Elisity Blog

7 Top OT Security Vendors for 2026: Securing ICS and Industrial Control Systems [Compared]

According to the SANS 2025 State of ICS/OT Security Survey, 22% of organizations experienced a cybersecurity incident affecting their ICS or OT systems in the past year. Forty percent of those incidents caused operational disruption. Meanwhile, Dragos reports 708 ransomware incidents hitting industrial entities in Q1 2025 alone, with manufacturing absorbing 68% of them. Dragos estimates OT cyber incidents put $329.5 billion per year at risk globally, and $172.4 billion of that comes from business interruption.

If you’re a CISO, security architect, or IT leader at a manufacturing, healthcare, or industrial organization, you can’t treat OT security as a someday project. Waiting is a decision too, and rarely a good one. This guide compares eight leading OT security vendors, the OT cybersecurity companies and vendors producing documented outcomes at enterprises with tens of thousands of connected devices, and shows how they fit together in a layered security architecture.

Top OT security vendors compared for 2026, illustrated over a modern industrial manufacturing facility
Leading OT security vendors are evolving to protect industrial control systems with identity-based microsegmentation and zero trust architectures.

Quick Answer: Eight vendors are shaping OT and industrial control system security in 2026: Elisity (identity-based microsegmentation, rapid non-disruptive deployment), Dragos (OT threat intelligence and incident response), Claroty (CPS platform breadth and asset discovery), Nozomi Networks (large-scale OT/IoT visibility, AI-powered detection), Armis (agentless asset intelligence), Tenable (OT vulnerability management), Palo Alto Networks (enterprise-scale OT network security), and Forescout (agentless IT, OT, IoT and IoMT discovery plus switch-based enforcement). Most organizations deploy two or three of these together, tailored to their environment, regulatory requirements, and operational complexity.

Updated 16 August 2026. Every vendor capability statement in this guide is drawn from that vendor’s own current public documentation, and product names are current as of that date. Forescout renamed the Forescout 4D Platform to the Forescout Vistaro platform on 24 June 2026 and described the change as “an update only to the name”.

The two lanes, in one line: most of these vendors lead in OT detection and visibility, while Elisity occupies the OT segmentation and enforcement lane, identity-based, agentless, and deployable without production downtime over any data plane. The two are complementary: detection tells you what moved, enforcement stops the lateral movement in the first place. For the IT and OT convergence playbook, see our OT security hub. For the manufacturing rollout pattern, see industrial microsegmentation or book a demo.

Detection answers a question after the fact. Enforcement changes the outcome. In OT, where lateral movement is the stage that lets an intrusion reach the systems that actually run production, identity-based segmentation that contains the blast radius is the control that decides whether an intrusion becomes an incident.
Elisity, on the enforcement thesis for OT. Lateral movement is a recurring stage in industrial intrusions, per the Dragos 2026 OT Cybersecurity Year in Review.

How We Evaluated These OT Security Vendors

Picking the right combination of OT security vendors means looking past marketing claims and testing capabilities against real-world industrial requirements. We focused on what matters most to CISOs, security architects, and network leaders protecting critical infrastructure at scale.

Asset Discovery and Visibility comes first. You can’t protect what you can’t see. We researched how each vendor discovers, classifies, and maintains visibility across managed and unmanaged IT, IoT, OT, and IoMT assets, including legacy devices running proprietary protocols that traditional IT security tools miss entirely.

Microsegmentation and Access Control addresses lateral movement, the stage that lets attackers reach high-value systems after an initial compromise. We evaluated whether vendors could enforce granular, identity-based policies without requiring new hardware, agents, or complex VLAN restructuring.

Threat Detection and Response covers each vendor’s ability to spot anomalies, known threat patterns, and suspicious behaviors within OT networks, including integration with broader security operations workflows.

Compliance Alignment matters more than ever. Regulations including IEC 62443, NERC CIP, NIST SP 800-82, NIST Cybersecurity Framework 2.0, HIPAA, and CMMC all increasingly require or strongly recommend network segmentation as a foundational control. We researched how directly each vendor supports these standards.

IT/OT Convergence Support gauges how well vendors handle environments where traditional IT networks intersect with operational technology. Claroty research shows that 55% of OT environments now contain four or more remote access tools, significantly expanding the attack surface.

We also evaluated deployment model and speed (can you deploy without shutting down production?), integration ecosystem (does the solution work with your existing stack?), and analyst and peer recognition (what do Gartner, Forrester, and verified customer reviews say?).

OT Security Vendor Comparison at a Glance

How to Read the OT Security Market: Two Complementary Lanes

Before the vendor-by-vendor detail, it helps to see the market as two lanes that work together rather than one ranked list. Detection and visibility platforms tell you what is on the network and what is behaving abnormally. Segmentation and enforcement platforms decide what is allowed to talk to what, and stop lateral movement before it spreads. Most mature programs run one of each. You can also map this to the OT security convergence playbook if you’re building the program from scratch.

One vendor sits in both lanes. Forescout runs eyeInspect, a passive deep packet inspection sensor for industrial protocols, in the detection lane, and eyeControl and eyeSegment in the enforcement lane. Forescout describes eyeControl as enforcing and automating Zero Trust policies for least-privilege access, and describes eyeSegment as “a unified policy layer across disparate enforcement points”. Evaluate the two halves separately, because the monitoring and enforcement components are licensed separately and the enforcement actions available to you depend on the switch models in your estate.

DimensionLane 1: OT Detection and VisibilityLane 2: OT Segmentation and Enforcement
Core jobSee assets, monitor behavior, detect threatsAllow or block communication by policy; contain blast radius
Primary outcomeAlert on what movedStop what should not move
Representative vendorsDragos, Claroty, Nozomi Networks, Armis, Tenable, Forescout (eyeInspect)Elisity, Forescout (eyeControl, eyeSegment), plus enforcement features within several Lane 1 and firewall platforms
Typical deploymentPassive sensors via SPAN or network tapsPolicy enforced over existing access-layer infrastructure, agentless
IEC 62443 roleInventory and anomaly evidence for zonesImplements the zones-and-conduits boundary itself

SPAN/DPI vs. the Infrastructure You Already Run

The two lanes also differ in how they see the network, and the distinction is a useful buyer test. Lane 1 platforms (Claroty, Dragos, Nozomi Networks, Tenable) typically rely on deep packet inspection, reading a copy of traffic from a SPAN port or a network tap to reconstruct what every device is doing at the protocol level. That produces rich forensic and vulnerability detail. Lane 2 enforcement can work from a lighter signal: the telemetry the infrastructure you already run emits (device tracking tables, NetFlow, and behavior analytics) is enough to attach identity to a device and decide what it may talk to. Both are legitimate visibility models. Deep packet inspection answers what is inside the packets; infrastructure-native telemetry answers who is talking to whom, which is the question enforcement actually has to act on.

This is also the honest division of labor to hold every vendor to. The enforcement lane doesn’t replace the CVE and vulnerability-remediation depth of a specialist OT discovery platform, and a discovery platform doesn’t enforce policy on its own. Ask any vendor which lane it truly owns, and be wary of one that claims to own both outright.

Lane framing reflects current analyst coverage: the Gartner Magic Quadrant for CPS Protection Platforms (February 2025) evaluates the detection and visibility lane, while microsegmentation and enforcement are evaluated in Forrester and Gartner Peer Insights microsegmentation coverage. CISA guidance (July 2025) calls microsegmentation a critical component of zero trust architecture across IT, OT, ICS, and IoT.

Vendor Primary Strength Deployment Model Best For Analyst Recognition
Elisity Identity-based microsegmentation over the infrastructure you already run Software-only, cloud-managed Orgs needing fast, non-disruptive segmentation across IT/OT/IoT Gartner Cool Vendor (CPS Security, 2025); Forrester Wave Strong Performer (Microsegmentation, Q3 2024); Gartner Peer Insights 5.0/5.0
Dragos OT threat intelligence and incident response On-premises sensors, cloud analytics Critical infrastructure needing ICS-specific threat detection and IR Gartner MQ Leader (CPS Protection Platforms, 2025); Peer Insights 4.5/5.0
Claroty CPS platform breadth and deep asset discovery Cloud SaaS (xDome) or on-premises (CTD) Large enterprises with complex, multi-site CPS environments Gartner MQ Leader, highest positioning (CPS, 2025); Peer Insights 4.8/5.0
Nozomi Networks Large-scale OT/IoT visibility with AI-powered detection Cloud SaaS (Vantage) or on-premises sensors Distributed industrial environments needing scalable monitoring Gartner MQ Leader (CPS, 2025); Forrester Wave Leader (IoT Security, Q3 2025); Peer Insights 4.9/5.0
Armis Agentless asset intelligence across 6B+ device profiles Cloud-native SaaS Heterogeneous IT/OT/IoMT environments needing asset visibility Gartner MQ Leader (CPS Protection Platforms, 2025); Peer Insights 4.6/5.0
Tenable OT vulnerability management with IT/OT convergence On-premises with cloud management Organizations extending existing Tenable IT vuln mgmt into OT Gartner Peer Insights 4.9/5.0 (CPS category)
Palo Alto Networks Enterprise-scale OT network security via NGFW portfolio Hardware (NGFW) and cloud (Prisma, Cortex) Enterprises already standardized on Palo Alto for IT security Gartner MQ Leader (Network Firewalls, 2024)
Forescout Agentless discovery across IT, OT, IoT, and IoMT (eyeInspect: 350+ industrial protocols) plus policy orchestration and switch-based enforcement (eyeSegment, eyeControl) Physical appliance, virtual appliance on ESXi, Hyper-V, KVM, or Nutanix AHV, or Docker container sensors Estates wanting monitoring and enforcement from one vendor, with enforcement actions checked against Forescout’s published switch compatibility matrix Gartner Peer Insights 4.3/5.0 from 36 ratings (CPS Protection Platforms)

How the leading OT security vendors compare at a glance, across primary strength, deployment model, ideal environment, and analyst recognition.

Leading OT and ICS Security Vendors in 2026

The OT cybersecurity vendors profiled below span both lanes of the market. Five lead in detection and visibility, one leads in identity-based segmentation and enforcement, one enforces at zone boundaries with firewalls, one spans both lanes, and most programs combine one from each. For the manufacturing rollout pattern specifically, see industrial microsegmentation. If your search is broader than OT, our companion guide to the top microsegmentation solutions for 2026 compares the enforcement lane across all industries.

Elisity: Identity-Based Microsegmentation and Non-Disruptive OT Segmentation

Overview

Elisity takes a different approach to OT security. Rather than layering additional hardware, agents, or complex firewall rules onto already fragile OT environments, Elisity delivers identity-based microsegmentation using the network infrastructure you already run from Cisco, Juniper, Arista, and Hirschmann. Because it’s software-only, organizations can achieve microsegmentation across all users, workloads, and devices in weeks, not the years that legacy segmentation projects typically require.

Elisity was designed around a problem industrial and healthcare teams know well: thousands of diverse, unmanaged, and ephemeral devices that can’t accept agents, can’t tolerate downtime, and can’t easily be re-architected into new VLAN structures. Legacy segmentation has historically failed these environments because of complexity, cost, and operational disruption. Elisity now runs in production across global pharmaceutical manufacturers, large multi-site health systems, and industrial enterprises, at the scale summarized further below.

Key Capabilities

Elisity’s microsegmentation platform has four integrated components that work together to discover, control, and manage security policies across enterprise networks.

Elisity IdentityGraph™ creates a real-time, correlated view of every user, workload, and device on the network, along with their metadata and relationships. By ingesting data from your existing network infrastructure and integrating with 25+ platforms (Claroty, Armis, Nozomi Networks, CrowdStrike, ServiceNow, and others), Elisity IdentityGraph™ builds a continuously enriched identity for every asset. Unlike IP-only discovery, Elisity IdentityGraph™ correlates identity, configuration, risk scores, and behavioral data so security teams can create and enforce policies with confidence, including continuous discovery and visibility of unmanaged and ephemeral IoT, OT, and IoMT assets.

Elisity Cloud Control Center provides centralized visibility, policy configuration, simulation, and analytics. AI and machine learning adapt to network changes and deliver visualizations of networks, zones, and devices with their relationships across locations. For large enterprises managing tens of thousands of devices across multiple sites, Elisity Cloud Control Center lets teams manage policies globally while maintaining granularity down to individual devices.

Elisity Virtual Edge translates identity mappings and policies to your network infrastructure. Policies normalize across multiple network infrastructure vendors and multiple sites, which is essential for organizations running heterogeneous network environments. Elisity Virtual Edge deploys onto the access-layer infrastructure you already run, turning that infrastructure into the enforcement point rather than requiring additional inline appliances or overlay networks.

Elisity Dynamic Policy Engine enables optional dynamic, context-aware policies based on the rich identity information from Elisity IdentityGraph™. Policies can optionally adapt based on risk scores, identity changes, or threat intelligence from integrated security tools, maintaining granular control over network access for every device, wherever and whenever it appears on the network.

Deployment and Operational Impact

Where Elisity really stands apart in OT environments is deployment speed. A typical implementation follows a straightforward timeline: roughly two weeks for planning and training, two days to deploy and configure Elisity Virtual Edge and establish a first policy, and one week or more for policy strategy, simulation, and rollout of the first policies. Compare that to legacy segmentation projects that routinely span years and require dozens of specialized administrators. Weeks versus years is not a rounding error.

In healthcare deployments, teams report bringing campus-wide visibility live in roughly 30 minutes to 2 hours, with no disruption to care. The operational payoff shows up in staffing too: one large health system reduced the team running its legacy NAC and firewall segmentation from more than a dozen people down to a small handful after moving to identity-based microsegmentation.

Proven at scale. Elisity runs in production across environments that include a global pharmaceutical manufacturer with nearly 200 production sites and more than 100,000 devices, a mid-Atlantic health system with roughly 50 sites and nearly 50,000 devices, and one of the largest US health systems, with more than 350 sites and over 500,000 devices. Multiple health systems each run Elisity across more than 100,000 devices, a children’s hospital network covers roughly 80,000 devices across 22 sites, and individual manufacturers run 15,000 to 26,000 OT devices across 23 to 38 sites each. One global industrial electronics manufacturer segmented IT and OT across 53 manufacturing facilities on its existing switching with Elisity’s identity-based, agentless enforcement, avoiding an $18.5 million network-hardware upgrade and cutting OT device onboarding costs by 33%.

Elisity deploys without network downtime and without requiring re-IP projects, new VLANs, additional ACLs, or NAC solutions. In OT environments where production uptime isn’t negotiable, that matters.

Compliance Coverage

Elisity directly supports compliance with IEC 62443 by creating zones and conduits via identity-based microsegmentation, without production disruption. Elisity also accelerates compliance with HIPAA, NIST SP 800-82, NIST CSF 2.0, CMMC, and emerging standards like CISA’s updated Cross-Sector Cybersecurity Performance Goals (CPGs 2.0), which emphasize network segmentation, zero-trust principles, and lateral movement mitigation. Push-button compliance reporting and audit logging make compliance audits faster and more confident.

Analyst and Peer Recognition

Gartner recognized Elisity as a Cool Vendor in Cyber-Physical Systems Security, 2025, citing its ability to transform the infrastructure you already run into policy enforcement nodes that automate least-privilege access for users, workloads, and devices. Elisity was also named a Strong Performer in The Forrester Wave™: Microsegmentation Solutions, Q3 2024, and its approach is analyzed in the Omdia microsegmentation research. On Gartner Peer Insights, Elisity Identity-Based Microsegmentation holds a 5.0 out of 5.0 rating. That recognition tracks with rapid growth: Elisity ranked #13 in North America on the Deloitte Technology Fast 500, with 8,860% revenue growth from 2021 to 2024.

Well-Suited For

Elisity is a strong fit for manufacturing, pharmaceutical, healthcare, and industrial organizations that need microsegmentation fast, without disrupting production or spending heavily on new network hardware. Organizations with 3,000+ connected devices that have not been able to finish legacy segmentation or NAC projects, or those needing to accelerate IEC 62443, HIPAA, or CMMC compliance through network-level controls, will find Elisity’s approach practical and proven. If you’ve been burned by a previous segmentation failure, or shelved segmentation because of its historical complexity, Elisity offers a realistic path forward.

Documented Limits

Elisity does not replace device admission. It enforces identity-based least-privilege policy on the access-layer switches an organization already operates, and something else still decides whether a device is allowed onto the network at all. Enforcement is bounded by a published compatibility matrix of specific hardware models and software versions, and it only covers traffic that traverses that infrastructure, so traffic between devices behind a downstream unmanaged device, or on a daisy-chained run, reaches no enforcement point. Elisity rates its own cloud and Kubernetes support as limited and states that organizations with primarily cloud-native workloads may need to pair it with a cloud-focused tool. Elisity publishes no residual-classification figure and documents a dependency on external sources, with IdentityGraph correlating identity from Active Directory, CMDBs, EDR platforms and tools including Armis, Claroty and Nozomi Networks. Elisity does not publish whether enforcement fails open or fails closed while a Virtual Edge Node reboots or during a Cloud Control Center outage, and publishes no rollback duration; those are the same two gaps recorded for Forescout below, and they should be answered in writing by any vendor on this list.

Complementary Solutions

Elisity’s core strength is microsegmentation and policy enforcement. Organizations that also need passive OT threat monitoring, deep protocol inspection, or vulnerability management can integrate Elisity directly with specialized OT platforms like Claroty, Nozomi Networks, Dragos, Armis, CrowdStrikeTenable and others. This is a division of labor, not a replacement: asset intelligence and threat context from those partner platforms enrich Elisity’s identity-based policy engine, creating a discover-and-protect architecture. Many Elisity customers deploy the platform alongside one or two of these complementary solutions.


The enforcement test for OT is simple: can you segment a brownfield plant without re-IP projects, new hardware, agents on the controllers, or a maintenance window? In safety-critical and uptime-sensitive settings, Elisity teams report bringing campus-wide visibility live in roughly 30 minutes to 2 hours with no disruption to care, precisely because nothing is inserted inline and no agent touches a device that an operator or a clinician depends on.
Elisity, summarizing generalized customer-reported OT and healthcare segmentation outcomes.

See how this maps to a plant floor on the OT network segmentation page, or walk a live policy build in a demo.

Dragos: OT Threat Intelligence and Industrial Incident Response

Overview

Dragos has built its reputation on deep OT threat intelligence and industrial incident response. Founded by former NSA and U.S. Cyber Command professionals, Dragos focuses exclusively on protecting industrial infrastructure, making it one of the most trusted names in OT-specific threat detection. Dragos Platform provides asset visibility, threat detection, and vulnerability management built specifically for ICS/SCADA environments.

Key Capabilities

Dragos Platform delivers OT asset identification, threat detection through behavioral analytics, and vulnerability management tailored to industrial protocols and environments. What truly distinguishes Dragos is its threat intelligence practice: the company tracks 119 ransomware groups targeting industrial organizations (up from 80 in 2024) and publishes the industry’s most widely cited industrial ransomware analysis reports. Their Q1 2025 analysis documented 708 ransomware incidents impacting industrial entities globally, with manufacturing absorbing 68% of those attacks.

Dragos also maintains a dedicated incident response team that has handled some of the most significant OT security incidents worldwide. Their 2026 OT Cybersecurity Year in Review found that 30% of incident response cases began with operational staff reporting abnormal behavior before security teams detected the intrusion. OT-specific detection is what closes that gap.

Compliance Coverage

Dragos provides educational and technical resources for ISA/IEC 62443 implementation and supports NERC CIP compliance monitoring through its platform.

Analyst and Peer Recognition

Dragos was named a Leader in the 2025 Gartner Magic Quadrant for CPS Protection Platforms. Dragos Platform holds a 4.5 out of 5.0 rating on Gartner Peer Insights based on 104 ratings.

Well-Suited For

Organizations that need deep OT threat intelligence, dedicated industrial incident response, and specialized visibility into ICS-specific threats. Dragos is particularly strong for critical infrastructure operators in energy, utilities, and manufacturing that require purpose-built OT detection capabilities.

Complementary Solutions

Dragos’s primary strength is threat detection, intelligence, and incident response. This is a clear division of labor with the enforcement lane: organizations wanting to add granular microsegmentation and access policy enforcement to their Dragos deployment can layer in a platform like Elisity, which enforces identity-based policies at the network level to contain the threats Dragos identifies.

Claroty: OT/CPS Platform Breadth and Asset Discovery

Overview

Claroty provides a cyber-physical systems (CPS) protection platform spanning OT, IoT, IoMT, and extended IoT (XIoT) environments. Claroty has built one of the largest footprints in the CPS security market, working with 20% of the Fortune 100 and surpassing $100 million in annual recurring revenue during 2023, with 300%+ customer growth since 2020.

Key Capabilities

Claroty’s platform includes two primary deployment models: xDome (cloud-native SaaS) and CTD (Continuous Threat Detection, on-premises). Together, they provide deep asset discovery and profiling, network segmentation recommendations, threat detection, and vulnerability management. Claroty’s research team, Team82, has discovered and disclosed 550+ CPS vulnerabilities, contributing significantly to the industry’s understanding of OT threats.

Claroty’s research has also produced impactful findings for the broader community, including the widely cited statistic that 55% of OT environments contain four or more remote access tools, greatly expanding the attack surface and operational complexity of securing those environments.

Claroty recently secured $150 million in Series F funding, a sign of strong market momentum.

Compliance Coverage

Claroty publishes dedicated compliance resources for ISA/IEC 62443 and NERC CIP, supporting both security posture improvement and regulatory requirements across multiple standards.

Analyst and Peer Recognition

Claroty was named a Leader in the 2025 Gartner Magic Quadrant for CPS Protection Platforms, positioned highest for Ability to Execute and furthest for Completeness of Vision among 17 evaluated vendors. Claroty also received the highest scores in three of four use cases in the 2025 Gartner Essential Capabilities for CPS Protection Platforms report. Claroty Platform holds a 4.8 out of 5.0 rating on Gartner Peer Insights based on 302 ratings.

Well-Suited For

Large enterprises looking for a CPS protection platform with strong asset discovery, segmentation recommendations, and top analyst scores across multiple evaluation criteria. Claroty fits well in healthcare (IoMT), manufacturing, and vital infrastructure environments with complex, multi-site footprints.

Complementary Solutions

Claroty excels at visibility, asset profiling, and threat detection across the CPS estate. For organizations that also want to enforce fine-grained, identity-based microsegmentation policies over the infrastructure you already run, Claroty pairs naturally with Elisity. Both platforms integrate directly, so Claroty’s rich asset intelligence feeds into Elisity’s policy engine for a discover-and-protect workflow. Teams researching Claroty alternatives typically evaluate other OT and CPS discovery platforms, but the constant across all of them is that discovery and enforcement remain distinct jobs, which is why Claroty pairs naturally with an enforcement platform rather than competing with one.

Nozomi Networks: Large-Scale OT/IoT Visibility and AI-Powered Threat Detection

Overview

Nozomi Networks is one of the most widely deployed OT/IoT security platforms in the world, protecting 115 million industrial and IoT assets across 12,000+ installations. Nozomi has built a strong reputation for scalability, AI-powered analytics, and exceptional customer satisfaction.

Key Capabilities

Nozomi Networks provides real-time OT and IoT asset inventory, network visualization, vulnerability assessment, and AI-powered anomaly detection. Vantage, the SaaS option, enables cloud-delivered OT security for organizations with distributed operational environments, while on-premises sensor deployments support air-gapped and high-security environments.

Nozomi’s investment in AI and machine learning for threat detection makes it particularly strong at catching new attack patterns in industrial networks, an increasingly important capability as adversaries develop techniques specifically targeting OT protocols and systems.

Compliance Coverage

Nozomi Networks supports ISA/IEC 62443 and NERC CIP compliance through its monitoring, visibility, and reporting capabilities.

Analyst and Peer Recognition

Nozomi Networks was named a Leader in the 2025 Gartner Magic Quadrant for CPS Protection Platforms and a Leader in The Forrester Wave™: IoT Security Solutions, Q3 2025, receiving the highest score in the “Current Offering” category. On Gartner Peer Insights, Nozomi Networks Platform holds a 4.9 out of 5.0 rating based on 247 ratings, with 98% of reviewers recommending the platform. Nozomi reports 96% customer retention and monthly NPS scores in the 90s.

Well-Suited For

Organizations with large-scale OT/IoT deployments that need asset visibility, AI-powered threat detection, and flexible deployment options (cloud or on-premises). Nozomi Networks is particularly strong for enterprises prioritizing detection and monitoring across expansive industrial environments.

Complementary Solutions

Nozomi Networks excels at OT visibility and threat detection. Following the same division of labor, organizations that want to pair Nozomi’s visibility with active segmentation controls can integrate with Elisity to create a discover, detect, and segment architecture. Security teams get both Nozomi’s monitoring depth and Elisity’s identity-based microsegmentation enforcement.

Armis: Agentless Asset Intelligence Across IT, OT, and IoMT

Overview

Armis has built the largest asset intelligence knowledge base in the industry, covering over 6 billion assets across roughly 20% of devices connected to global networks, with insights from 25,000 locations across 17 industries. Armis Centrix delivers agentless asset visibility, security, and exposure management across IT, OT, IoT, and IoMT environments.

Key Capabilities

Armis Centrix for OT/IoT Security sees, protects, manages, and optimizes all OT, IoT, and ICS assets. Armis Asset Intelligence Engine identifies devices, assesses their risk posture, and detects behavioral anomalies without requiring agents, network changes, or additional hardware. Armis’s strength lies in that massive device knowledge base, which enables exceptionally accurate device identification and classification across diverse industrial environments.

Armis also provides exposure management capabilities, helping organizations prioritize vulnerabilities based on risk context rather than raw severity scores. Security teams managing thousands of heterogeneous OT assets progressively value this approach.

Analyst and Peer Recognition

Armis was named a Leader in the 2025 Gartner Magic Quadrant for CPS Protection Platforms. Armis Centrix holds a 4.6 out of 5.0 rating on Gartner Peer Insights based on 262 ratings.

Well-Suited For

Organizations seeking agentless asset intelligence and exposure management across large, heterogeneous environments spanning IT, OT, and IoMT. Armis fits particularly well in healthcare organizations managing complex medical device environments and manufacturers with diverse connected device fleets.

Complementary Solutions

Armis provides powerful asset visibility and risk assessment. Organizations looking to combine Armis’s asset intelligence with identity-based microsegmentation can integrate directly with Elisity, so that rich device context from Armis Asset Intelligence Engine informs detailed segmentation policies enforced over the infrastructure you already run. If you’re comparing Armis alternatives, other agentless asset-intelligence platforms cover similar ground. Whichever you choose, pairing it with identity-based microsegmentation adds the enforcement layer that asset intelligence alone doesn’t provide. Many organizations run both platforms together: Armis for asset awareness, Elisity for active policy enforcement.

Tenable: OT Vulnerability Management and Compliance-Driven Monitoring

Overview

Tenable, widely known for vulnerability management, extends those capabilities to OT environments through Tenable OT Security. Positioned as a unified solution for converged OT/IT environments, Tenable OT Security safeguards industrial control systems without disrupting operations. Tenable reported $999.4 million in revenue in FY2025, up 11% year-over-year, adding 502 new enterprise platform customers.

Key Capabilities

Tenable OT Security provides asset discovery across known and unknown devices, vulnerability assessment tailored to OT environments, threat detection and mitigation, and configuration control monitoring. Both passive monitoring and active querying architectures are available, letting organizations balance visibility with the sensitivity of industrial networks.

Tenable’s strength lies in connecting OT vulnerability data with its broader exposure management platform, giving security teams a unified view of risk across both IT and OT environments. That converged visibility becomes increasingly important as IT/OT boundaries dissolve in modern manufacturing and critical infrastructure.

Compliance Coverage

Tenable provides dedicated NERC CIP compliance support and references ISA/IEC 62443 among the standards its OT Security platform supports.

Analyst and Peer Recognition

Tenable OT Security holds a 4.9 out of 5.0 rating on Gartner Peer Insights based on 37 ratings in the CPS Protection Platforms category.

Well-Suited For

Organizations already using Tenable for IT vulnerability management that want to extend that expertise into OT environments. Tenable OT Security fits well for energy, utilities, and manufacturing organizations with strong compliance drivers around NERC CIP and IEC 62443.

Complementary Solutions

Tenable’s core strength is vulnerability management and compliance monitoring. Organizations that want to add microsegmentation enforcement alongside Tenable’s vulnerability insights can pair Tenable OT Security with Elisity. Both platforms integrate, so vulnerability context from Tenable enriches Elisity’s microsegmentation policy decisions and segmentation policies can adapt based on the risk posture of individual assets.

Palo Alto Networks: Enterprise-Scale OT Security Within a Broader Security Platform

Overview

Palo Alto Networks brings its enterprise security platform capabilities to OT environments, drawing on its broad security portfolio for OT visibility, threat prevention, and network security. For large enterprises already standardized on Palo Alto Networks for IT security, extending those capabilities into OT environments can offer operational efficiencies and a unified security architecture.

Key Capabilities

Palo Alto Networks’ approach to OT security uses its next-generation firewalls, Prisma Access, and Cortex platforms to extend protection into industrial environments. OT-specific threat signatures, application identification for industrial protocols, and integration with its broader zero-trust network architecture round out the offering. Industrial OT Security provides asset discovery, risk assessment, and threat prevention tailored to industrial environments.

Palo Alto’s global threat intelligence network feeds OT-specific signatures into the platform, providing broad coverage of known threat actors and attack techniques targeting industrial systems.

Compliance Coverage

Palo Alto Networks supports compliance with major industrial standards including IEC 62443, NERC CIP, and NIST CSF through its network security and zero-trust capabilities. Firewall-based segmentation enforces zone-based access controls aligned with IEC 62443 zone and conduit models.

Well-Suited For

Large enterprises already invested in the Palo Alto Networks ecosystem that want to extend their existing security architecture into OT environments. Works well for organizations with dedicated network security teams experienced in managing Palo Alto infrastructure. As one of the primary OT firewall vendors, Palo Alto Networks is a natural fit where zone-boundary and north-south enforcement is the priority.

Complementary Solutions

Palo Alto Networks’ approach relies on firewall-based enforcement, which can be complex to deploy in brownfield OT environments where adding inline hardware or modifying network architecture may impact production systems. Organizations looking for software-only, non-disruptive microsegmentation that complements Palo Alto’s perimeter and zone-based controls can add Elisity to enforce identity-based policies over the infrastructure you already run, covering east-west traffic and unmanaged device segments that traditional firewall architectures may not reach. See how Elisity and Palo Alto Networks work together.

Forescout: Agentless OT Discovery and Switch-Based Policy Enforcement

Overview

Forescout is the one vendor in this guide that operates in both lanes: agentless discovery and OT deep packet inspection on the monitoring side, and policy enforcement through managed network devices on the segmentation side. On 24 June 2026 Forescout renamed the Forescout 4D Platform to the Forescout Vistaro platform and described the change as “an update only to the name”. The platform is made up of eyeSight, eyeSentry, eyeSegment, eyeControl, eyeInspect, eyeFocus, eyeAlert, eyeScope, eyeExtend and the Flyaway Kit.

Key Capabilities

Forescout eyeInspect is the OT monitoring component. Forescout describes it as providing “deep packet inspection of 350+ industrial protocols with thousands of OT-specific threat indicators and anomaly detection”, and markets the platform under “The Broadest Coverage Across OT, IoT, IoMT, BAS and CPS”. Traffic reaches it through a Passive Sensor connected to the ICS or SCADA network via a SPAN or mirroring port, with a separate Active Sensor that “remains inactive unless the eyeInspect operator issues a direct command”, and a Command Center that aggregates sensors. The parser set lives in what Forescout’s OT Plugin Configuration Guide calls a “Traffic Inspection Library” that is “updated periodically”. Forescout publishes no named list of the 350+ protocols.

Discovery is agentless. Forescout’s products overview states “over 30” monitoring techniques while the eyeSight product page states “over 20”; both pages are undated and Forescout does not reconcile the two figures anywhere it publishes, so read the range rather than either number. Forescout Device Cloud is described as holding over 12 million device fingerprints. An optional endpoint agent, SecureConnector, exists and is deployed “by including the Start SecureConnector action in a policy”, which makes agent use a policy choice rather than a platform requirement.

Enforcement and Segmentation

Forescout eyeControl “enforces and automates Zero Trust policies for least-privilege access”, and Forescout states the platform “ensures least privileged access by dynamically assigning devices to appropriate VLANs or applying access control lists based on predefined policies”. The mechanisms behind that sentence are documented in the Switch, Wireless and RADIUS plugins, which reach managed switches over CLI, SNMP or Netconf. The Switch plugin’s Restrict actions are named as Access Port ACL, Assign Security Group Tag, Assign to VLAN, Endpoint Address ACL, Switch Block and Virtual Firewall. RADIUS Change of Authorization is handled by the RADIUS plugin, and Cisco TrustSec enforcement is performed by “authorized and authenticated Cisco switches and routers”.

eyeSegment is the policy surface above those mechanisms. Forescout describes it as letting teams “See, model, and simulate segmentation policies across your entire enterprise ... without agents, without disruption”, markets it under “Simulate Before You Enforce”, and on the same page tells customers they can “enforce segmentation that reduces your attack surface”. Forescout also describes eyeSegment as “a unified policy layer across disparate enforcement points” that will “orchestrate controls across enforcement points”. Forescout does not state on that page which component performs the enforcement, and it publishes no dependency statement tying eyeSegment to the plugins above, so confirm the licensing and the enforcement path against your own quote.

What Forescout Announced in March 2026

On 23 March 2026, three months before the Vistaro rename, Forescout announced cloud-native, agentless network segmentation managed from a single console. The release states the approach requires “no network redesign or vendor lock-in” and “reduces onboarding from weeks to hours”, and cites “more than 30 agentless discovery methods” and integration with “180+ security and IT products”. Forescout attributes the design to simulation-first validation, violation-aware enforcement, AI-driven policy baselines, a matrix-driven view and identity- and attribute-driven zone modeling, with commentary from Justin Foster and Paul Kao.

Network World covered the launch on 24 March 2026 under the headline “Forescout brings identity-driven segmentation to multi-vendor networks”, written by Sean Michael Kerner. That article, not Forescout’s release, is the source for the figure of 1,200 device attributes and for the description of an Arista CloudVision enforcement path. Treat both as Network World’s reporting until Forescout documents them.

Documented Limits

Forescout publishes its enforcement constraints in unusual detail, which makes them checkable. Access Port ACL states that “trunk ports and uplink ports are not supported”. Pre-Connect Mode “is only available for use on managed Cisco switches”. The action’s MAC ACL option “cannot be used on Cisco Nexus switches”. For generic switches, “Only the Switch Block and the Expedite IP Discovery actions” are supported, and for firewalls, routers and SD-WANs the Switch plugin supports “Only the Expedite IP Discovery action”. In the Switch Vendor ACL Support matrix, Juniper records Access Port ACL as not supported, Arista records Endpoint Address ACL based on MAC as not supported, and among the Extreme entries only Extreme X-series carries ACL Actions at all. Aruba appears only under the HPE brand names HPE-ArubaOS-CX, HPE-Comware OS and HPE-Provision/ProCurve/Aruba OS, with no standalone Aruba row. Check your own switch models and software versions against Forescout’s published Compatibility Matrix before assuming an action is available.

eyeSegment “does not support Certification Compliance mode or Devices that do not have IPv4 addresses” and requires outbound access to *.dapi-query.prod.cloud.forescout.com and *.dapi-ingest.prod.cloud.forescout.com. Virtual appliances require “No CPU over-commitment”, and traffic monitoring on the extra-large virtual appliance is documented as “Not supported”. Licensing is counted “per 1,000 Endpoints”, with a device counted “when it is known to the Forescout platform by either its MAC address or IP address”, and an eyeInspect Base Flat Fee license “requires an associated eyeInspect Endpoint license”. An extra-large eyeInspect Sensor is sized up to 10,000 assets, and Command Center tiers are documented at up to 5 sensors, up to 15 sensors, and unlimited.

Two things are not documented, and both are worth asking about in writing. Forescout does not publish whether enforcement fails open or fails closed when the platform loses reachability; the only failure consequence stated is for eyeSegment data, “If traffic cannot be reported, the data shown in your matrix will not be up-to-date”. And the disposition of an unclassified device is a function of the policy the operator writes, because unclassified devices are “placed in an Unclassified group” that the operator “may then choose to manually classify”. Note also that the latest retrievable administration and installation guides are the v8.4.2 documents while the current release train is 9.1.6, so version-check anything you rely on.

Analyst and Peer Recognition

Forescout holds a 4.3 out of 5.0 rating on Gartner Peer Insights based on 36 ratings in the CPS Protection Platforms category, observed 16 August 2026. Forescout’s own site offers a Gartner Critical Capabilities reprint. We found no Magic Quadrant position published by Forescout itself that we could verify directly, so none is stated here.

Well-Suited For

Organizations that want agentless discovery across IT, OT, IoT, and IoMT plus switch-based enforcement from a single vendor, and that can match Forescout’s published enforcement actions to the switch models they actually run. The fit is strongest where the access layer is predominantly Cisco: Forescout limits Pre-Connect Mode to managed Cisco switches, and its ACL support matrix records Access Port ACL as not supported on Juniper and MAC-based Endpoint Address ACL as not supported on Arista. Teams whose OT priority is protocol-level forensic depth should weigh eyeInspect against Claroty and Cisco Cyber Vision on the protocol table below.

Complementary Solutions

Forescout’s monitoring and enforcement components are licensed and deployed separately, and its enforcement reach is bounded by the switch models in the published compatibility matrix. Organizations that want identity-based east-west policy on the access layer they already run, independent of per-switch ACL action support, tend to pair a segmentation platform with a discovery platform rather than buy both from one vendor. Elisity publishes that it “runs alongside an existing ISE, Forescout or ClearPass deployment without changes to that configuration”. Forescout does not appear on Elisity’s published integration list, so treat the two as coexisting controls rather than an integrated pair. For a vendor-by-vendor view of that decision, compare Forescout alternatives.

How Many OT Protocols Does Each Vendor Support?

Protocol coverage is the number buyers ask for first and the number vendors publish least consistently. Of the four deep packet inspection (DPI) platforms below, two publish a protocol count and two publish none. Inside Forescout the two product names are often confused: eyeInspect is the DPI engine that carries the protocol count, and eyeSegment is the policy layer above it, which carries no protocol figure at all. The table records what each vendor publishes about its own protocol count, how it acquires traffic, and which protocols it names in public.

Vendor and product Published protocol figure The vendor’s own scope wording for that figure Traffic acquisition, per the vendor Named protocols the vendor publishes Source and date
Forescout eyeInspect 350+ “deep packet inspection of 350+ industrial protocols”; “The Broadest Coverage Across OT, IoT, IoMT, BAS and CPS” Passive Sensor “connected to the ICS / SCADA network via a SPAN / mirroring port to passively listen”; separate Active Sensor that “remains inactive unless the eyeInspect operator issues a direct command” Not documented. Forescout publishes no named list of the 350+ protocols. Its OT Plugin guide describes a “Traffic Inspection Library” that is “updated periodically”, with no parser count forescout.com/product/ and /product/eyeinspect/, both undated, observed 16 August 2026; OT Plugin Configuration Guide v3.0.0
Claroty (CTD, xDome) 450+ “an unmatched 450+ protocols ... OT, IoT, and other XIoT assets”; federal collateral adds “ICS / SCADA, IIoT, IoT, IT, IoMT, and Serial Devices” “reconfiguring a switch in the OT network with a SPAN, mirror, or monitor port”, analysed “via deep packet inspection (DPI)”; five collection methods in total Partial. Claroty names Modbus on its Passive Monitoring page, and IEC 60870-5-104 and DNP3 in its rail material, described as “hundreds of industrial and rail-specific protocols” claroty.com/platform/passive-monitoring, 2026 footer, no page date; federal at-a-glance PDF is undated
Nozomi Networks (Guardian) Not documented Nozomi publishes no total. “This list is updated every 3 - 6 months. Please contact your Nozomi Networks representative for a complete and current list” Guardian sensors “connect to mirrored ports or taps and operate without interrupting operations”; “All Guardian models perform deep packet inspection”; a passive-only mode exists for “NERC CIP, nuclear, defense” The wired protocol list is gated behind a “Partial ... Supported Protocol List” download. Wireless sensor protocols are named: BLE, WIFI 802.11 a/b/n/ac/ax, IEEE 802.15.4, Z-Wave, LoRa and LoRaWAN, cellular GSM, 2G, 3G, 4G, 5G nozominetworks.com/platform/technical-specifications, 2026 footer, observed 16 August 2026
Cisco Cyber Vision Not documented as a total. Cisco enumerates protocols by vendor and says “Please ask us for the latest list” The Protocols Data Sheet covers “protocols supported by Cyber Vision version 5.4 to gain visibility on your industrial network” “passively capturing and decoding network traffic using Deep Packet Inspection (DPI) of industrial control protocols”, plus “active discovery that sends extremely precise and nondisruptive requests in the semantics of the specific ICS protocol at play”. Sensors embedded in selected switches and routers add “only 2% to 5% additional network traffic”; SPAN is the brownfield alternative The fullest public list of the four. Named: IEC 104, IEC 101 over IP, DNP3, IEC 61850 (MMS, Goose, SV), C37.118, DLMS/COSEM, ICCP (GRID)/TASE.2, EtherCAT, AMS, Ethernet/IP, CIP, Modbus ASCII, Modbus RTU, Modbus/TCP, XWAY, UNITE, UMAS, EthWay, Profinet, Profinet DCP, Profinet IO CM, S7, S7 “Plus”, Siemens LOGO!, BACnet, LonWorks, OPC-DA, OPC-UA, OPC-AE, OSIsoft PI-Connect, PcVue Solution. Active Discovery names 14: ABBNC, BACNet, Beckoff AMS, DNP3, EtherNet/IP, eWON, GE-SRTP, Melsoft, MMS, Modbus, Omron, Profinet, S7, S7Plus Cyber Vision Protocols Data Sheet, updated 18 December 2025; Cyber Vision Data Sheet, updated 14 April 2026
Elisity Not applicable. Elisity publishes no protocol count because Elisity does not perform deep packet inspection Elisity’s documented method is passive discovery plus consumed classification: “Elisity discovers assets and flows passively by mirroring traffic at the existing access layer. There is no scan that could disturb a fragile controller and no probe that an OT engineer has to approve” Traffic mirroring at the existing access layer; enforcement on the same infrastructure through Virtual Edge Nodes Protocol-level identity is consumed, not derived. IdentityGraph correlates from Active Directory, CMDBs, EDR platforms and tools including Armis, Claroty xDome and Nozomi Networks. Elisity states that Claroty xDome passes 8 attributes per device including Purdue level, and that Nozomi Networks supports over 100 OT and IoT protocols including Modbus, BACnet, DNP3, EtherNet/IP, PROFINET and OPC UA elisity.com/ot-security/segment-it-ot-without-downtime, /integrations-overview and the Claroty and Nozomi integration pages, all undated, retrieved 16 August 2026

These figures are not directly comparable. Forescout counts industrial protocols across OT, IoT, IoMT, BAS and CPS. Claroty counts protocols across ICS/SCADA, IIoT, IoT, IT, IoMT and serial devices. Nozomi and Cisco publish no count at all. No vendor documents whether protocol variants such as Modbus ASCII, Modbus RTU and Modbus/TCP are counted separately, so the numbers should not be normalised against each other. Figures observed 16 August 2026.

Sources for this table: forescout.com/product/ and /product/eyeinspect/ plus the Forescout OT Plugin Configuration Guide v3.0.0; claroty.com/platform/passive-monitoring and Claroty’s federal at-a-glance PDF; nozominetworks.com/platform/technical-specifications; the Cisco Cyber Vision Protocols Data Sheet (18 December 2025) and Cyber Vision Data Sheet (14 April 2026); and elisity.com/ot-security/segment-it-ot-without-downtime, /integrations-overview and the Claroty and Nozomi integration pages. “Not documented” in this table means the statement was absent from those sources when they were reviewed on 16 August 2026. It is not a finding that the capability is absent.

Where These Vendors Rank in Industry Analyst Reports

Analyst evaluations provide useful reference points when narrowing your vendor shortlist. Below is how the vendors profiled above appear in recent industry reports.

OT security vendors evaluation matrix comparing capabilities across asset discovery and microsegmentation
How the top OT security vendors compare across five key capability areas for industrial network protection.
Analyst evaluationLane it measuresVendors recognized
Gartner Magic Quadrant for CPS Protection Platforms (Feb 2025)Detection and visibilityLeaders: Claroty, Dragos, Microsoft, Armis, Nozomi Networks
Forrester Wave: Microsegmentation Solutions (Q3 2024)Segmentation and enforcementElisity recognized as a Strong Performer
Gartner Cool Vendors in Cyber-Physical Systems Security (Sep 2025)Segmentation and enforcementElisity named a Cool Vendor
Forrester Wave: IoT Security Solutions (Q3 2025)Detection and visibilityLeader: Nozomi Networks
Gartner Peer Insights, Network Security Microsegmentation (2026)Segmentation and enforcementActive market: Elisity, Illumio, Akamai/Guardicore, ColorTokens

The pattern: the CPS Protection Platforms Magic Quadrant evaluates the detection and visibility lane, where Claroty, Dragos, Nozomi Networks, Armis, and Microsoft lead. Segmentation and enforcement is evaluated separately, in Forrester microsegmentation coverage and Gartner Peer Insights, where Elisity appears alongside Illumio, Akamai/Guardicore, and ColorTokens. A complete OT program reads both bodies of analyst work, not one.

Gartner Magic Quadrant for CPS Protection Platforms (February 2025)

Gartner published its first Magic Quadrant for Cyber-Physical Systems Protection Platforms in February 2025, evaluating 17 vendors on asset discovery, threat detection, vulnerability management, and secure remote access. Five vendors from this guide appeared as Leaders: Claroty (positioned highest for both Ability to Execute and Completeness of Vision), Dragos, Microsoft, Armis, and Nozomi Networks. The CPS protection platform market is projected to grow from $23.47 billion in 2025 to $50.29 billion by 2030, according to MarketsandMarkets. Gartner predicts that 75% of CPS-intensive organizations will adopt dedicated CPS protection platforms by 2027.

Gartner Important Capabilities for CPS Protection Platforms (2025)

In the companion Critical Capabilities report, Claroty scored highest in three of four evaluated use cases, reinforcing its strength across healthcare, manufacturing, and necessary infrastructure deployments. This report provides more granular detail than the Magic Quadrant by scoring vendors against specific operational scenarios relevant to different industries.

Forrester Wave: Microsegmentation Solutions, Q3 2024

Elisity was named a Strong Performer in The Forrester Wave for Microsegmentation Solutions, Q3 2024. This evaluation assessed vendors on their ability to deliver precise network segmentation across diverse environments, including those with unmanaged IoT and OT devices. Microsegmentation is a distinct capability category from CPS protection platforms, which is why Elisity appears in this evaluation rather than the Gartner MQ for CPS.

Gartner Cool Vendors in Cyber-Physical Systems Security (September 2025)

Gartner’s Cool Vendors report identifies innovative vendors tackling challenges beyond what established CPS protection platforms address. Elisity was recognized as a Cool Vendor in Cyber-Physical Systems Security, 2025 for its identity-based microsegmentation approach that transforms the infrastructure you already run into policy enforcement points. The report, authored by Katell Thielemann, highlights Elisity’s agentless deployment, automated least-privilege enforcement, and ability to reduce network complexity as capabilities that help organizations move beyond visibility to active segmentation in CPS environments.

Forrester Wave: IoT Security Solutions, Q3 2025

Nozomi Networks was named a Leader in The Forrester Wave for IoT Security Solutions, Q3 2025, receiving the highest score in the “Current Offering” category. This report evaluated vendors on IoT-specific detection, asset management, and scalability across large device fleets.

These analyst reports offer a starting framework, but your evaluation should also weigh deployment impact on production environments, compliance alignment with your specific regulatory requirements, and integration compatibility with your existing security stack. No single analyst report captures every dimension that matters for a given organization’s OT security needs.

What to Look for When Choosing an OT Security Vendor

A few factors consistently separate successful OT security deployments from stalled projects. These are the factors CISOs and security architects tell us matter most.

Five key criteria for choosing an OT security vendor including microsegmentation and compliance
The five fundamental evaluation criteria every organization should assess when selecting an OT security vendor.

OT-Specific Expertise vs. IT Bolt-Ons

Ask any vendor whether their solution was designed for OT environments or adapted from IT security tools. OT networks contain devices running legacy protocols like Modbus, DNP3, EtherNet/IP, and PROFINET that behave fundamentally differently from IT assets. Vendors that treat OT as just another endpoint category often fail to account for the sensitivity of industrial devices to active scanning, the criticality of uptime, and the unique communication patterns of SCADA and DCS systems. Look for vendors that understand the protocols, workflows, and risk tolerances specific to your industry.

Non-Disruptive Deployment

Any security solution that requires network downtime, re-IP projects, new VLAN structures, or agents installed on sensitive OT devices introduces risk to production operations. Successful OT security deployments use existing infrastructure and operate passively or through software-only approaches that can go live without change control delays or production interruptions. As the Elisity Microsegmentation Buyer’s Guide emphasizes, your microsegmentation architecture must align with existing infrastructure and scale across hybrid environments without performance impacts on applications and network traffic.

Plan for a baseline period before you turn on enforcement, typically one to two months. Watching real traffic first lets you validate policy against how the plant actually communicates, not how a network diagram says it should. In practice, the most common surprise isn’t a true OT device that went undiscovered. It’s an IT asset performing an OT function that got misclassified. A monitor-first workflow catches that before a rule ever blocks a production flow, which is the single most reliable way to keep a rollout non-disruptive.

Passive vs. Interrogative Discovery

Ask how a tool discovers devices, because the method matters as much as the result. Many legacy NAC and access-control tools (the ISE and ClearPass interrogation model) actively probe or query endpoints to classify them. In OT, that active interrogation is a problem: probing a PLC or querying a controller can disturb latency-sensitive control traffic, and OT teams routinely reject any tool that has to interrogate the very devices it’s trying to protect. A fully passive, behavior-analytics approach classifies devices from the traffic they already generate, with nothing injected onto the control network. When you evaluate discovery, confirm which model a vendor uses, because it determines whether the tool is safe to run on a live plant floor at all.

Static Policy with a Human in the Loop

For OT and clinical environments, confirm the vendor supports human-approved static policy, not only fully automated dynamic quarantine. Automated response is attractive on an IT network, but on a plant floor or in a clinical setting the failure mode is severe: a control-critical device flagged and isolated automatically in the middle of an operation. Mature deployments keep a human in the loop for enforcement changes on the most sensitive zones, so a policy action never takes a running process offline without review. Dynamic, context-aware policy still has a place, but it should be an option you enable deliberately, not the default behavior on a production line.

Buyer’s question: hardware ceiling honesty. In real evaluations, the most revealing question we hear buyers ask is whether a vendor will name the exact enforcement limits of legacy or end-of-life infrastructure. Older access-layer hardware (for example, 2960-class platforms) has finite ASIC and TCAM capacity, which caps how many enforcement rules it can hold. A credible vendor tells you where full enforcement is achievable and where it isn’t, rather than promising uniform enforcement everywhere. Vague answers here are a warning sign; specific ones tell you the vendor has actually deployed on brownfield estates like yours.

Microsegmentation as a Foundational Control

Network segmentation is widely recognized as one of the most effective controls for limiting breach blast radius in OT environments. CISA’s updated Cross-Sector Cybersecurity Performance Goals (CPGs 2.0), released in December 2025, emphasize network segmentation, zero-trust principles, and lateral movement mitigation as core security objectives. IEC 62443 centers its security architecture on zones and conduits. HIPAA has elevated network segmentation to mandatory status in recent updates. Evaluate vendors on their ability to deliver meaningful microsegmentation. Broad network zones are the easy part. The hard part is specific, identity-based policy that follows a device wherever it appears on the network.

Compliance Alignment

With the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) taking full effect in May 2026 with 72-hour reporting windows, and IEC 62443 becoming the standard for manufacturing cybersecurity globally, compliance drives vendor selection. Your OT security vendor should directly accelerate compliance with the standards relevant to your industry. Push-button compliance reporting and automated audit logging can dramatically cut the time and cost of audits.

Integration Ecosystem

No single vendor covers every aspect of OT security. Strong platforms integrate with your existing technology stack: identity providers, CMDB and asset management tools, EDR platforms, SIEM/SOAR systems, and specialized OT security tools. Evaluate the breadth and depth of a vendor’s integration ecosystem and make sure it covers the tools you already rely on. Elisity, for example, integrates with 50+ platforms across the security ecosystem, letting organizations build layered defenses without ripping and replacing existing investments.

Deployment Disruptiveness: A Buyer Scoring View

In OT, how a control deploys matters as much as what it does, because a maintenance window on a production line has a direct cost. The view below scores common OT security approaches on the two questions buyers ask first: will it require downtime, and how fast does it reach value. It is a category view, not a single-vendor scorecard.

ApproachRequires downtime or change windowAgent on OT assetsTypical time to first enforcement
Passive detection sensors (SPAN/tap)No (visibility only, does not enforce)NoN/A, detection not enforcement
Inline firewalls and new VLANsUsually yes (re-IP, cabling, change control)NoWeeks to months
Agent-based microsegmentationVaries; agents often unsupported on controllersYesWeeks, where agents can be installed
Identity-based agentless microsegmentationNo (enforces over the existing access layer)NoDays to weeks, observe-then-enforce

An observe-then-enforce, agentless pattern lets teams build and validate policy in a monitor-only mode before any rule blocks traffic, which is what makes no-downtime enforcement practical on a live plant floor.

How OT Security Differs from IT Security

For security leaders whose backgrounds are primarily in IT, a few fundamental differences drive every OT vendor decision. Miss them, and the best IT tool still stalls on a plant floor.

Safety vs. Confidentiality Priorities

In IT security, the CIA triad typically prioritizes confidentiality. OT inverts that order. Availability and safety come first because disrupting an industrial control system can cause physical harm to workers, environmental damage, or loss of essential services like healthcare delivery, millions in lost profits, or power generation. Any OT security solution must respect this priority: security controls can’t introduce latency, downtime, or unpredictable behavior in production systems.

This is why non-disruptive deployment is decisive in safety-critical settings, not a nice-to-have. In healthcare environments analogous to OT, Elisity teams report bringing campus-wide visibility live in roughly 30 minutes to 2 hours with no disruption to care, precisely because nothing is inserted inline and no agent touches a device that a clinician or an operator depends on.

Legacy Systems and Extended Lifecycles

While IT assets are typically refreshed every three to five years, OT devices like PLCs, HMIs, RTUs, and SCADA servers may stay in production for 15 to 25 years or longer. Many run operating systems and firmware that no longer receive patches. They often lack the computational resources to run security agents and may communicate using proprietary protocols that standard IT security tools cannot inspect. OT security solutions must protect these legacy assets without modifying them.

Proprietary Protocols and Communication Patterns

OT networks rely on industrial protocols like Modbus, DNP3, BACnet, EtherNet/IP, PROFINET, and OPC UA. These protocols were designed for reliability and real-time performance, not security. Many lack authentication, encryption, or integrity checks. OT security vendors need to understand these protocol behaviors to distinguish between legitimate operational traffic and potential threats.

Uptime Requirements

Manufacturing plants, hospitals, water treatment facilities, and energy infrastructure often operate 24/7/365 with extremely limited maintenance windows. Unlike IT environments where patching and rebooting can be scheduled during off-hours, OT environments may have planned downtime only once or twice per year. Non-disruptive deployment and operation isn’t a nice-to-have. It’s a requirement. Solutions that need inline hardware installation, network reconfiguration, or any form of traffic disruption during deployment are often impractical in these environments.

Key OT Security Threats in 2026

OT threats are getting worse. And they’re getting more specific.

State-Sponsored Activity Targeting Industrial Systems

Nation-state actors continue targeting industrial infrastructure as a strategic objective. Dragos’s 2026 OT Cybersecurity Year in Review reported that state-sponsored groups are steadily developing capabilities designed to disrupt industrial processes, moving beyond reconnaissance and positioning into active operational preparation. Proactive segmentation and access control limit what adversaries can reach even after gaining initial access to an OT network.

Ransomware Continues to Devastate Manufacturing

Ransomware remains the most visible and disruptive threat to industrial organizations. Dragos tracked 119 ransomware groups targeting industrial organizations in 2025, up from 80 in 2024, with over 3,300 industrial organizations impacted. In Q1 2025 alone, 708 ransomware incidents struck industrial entities, with manufacturing absorbing 68% (480 incidents). Manufacturing breaches now average over $5 million per incident. Healthcare breaches average $7.42 million, the highest across all industries for the 14th consecutive year.

Source for the manufacturing and healthcare breach-cost figures: IBM Cost of a Data Breach Report 2025.

IT/OT Convergence Enables Lateral Movement

As IT and OT networks become continually interconnected, attackers exploit IT-side compromises to move laterally into OT environments. SANS’s 2025 survey found that among organizations reporting OT incidents, 50% were attributed to unauthorized external access and 38% to ransomware. Microsegmentation between IT and OT zones is one of the most vital controls an organization can implement. Solutions like Elisity that enforce identity-based policies across both IT and OT assets on the same network infrastructure address this convergence challenge directly.

Supply Chain and Third-Party Access Risks

Industrial organizations increasingly depend on third-party vendors, integrators, and OEMs who require remote access to OT systems for maintenance and support. With 55% of OT environments containing four or more remote access tools according to Claroty research, the attack surface from uncontrolled third-party access is significant. Microsegmentation and least-privilege access enforcement mean that even if a third-party credential gets compromised, the attacker’s ability to move laterally is severely constrained.

Regulatory Compliance Requirements for OT Security

Regulators aren’t slowing down. This section maps microsegmentation and other security controls to the standards that matter, and you can go deeper in our guide to network segmentation compliance best practices.

IEC 62443 Security Levels and the Enforcement Controls They Imply

IEC 62443 organizes an environment into zones (groups of assets with shared security requirements) and conduits (the controlled communication paths between them). Each zone is assigned a Security Level. The standard defines what protection is required at each level; the table below maps those requirements to the segmentation and enforcement controls that satisfy them in a brownfield OT network.

Security LevelThreat it must withstandEnforcement control implied
SL 1Casual or coincidental violationDocumented zone boundaries; default-deny between zones
SL 2Intentional violation, simple means, low resourcesConduit enforcement with explicit allow-lists; identity attached to each permitted flow
SL 3Intentional violation, sophisticated means, moderate resourcesIdentity-based microsegmentation down to the device; least-privilege conduits; continuous policy
SL 4Intentional violation, sophisticated means, extended resourcesPer-device segmentation with strong identity, monitored conduits, and rapid revocation

The practical gap in most brownfield plants sits at SL 2 and SL 3, where conduits must be enforced but the assets can’t accept agents and can’t run an 802.1X supplicant. An identity-based, agentless approach enforces the conduit over the existing access layer, so legacy controllers reach the required level without a hardware refresh.

IEC 62443: Industrial Cybersecurity Standard

IEC 62443 has become the global standard for industrial cybersecurity, with adoption accelerating across manufacturing, energy, and critical infrastructure. Its security architecture centers on zones (groups of assets with common security requirements) and conduits (controlled communication paths between zones). Network segmentation is foundational to IEC 62443 compliance, and the standard defines security levels (SL1 through SL4) that require progressively more granular access controls.

A practical evaluation question for IEC 62443 and the Purdue model is whether a vendor can express zones and conduits against the network you already run, rather than requiring OT teams to rip out and rebuild it. Purdue levels and 62443 zones are logical constructs; a modern approach maps them onto the existing physical topology through identity-based policy, so a brownfield plant reaches its target security level without re-architecting the network you already run or scheduling a plant-wide cutover.

Identity-based microsegmentation directly supports IEC 62443 by creating logical zones and conduits through policy rather than physical network reconfiguration. Organizations can implement and demonstrate compliance with IEC 62443-3-2 (security risk assessment) and IEC 62443-3-3 (system security requirements) without the multi-year timelines often tied to physical network redesigns. Elisity positions its platform specifically around achieving IEC 62443 compliance without production disruption.

NERC CIP

For energy and utility organizations, NERC Critical Infrastructure Protection (CIP) standards require network segmentation, access controls, and continuous monitoring of important cyber assets. Platforms like Tenable OT Security, Claroty, and Nozomi Networks directly support NERC CIP compliance through their monitoring and reporting capabilities.

NIST SP 800-82 and NIST CSF 2.0

NIST Special Publication 800-82 provides the definitive guide to ICS security and strongly recommends network segmentation as a core control. NIST Cybersecurity Framework 2.0, along with CISA’s Cross-Sector Cybersecurity Performance Goals (CPGs 2.0) released in December 2025, emphasizes network segmentation, zero-trust principles, and lateral movement mitigation as essential cybersecurity objectives. Microsegmentation maps directly to the “Protect” function of the CSF and is progressively called out in the “Detect” and “Respond” functions as a critical enabler of containment.

CMMC (Cybersecurity Maturity Model Certification)

For organizations in the defense industrial base, CMMC compliance requires demonstrable network segmentation and access controls to protect Controlled Unclassified Information (CUI). Identity-based microsegmentation provides the granularity needed to isolate CUI-handling systems and demonstrate compliance during third-party assessments.

HIPAA and HHS 405(d)

Healthcare organizations face specific requirements under HIPAA for protecting electronic Protected Health Information (ePHI). Recent HIPAA updates have elevated network segmentation to mandatory status, and the HHS 405(d) program specifically recommends microsegmentation for protecting clinical environments with connected medical devices. Elisity’s deployments at large multi-site health systems demonstrate how identity-based microsegmentation applies to healthcare compliance.

CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)

Taking full effect in May 2026, CIRCIA requires critical infrastructure organizations to report significant cyber incidents within 72 hours. Organizations that have implemented microsegmentation benefit from enhanced logging, faster incident containment, and clearer forensic data, all of which support timely and accurate incident reporting.

Frequently Asked Questions About OT and ICS Security

How do I segment a converged IT/OT network across multiple plants?

Use identity-based microsegmentation that enforces policy through the access-layer switches each plant already runs, instead of deploying firewalls or re-architecting VLANs site by site. Policies are defined once in a cloud console and normalized across every location and switch vendor, which is how global rollouts reach three to four sites per week. See Elisity’s industrial security solutions for the IEC 62443 zone-and-conduit model this supports.

How do I secure industrial devices without agents?

Enforce policy in the network rather than on the device. Agentless microsegmentation discovers every industrial device passively, builds an identity profile from network metadata and integrations such as Claroty or Nozomi Networks, and applies least-privilege policy at the switch port. The device itself is never touched: no agent, no reboot, no downtime. Learn how this works in network visibility and microsegmentation.

How do I protect PLCs and SCADA systems that can’t be patched?

Wrap unpatchable PLCs and SCADA systems in compensating controls: microsegmentation policies that restrict each controller to the specific engineering workstations, historians, and protocols it needs. This contains exploitation of known vulnerabilities without touching the device, and it is the approach IEC 62443 zones and conduits formalize and auditors accept. See network segmentation compliance best practices.

Which OT security vendors should manufacturing organizations consider?

Start with your primary security objective. If your top priority is microsegmentation to prevent lateral movement and ransomware spread without disrupting production, Elisity provides identity-based microsegmentation that deploys in weeks using the network infrastructure you already run. For OT-specific threat intelligence and incident response, Dragos provides deep industrial threat detection. Claroty and Nozomi Networks are both widely deployed in manufacturing for asset visibility and monitoring. Many manufacturing organizations run complementary solutions together: Elisity’s microsegmentation paired with Claroty or Nozomi Networks’ asset visibility and threat detection, for example.

How should I evaluate OT security vendors for IEC 62443 compliance?

Focus on the standard’s core concept of zones and conduits. Can the vendor create logical security zones without requiring physical network redesign? Can it enforce controlled communication paths between zones through targeted policies? Does it support the security level (SL) appropriate to your environment? Can it provide the audit logging and reporting needed to demonstrate compliance? Elisity supports IEC 62443 compliance through identity-based microsegmentation that creates zones and conduits via policy, without production disruption.

What is microsegmentation and why does it matter for OT security?

Microsegmentation divides a network into isolated segments at a fine-grained level, controlling communication between individual devices, workloads, and users based on identity and policy rather than network location alone. In OT environments, microsegmentation is critical because it prevents lateral movement, the stage where an attacker moves from a compromised device to reach more valuable targets. By containing threats to the smallest possible blast radius, microsegmentation protects production systems even when a breach occurs elsewhere on the network. Modern approaches like identity-based microsegmentation can protect unmanaged OT devices without requiring agents, new hardware, or network downtime.

On lateral movement in OT: the Dragos 2026 OT Cybersecurity Year in Review documents lateral movement as a recurring stage in industrial intrusions, and the SANS 2025 State of ICS and OT Security Survey reports unauthorized external access as a leading initial vector. Containing lateral movement is the control objective these findings point to.

How do OT firewall vendors differ from OT segmentation vendors?

OT firewall vendors, such as Palo Alto Networks and other Fortinet-class next-generation firewall providers, enforce zone boundaries at chokepoints between larger network segments, which suits the IT/OT boundary and north-south traffic well. Identity-based segmentation vendors like Elisity operate inside those zones, controlling east-west traffic between individual devices over the infrastructure you already run, without inline hardware. The two are complementary rather than competing: a firewall guards the perimeter of a zone, while microsegmentation contains lateral movement within it. For how firewall-based enforcement and identity-based microsegmentation fit together, see the Palo Alto Networks profile above.

What are the best alternatives to Armis and Claroty for OT asset visibility?

If you’re evaluating Armis alternatives, the category to compare is agentless asset-intelligence platforms; Claroty, Nozomi Networks, and Dragos all offer overlapping discovery depth with different strengths. If you’re weighing Claroty alternatives, compare other OT and CPS discovery platforms (Armis, Nozomi Networks, Dragos, Tenable) on protocol coverage and deployment model. In every case, remember that asset visibility and policy enforcement are different jobs. An identity-based microsegmentation platform like Elisity complements any of these OT cybersecurity vendors rather than replacing them, so the practical shortlist is usually one discovery platform plus one enforcement platform.

Can OT security solutions be deployed without causing production downtime?

Yes, but it depends entirely on the vendor and architecture. Solutions that require inline hardware installation, new VLANs, re-IP projects, or agents on OT devices will likely require planned downtime and change control coordination. Software-only approaches, like Elisity’s identity-based microsegmentation that uses the network infrastructure you already run, can deploy without production downtime or network disruption. Passive monitoring platforms from vendors like Nozomi Networks and Dragos can also deploy with minimal operational impact, as they generally connect through SPAN ports or network taps rather than being inserted inline.

How does OT security differ from IT security?

OT security protects physical processes, industrial equipment, and operational infrastructure, while IT security protects data, applications, and computing resources. Key differences include priorities (safety and availability vs. confidentiality), asset lifecycles (OT devices may operate for 15 to 25+ years vs. three to five years for IT), protocols (industrial protocols like Modbus and DNP3 vs. IP/TCP-based protocols), and risk tolerance for downtime (OT can’t tolerate unplanned disruption). OT security solutions must respect these differences by operating non-disruptively, supporting legacy devices, and understanding industrial communication patterns.

How much do OT security platforms typically cost?

Costs vary significantly based on scope, deployment model, and organizational size. Enterprise OT visibility and threat detection platforms generally range from six figures to mid-seven figures annually for large deployments. Microsegmentation solutions vary based on device and site count. One of the most important cost considerations is total cost of ownership, including deployment labor, ongoing management, and the opportunity cost of lengthy implementation timelines. The savings are often operational rather than purely licensing: one large health system reduced the team running its legacy NAC and firewall segmentation from more than a dozen people down to a small handful after moving to identity-based microsegmentation. Traditional IEC 62443 compliance implementation can cost $3 million to $8 million over 18 to 36 months, making efficient microsegmentation platforms a progressively more attractive alternative.

The $3 million to $8 million range reflects traditional firewall and VLAN-based implementations, based on Elisity field analysis of brownfield OT segmentation programs.

Is there a Gartner Magic Quadrant for OT security?

Gartner published its first Magic Quadrant for Cyber-Physical Systems Protection Platforms in February 2025. Leaders in that report include Claroty, Dragos, Microsoft, Armis, and Nozomi Networks. The evaluation criteria cover asset discovery, threat detection, vulnerability management, and secure remote access. Gartner predicts 75% of CPS-intensive organizations will adopt dedicated CPS protection platforms by 2027. For manufacturing and industrial organizations, this report provides a useful starting framework, though your evaluation criteria should also include deployment impact on production environments and compliance alignment with standards like IEC 62443 and network segmentation compliance. Separately, Gartner published its Cool Vendors in Cyber-Physical Systems Security report in September 2025, recognizing vendors with innovative approaches to CPS challenges beyond the scope of CPS protection platforms. Elisity was named a Cool Vendor in that report for its identity-based microsegmentation capabilities.

What is the best SIEM for OT and industrial control systems?

Purpose-built OT monitoring platforms from Dragos and Nozomi Networks often outperform traditional SIEMs for ICS-specific threat detection because they understand industrial protocols like Modbus, EtherNet/IP, and PROFINET natively. If your organization already runs a SIEM (Splunk, Microsoft Sentinel, or similar), look for OT-specific data connectors and asset context enrichment that can feed OT alerts into your existing SOC workflows. The key evaluation criteria are protocol coverage, false positive rates in operational environments, and integration with your existing security stack.

What is the best EDR for OT networks?

Traditional EDR tools usually can’t run on OT endpoints because legacy PLCs, HMIs, and SCADA systems often use proprietary operating systems that don’t support agent installation, and any software change risks production disruption. Agentless monitoring solutions from Dragos, Claroty, and Nozomi Networks provide visibility without endpoint agents. For containment, network microsegmentation from Elisity can restrict lateral movement over the infrastructure you already run without touching the endpoints. The right approach depends on your mix of managed vs. unmanaged devices and your tolerance for operational change.

What is the best NAC for industrial and OT environments?

Legacy NAC solutions built for IT environments struggle with OT because industrial devices often can’t support 802.1X supplicants, and network disruptions during authentication can halt production. Modern alternatives fall into two categories: OT-aware NAC solutions that handle protocol exceptions, and identity-based microsegmentation platforms like Elisity that enforce access policies over the infrastructure you already run without requiring endpoint agents or network redesign. When evaluating, prioritize solutions that can classify unmanaged devices by identity attributes, enforce granular policies without VLANs, and deploy without production downtime. For a deeper analysis, see our guide on why NAC projects stall and what alternatives are reshaping network security.

How do I segment IT and OT networks without causing production downtime?

Use an observe-then-enforce approach over the existing access layer rather than inserting inline hardware. Identity-based, agentless microsegmentation learns normal communication in a monitor-only mode, lets you validate policy against real traffic, and then enforces without re-IP work, new cabling, or agents on controllers. Because nothing is placed inline and no agent touches the OT asset, enforcement can begin without a maintenance window. Passive detection platforms from vendors like Nozomi Networks and Dragos deploy with similar low impact, but they alert rather than enforce, so most programs pair the two.

What is the best OT security vendor for IT and OT convergence?

There is no single best vendor, because IT and OT convergence needs two capabilities that different vendors lead in. For detection and asset visibility across the converged estate, Claroty, Nozomi Networks, Dragos, and Armis are widely deployed. For enforcing the IT and OT boundary, identity-based microsegmentation that applies one policy model across IT, OT, and IoT without agents is the convergence control. Elisity occupies that enforcement lane and is built for the IT and OT convergence team rather than for a single domain. The practical answer for most organizations is one vendor from each lane.

Can I microsegment OT networks using my existing network infrastructure?

Yes. Identity-based microsegmentation can enforce policy over the existing access layer you already operate, with no forklift upgrade and no agents on OT assets. Policy follows the identity of the device, user, or workload rather than its IP address or location, so legacy controllers and unmanaged devices can be brought into zones and conduits without re-addressing the network. This is what makes the approach viable in brownfield plants where assets carry a 15 to 25 year lifecycle and cannot be re-platformed on a normal IT refresh cadence.

How does monitoring differ from enforcement in OT security?

Monitoring detects and reports; enforcement allows or blocks. A detection platform watches traffic and raises an alert when something looks wrong, which is essential for situational awareness but doesn’t by itself stop an attacker from moving laterally. An enforcement control decides which devices are permitted to communicate and denies the rest, which contains the blast radius even when an intrusion has already begun. In OT, where lateral movement is a recurring stage in industrial intrusions documented in the Dragos 2026 OT Cybersecurity Year in Review, mature programs run both: detection to see, enforcement to stop.

Is Forescout an OT security vendor?

Yes, and it operates in both halves of the OT market. Forescout eyeInspect is the monitoring half: Forescout describes it as performing “deep packet inspection of 350+ industrial protocols with thousands of OT-specific threat indicators and anomaly detection”, delivered by a Passive Sensor on a SPAN or mirroring port with a separate Active Sensor that stays inactive until an operator issues a direct command. Forescout eyeControl is the enforcement half, described as enforcing and automating “Zero Trust policies for least-privilege access”, with documented switch actions including Access Port ACL, Assign to VLAN, Assign Security Group Tag, Endpoint Address ACL, Switch Block and Virtual Firewall. Which of those actions you can use depends on the switch vendor and model, which Forescout publishes in a compatibility matrix: Pre-Connect Mode is limited to managed Cisco switches, Access Port ACL is recorded as not supported on Juniper, and generic switches support only Switch Block and Expedite IP Discovery.

How many OT protocols does Forescout support compared with Claroty and Nozomi?

Forescout publishes 350+ industrial protocols for eyeInspect and no named list of them. Claroty publishes 450+ protocols across OT, IoT and other XIoT assets. Nozomi Networks publishes no total at all, stating that its list is “updated every 3 - 6 months” and directing buyers to contact a representative for a complete and current list, and Cisco publishes no aggregate for Cyber Vision either, enumerating protocols by vendor instead. The counts are not directly comparable: each vendor counts across a different asset scope, and none of them documents whether variants such as Modbus ASCII, Modbus RTU and Modbus/TCP are counted separately. Figures observed 16 August 2026.

Do I need both an OT monitoring platform and a segmentation platform?

Most mature programs run one product from each lane. Monitoring platforms such as Claroty, Dragos, Nozomi Networks, Tenable and Forescout eyeInspect tell you what is on the network and what is behaving abnormally. Segmentation platforms decide what each device is allowed to reach and contain lateral movement once something is already inside. Elisity states that it is “a policy and enforcement layer, not a replacement for asset intelligence, endpoint detection, OT security, or IT service management platforms”, and consumes device context from Claroty xDome, Armis and Nozomi Networks rather than performing its own deep packet inspection. The practical test is whether anything in your current stack blocks east-west traffic between two devices on the same VLAN.

What Comes Next

Effective OT security in 2026 requires layers: asset visibility, threat detection, and proactive access controls through microsegmentation. No single vendor covers everything, and the most effective programs run two or three complementary solutions working together.

For organizations ready to implement microsegmentation across OT environments without the risk, cost, and multi-year timelines of legacy approaches, Elisity’s identity-based microsegmentation delivers proven results in weeks using the network infrastructure you already run. Pair it with specialized OT monitoring and threat intelligence from Dragos, Claroty, Nozomi Networks, Armis, or Tenable, and you have a layered architecture that protects essential infrastructure while keeping operations running.

Organizations that start with visibility and microsegmentation tend to build momentum faster than those waiting for a perfect plan. Start there.

Ready to see how Elisity can protect your OT environment? Book a demo to learn how identity-based microsegmentation can deploy across your manufacturing, healthcare, or industrial facilities in weeks, without downtime and without new hardware.

If you’re scoping OT segmentation specifically, map it to your environment on the OT network segmentation page or in a guided demo. Teams standardizing on a single policy model across IT, OT, and IoT can also review industrial microsegmentation for the manufacturing rollout pattern.

Related Resources from Elisity

About the Author

William Toll is Head of Product Marketing at Elisity, where he leads go-to-market strategy for identity-based microsegmentation solutions. With experience spanning product marketing for enterprise security platforms, William focuses on helping organizations understand how modern network security approaches can address real-world operational challenges in manufacturing, healthcare, and vital infrastructure environments.

Connect with William Toll on . He writes on identity-based microsegmentation, OT and IT convergence, and zero trust enforcement for manufacturing, healthcare, and vital infrastructure environments.

No Comments Yet

Let us know what you think