OT / CPS / Dragos

Dragos Platform

The Dragos Platform brings industrial asset context, network observations and OT threat detections into an investigation. Its response playbooks are a useful teaching example: an alert becomes a question about a physical process, a responsible engineer and an action that can be performed safely.

Industrial visibility and threat detectionResearch reviewed

What you are evaluating

Evaluate the asset visibility, threat detection and investigation software explicitly quoted. OT Watch, incident-response services, WorldView intelligence and newer platform extensions have separate scope; a platform purchase does not establish a staffed response commitment.

A useful evaluation context

Teams that need industrial investigation context and a defined handoff between security analysts and plant engineers.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Industrial network monitoring supplies device and communication context.
  • Threat detections and case workflows help analysts investigate industrial activity.
  • A documented ServiceNow integration supplies OT asset and vulnerability context to enterprise workflows.

Where it fits in the work

  1. Map one process cell and identify the approved collection point with its engineer.
  2. Review an alert alongside the affected assets and maintenance schedule.
  3. Use the relevant playbook to propose a reversible action and hand it to the process owner.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

In a simulator, an engineering workstation communicates with a controller outside its maintenance window. Write a case that separates the observed network event from the unproven claim that controller logic changed.

Evidence to look for

Include the asset owner, evidence timestamps, approved work order and a decision on whether more evidence is needed. Do not isolate a production controller as a training exercise.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which collection methods and protocol versions are included for this site?
  2. Which playbooks and intelligence subscriptions are on the proposed license?
  3. Who approves containment when loss of communication can affect safety?

Find your next idea.

Tip: press / to open search. Escape closes this window.