ORDR logo

ORDR + Elisity: AI-Powered Asset Intelligence for Dynamic Microsegmentation

ORDR discovers and profiles every connected asset across IT, IoT, OT, and IoMT environments, tracking more than 2,500 attributes per device. Elisity carries that intelligence into the Elisity IdentityGraph™ and enforces identity-based microsegmentation through the network infrastructure you already own. Together, you get risk-aware policies built on real device context, including risk scores, PHI indicators, and “Known in ORDR” trust status.

Asset Intelligence
Vulnerability Management
ORDR and Elisity integration showing ORDR asset intelligence active in the Elisity Cloud Control Center
 

Support Documentation

Read the complete integration details and resources.
 

Challenge


Unmanaged IT, IoT, and IoMT Devices You Cannot See or Classify

A hospital floor runs infusion pumps, patient monitors, ultrasound carts, and nurse call systems. A plant floor runs PLCs, HMIs, and building automation controllers. None of them accept an endpoint agent, and in most inventories none of them resolve to anything richer than a MAC address, a DHCP fingerprint, and a VLAN assignment. Security teams are left with a list that confirms a device exists without saying what it is, who manufactured it, what operating system it runs, or what it normally communicates with. Policy work stalls there. You cannot write a least-privilege rule for an asset you can only describe as an address on VLAN 40, so unmanaged devices land in broad permissive zones by default, which are exactly the zones an attacker uses to move laterally. Manufacturer, model, operating system, and behavioral profile are the minimum context required before identity-based microsegmentation becomes something more than a diagram.

Elisity Solution


ORDR Collectors Enrich Elisity IdentityGraph With 2,500+ Asset Attributes

ORDR profiles every connected asset, and Elisity turns that profile into enforceable policy. ORDR Collectors deployed on premises combine passive flow collection with safe active probing to discover and classify IT, IoT, OT, and IoMT devices, tracking more than 2,500 attributes per asset. That intelligence flows into the Elisity IdentityGraph through an API connection configured in the Elisity Cloud Control Center, where manufacturer, model, operating system, FQDN, device type, device profile, and ORDR category arrive as first-class identity attributes rather than entries in a separate console. Your team stops exporting spreadsheets between platforms and stops maintaining a second inventory that drifts out of date the week after it is finished. ORDR establishes what each asset is and how it behaves. Elisity uses that identity to decide what the asset is permitted to reach, north-south and east-west, and enforces the decision through the network infrastructure you already own. No agents on the endpoint, no new appliances in the path.

Challenge


Risk-Blind Segmentation Treats Every Device of a Type the Same

Knowing that a device is an infusion pump is not the same as knowing it runs an operating system with an unpatched CVE, that it is clinically critical during a code, or that it handles protected health information. Most segmentation projects flatten those distinctions. Every pump lands in the pump group, every controller lands in the controller group, and the resulting policy is only as tight as the weakest member of the set. When a vulnerability advisory arrives on a Friday afternoon, the team has no attribute to pivot on: risk scoring lives in one platform, policy lives in another, and reconciling the two is a manual exercise measured in weeks. Compliance reviewers ask a version of the same question and get the same answer. Which controls apply to the devices that touch PHI, and how do you prove those controls followed a device when it moved to another floor, another building, or another clinic?

Elisity Solution


Risk Scores, PHI Indicators, and Known in ORDR Status Drive Elisity Policy

Elisity policy groups match on ORDR risk attributes directly, so segmentation reflects device risk rather than device type alone. Risk score, risk state, criticality, ORDR category, PHI indicator, and the “Known in ORDR” trust status are all available as policy group criteria in the Elisity Cloud Control Center. That makes rules like these routine to build and defend: any asset where “Known in ORDR” is false receives a restricted profile until it is identified; any device flagged as handling protected health information is limited to the clinical application servers it actually needs; any asset whose risk state rises moves into a tighter policy group without a change ticket or a maintenance window. Because the Elisity IdentityGraph re-evaluates attributes continuously, a device that gets remediated relaxes back into its normal group on its own. Auditors get a defensible answer: the control is bound to the asset’s identity and risk posture, not to the subnet it happens to occupy today.

Challenge


Manual Classification Cannot Keep Pace With Specialized Device Fleets

Healthcare, manufacturing, and industrial organizations run thousands of device models that a generic classifier has never seen. Heart pump controllers, sterilizers, telemetry gateways, PLCs, and building automation systems all look like ordinary hosts on the wire until someone with domain knowledge labels them by hand. So teams build the inventory manually: a biomedical engineering spreadsheet here, a facilities list there, a network export nobody has refreshed since the last audit. It is accurate the day it is finished and stale a quarter later, because assets are added, replaced, re-imaged, and moved between buildings continuously. The result is a classification layer that cannot support automated policy. Every new device becomes a ticket, every acquired clinic or new production line multiplies the work, and the segmentation program advances at the speed of the people doing data entry instead of the speed of the network.

Elisity Solution


Automated Classification Maps 19 ORDR Attributes to Elisity Policy Groups

The integration maps 19 ORDR device attributes into Elisity policy group criteria, so classification happens once and policy follows automatically. The ORDR AI and machine learning classification engine identifies specialized equipment by behavior and communication pattern, then passes device type, device profile, device group, ORDR category, manufacturer, model, operating system, FQDN, risk state, and related fields into the Elisity IdentityGraph. A heart pump controller is classified as a heart pump controller, a PLC as a PLC, a building automation controller as a building automation controller, and each one lands in the policy group its role calls for. New assets inherit policy the moment ORDR profiles them, so a newly deployed imaging system is governed on day one instead of after the next inventory cycle. Enforcement runs through the network infrastructure you already own, which is why modern microsegmentation is measured in weeks where a VLAN redesign is measured in years.

Explore Our Integrations

Elisity integrates with leading IT, OT, and IoT asset intelligence platforms. Combine deep device discovery and classification with identity-based microsegmentation enforced through your existing network infrastructure.

Device Intelligence / Risk Status

EDR / Risk Status

CMDB

Network Enforcement Point

User Identity / Device Metadata

SIEM

ORDR + Elisity Integration FAQ

Get answers to common questions about how ORDR integrates with Elisity to deliver AI-powered asset intelligence and identity-based microsegmentation across IT, IoT, OT, and IoMT environments.

How does the ORDR and Elisity integration work?

ORDR discovers, classifies, and profiles every connected asset using on-premises Collectors that combine passive flow collection with active probing, tracking more than 2,500 attributes per device across IT, IoT, OT, and IoMT environments. You connect ORDR to Elisity by entering API credentials in the Elisity Cloud Control Center, which takes minutes. Once connected, ORDR asset intelligence including manufacturer, model, operating system, FQDN, device type, risk state, and ORDR category flows into the Elisity IdentityGraph, where it becomes policy group criteria. Elisity then enforces identity-based microsegmentation through the network infrastructure you already own, with no new hardware and no endpoint agents.

Do I need to install agents on devices for ORDR and Elisity microsegmentation?

No. The integration is agentless on both sides. ORDR Collectors discover and profile devices from the network using flow data and safe active probing, so nothing is installed on the asset itself, and Elisity enforces segmentation policy through your existing network infrastructure rather than through an endpoint agent. That matters because the devices most in need of segmentation are the ones least able to run software: infusion pumps, imaging systems, PLCs, building automation controllers, and legacy operating systems under vendor or safety certification restrictions. You get full visibility and enforced microsegmentation without ever touching a production endpoint.

What ORDR device attributes can Elisity use in microsegmentation policies?

The integration maps 19 ORDR attributes into Elisity policy group criteria. They include device type, device profile, device group, ORDR category, manufacturer, model, operating system, and FQDN for classification, plus risk-oriented fields such as risk score, risk state, criticality, PHI indicator, and the “Known in ORDR” trust status. Security teams combine those attributes into policy groups, for example restricting any asset where “Known in ORDR” is false, or applying tighter controls to devices flagged as handling protected health information. Because the Elisity IdentityGraph re-evaluates attributes continuously, policy follows the device as its classification or risk state changes.

What device types does the ORDR and Elisity integration cover?

ORDR profiles the full range of enterprise and specialized assets: managed IT endpoints and servers, IoT devices such as cameras and access control panels, OT equipment including PLCs, HMIs, and building automation controllers, and IoMT devices such as infusion pumps, patient monitors, imaging systems, and heart pump controllers. The ORDR AI and machine learning classification engine identifies these devices by behavior and communication pattern rather than by an installed agent. All of that classification flows into the Elisity IdentityGraph, so microsegmentation policies reflect what each device actually is and how it behaves, not just the IP address or VLAN it was assigned.

How long does it take to deploy ORDR with Elisity microsegmentation?

The API connection takes minutes: you enter ORDR API credentials in the Elisity Cloud Control Center and asset attributes begin enriching the Elisity IdentityGraph immediately. From there, most organizations move from connection to enforced microsegmentation policies in weeks rather than the months or years a traditional VLAN redesign requires. ORDR classification removes the manual device inventory step, and Elisity enforces policy through the network infrastructure you already own, so there is no new hardware to procure, no agents to roll out, and no network re-architecture to schedule around production windows.

Back to top

Resources

Modern vs. Legacy Microsegmentation: The Evolution of a Critical Zero Trust Requirement
elisity-man-interacting-with-HMI-OT-manufacturing

Modern vs. Legacy Microsegmentation: The Evolution of a Critical Zero Trust Requirement

Apr 10, 2025, 10:14:40 AM 12 min read
Microsegmentation ROI and KPIs: 2026 Benchmarks and Checklist
Maximizing Microsegmentation ROI: Essential KPIs for Security Leaders

Microsegmentation ROI and KPIs: 2026 Benchmarks and Checklist

Aug 13, 2025, 11:21:16 AM 25 min read
Cybersecurity Budget Benchmarks for 2026: Essential Planning Guide for Enterprise Security Leaders
Network Engineer

Cybersecurity Budget Benchmarks for 2026: Essential Planning Guide for Enterprise Security Leaders

Nov 13, 2025, 3:09:55 PM 18 min read