Documented OT-defense capability coverage
What current official provider records document across the normalized defensive capability model—and what those counts cannot establish.
What current official provider records document across the normalized defensive capability model—and what those counts cannot establish.
The maintained dataset joins 45 organization records, 26 normalized capabilities, 10 operating models, 19 authority records, and 10 operating domains. Counts describe the research corpus; they are not a market-size or quality score.
Key findings
IT Security-Operations Integration And APIs appears in 45 of 45 maintained organization records, the highest documented count in the current sample. Unidirectional Transfer And Network Isolation appears in 2. A higher count signals more public positioning, not greater importance or product quality.
What the count can support
The dataset can show how frequently a capability appears in approved official positioning, which operating models document it, and where a buyer may find research candidates. It cannot show depth, accuracy, configured availability, implementation quality, adoption, satisfaction, commercial fit, or outcome.
Methodology
- Define the market boundary, exclusions, operating models, and capability taxonomy before classifying organizations.
- Require an approved official source for organization inclusion and each documented capability.
- Keep authority sources, provider claims, independent observations, editorial synthesis, and unknowns in separate evidence states.
- Use one primary operating model per organization while retaining adjacent scope in the narrative record.
- Preserve source URLs, review dates, material changes, limitations, and correction history.
Limitations
- The maintained population is substantial but not claimed to be a complete global market.
- Official public documentation may omit available capabilities or lag product and service changes.
- Documented positioning does not measure product depth, configured availability, independent performance, implementation effort, customer outcome, or commercial terms.
- Authority mappings are editorial research aids and do not establish buyer-specific applicability or product conformity.
- No organization may purchase inclusion, classification, finding, or correction outcome.
Reproducibility and updates
The report is reproduced from the provider registry, normalized facts and evidence, authority and domain records, and the publication taxonomy. A material change requires a dated source and editorial explanation. Historical values remain available through the change ledger rather than disappearing when the current record changes.
Research boundary
OT Defense Review is not a regulator, standards body, certification body, control-system integrator, safety authority, engineering firm, incident-response provider, insurer, or law firm. Its records support market research and decision review; they do not establish compliance, certification, security, safety, reliability, exploitability, or fitness for a specific operational environment.