OT DEFENSEREVIEW

Intelligence for systems that move the physical world.

Privileged operations · Analysis

Lead story: ConsoleWorks logs need command-to-process consequence mapping

ConsoleWorks describes recorded sessions, configuration evidence, and asset context. An OT assurance record still has to connect each consequential command with the device response and physical operating effect before reviewers can reconstruct what changed.

Operational technology defense intelligence

View newsroom

CylusOne alerts need rail-topology and operating context

Cylus presents rail-specific asset discovery, threat detection, investigation context, and mitigation playbooks across rolling stock, trackside, stations, communications, and control centers. A rail operator still has to join an alert to the affected topology, service state, safety constraints, accountable owner, and authorized response.

Map Yokogawa SOC handoffs by site, owner, SLA, and plant state

Yokogawa presents a managed IT/OT security operations center with continuous monitoring, incident tickets, workflows, and service levels. Buyers need a site-specific handoff matrix showing who owns triage, when the plant team takes control, how operating state changes escalation, and which evidence closes the service-customer loop.

Phosphorus automation does not bypass OT change authority

Phosphorus describes automated xIoT remediation for credentials, firmware, certificates, risky configurations, and unnecessary services. In an operating environment, safe automation still needs asset identity, engineering scope, approved preconditions, production timing, rollback, and observed process-state evidence.

A Palo Alto OT asset profile is not communication authority

Palo Alto Networks describes passive OT asset discovery, profiling, risk context, and policy controls. A device profile can inform review, but permitted communications still require validated identity, process context, zone and conduit intent, engineering constraints, approved rules, controlled change, and post-change evidence.

A NetRise firmware finding is not site-specific OT risk

Binary-derived component inventory and reachability analysis can sharpen firmware review, but an asset owner still has to prove device identity, deployed version, exposure, process consequence, and change authority.

An OTbase firmware record needs device and configuration lineage

OTbase documents a contextualized OT asset inventory with device, firmware, topology, lifecycle, and vulnerability context. A firmware value becomes actionable only when it is tied to the correct physical device, acquisition method, observation time, engineering baseline, process role, exposure, approved change, and recovery evidence.

How the market is organized

Explore all
Visibility and context

An asset list is not an operational model

OT defense begins with identity, role, location, ownership, criticality, communication, dependency, version, configuration, exposure, and lifecycle. Collection methods have different coverage and operating risks.

Read the market record →
Detection and investigation

Network telemetry must lead to an accountable decision

Protocol decoding, baselines, threat content, packets, alerts, and cases matter only when teams can interpret process context, preserve evidence, and coordinate a response that does not create avoidable operational harm.

Read the market record →
Access and architecture

Remote work, identity, zones, and conduits are one control system

Vendor maintenance, engineering access, credentials, session paths, file transfer, emergency use, segmentation, and fail states need an explicit architecture and accountable owner at each boundary.

Read the market record →
Resilience and lifecycle

Protection is incomplete without recoverable operations

Exposure decisions, backups, configuration baselines, tested restoration, spares, incident authority, safety coordination, and product-support lifecycles determine whether a defense program can sustain the physical mission.

Read the market record →

Authorities and standards board

Explore all
NIST SP 800-82 Rev. 3
NIST SP 800-82 Rev. 4 pre-draft
NIST CSF 2.0
ISA/IEC 62443-2-1:2024
IEC PAS 62443-2-2:2025
OT defense operating domains
Asset inventory, context, and lifecycle
Network architecture, segmentation, and conduits
Vulnerability, exposure, and remediation governance
Detection, investigation, and operational response
Remote access, identity, and third-party control

Defense systems and organizations

Explore all

Industrial defense change log

Explore all
Transaction announcementAccenture announces agreements involving Dragos, runZero, and NetRise

The proposed combination could alter ownership, packaging, data, services, partner relationships, and the OT security market architecture.

Regulatory milestoneEU Cyber Resilience Act Chapter IV begins applying

Industrial product suppliers and buyers need exact legal-role, product, conformity, reporting, support, and evidence records tied to the staged dates.

Acquisition completionDragos completes acquisition of Phosphorus

Ownership is established, while product integration, packaging, migration, support boundaries, data handling, and operating changes still require dated evidence rather than inference from the transaction alone.

Acquisition closeServiceNow completes the Armis acquisition

Buyers need current evidence for product identity, packaging, workflow, data governance, integrations, and organizational responsibility after the ownership change.

Provider researchDragos releases its 2026 OT cybersecurity year in review

Readers should preserve sample, denominator, method, source population, and provider-research classification beside every reported finding.

Standards developmentNIST begins the SP 800-82 Rev. 4 pre-draft process

Programs should preserve Rev. 3 as current final guidance while tracking the revision through explicit development states.

Control Systems Research Desk

Explore all
OT DEFENSE REVIEW · 2026OT defense market architectureIndependent market research
Original analysis

How monitoring, exposure, access, segmentation, endpoint, controlled-transfer, OEM, managed-defense, and risk platforms divide the defensive stack.

The research connects the provider market, normalized capabilities, authority records, operating domains, and source limitations rather than presenting a score or universal winner.

Read the report →
Conditional comparisons

Compare operating fit, not popularity

Dragos Platform vs Claroty
Nozomi Networks vs Tenable OT Security
Armis Centrix vs Forescout
Microsoft Defender for IoT vs Cisco Cyber Vision
Palo Alto Networks OT Security vs Fortinet OT Security