies device and communication context.
- Threat detections and case workflows help analysts investigate industrial activity.
- A documented ServiceNow integration supplies OT asset and vulnerability context to enterprise workflows.
Where it fits in the work
- Map one process cell and identify the approved collection point with its engineer.
- Review an alert alongside the affected assets and maintenance schedule.
- Use the relevant playbook to propose a reversible action and hand it to the process owner.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
In a simulator, an engineering workstation communicates with a controller outside its maintenance window. Write a case that separates the observed network event from the unproven claim that controller logic changed.
Evidence to look for
Include the asset owner, evidence timestamps, approved work order and a decision on whether more evidence is needed. Do not isolate a production controller as a training exercise.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which collection methods and protocol versions are included for this site?
- Which playbooks and intelligence subscriptions are on the proposed license?
- Who approves containment when loss of communication can affect safety?