Most OT security projects start with visibility. Teams first need to know which devices and controllers are connected to the plant network, then control third-party access and turn network activity into alerts the SOC can use. Some platforms lead with asset discovery and exposure management, while others put more weight on threat detection, incident response, or secure remote access. A novel ICS implant is the rare path.
Start with the operating problem. If unknown assets are the main risk, prioritize discovery and asset context. If the SOC needs OT-specific detection and response, prioritize monitoring and incident workflows. If vendors still share jump-box credentials, secure remote access should be part of the shortlist from day one. Flat Layer 2 and shared VPN credentials do more damage than missing threat intel. NIST SP 800-82r3 is still the reason active scans at the PLC are a bad first move. If you cannot see without scanning Level 1, you do not have a platform problem yet. You have a tap problem.
If you want CPS visibility plus asset-scoped vendor access in one console, start with Claroty - xDome or on-prem CTD, and read Advanced versus Essential. If Tenable One already owns IT exposure, Tenable OT Security is the sensor that feeds that model. If the need is detection content plus OT incident response, Dragos is the services bench. If you want a multi-site passive sensor trunk with Vantage or an on-prem console, Nozomi. If you want agentless OT visibility and, if needed, a path off Defender for IoT, Forescout eyeInspect. ICSForge is not a platform or a sensor. It is the open-source lab that shows whether the detections you already have fire. The method is on How we review tools.
What usually goes wrong when buying an OT security platform
Most quotes in this category fail for the same few reasons. The fix is operational, not a new acronym.
| Problem | Solution |
|---|---|
| A plant buy is sold as another IT sensor | Confirm the product sits on the plant trunk |
| Vendor access is a second console | Ask whether vendor access is in the same product |
| No public OT rate is on the page | Treat it as quote-only unless a public list rate exists |
| The item is not allowed to talk to the enterprise SOC | Read whether the plant zone can share that telemetry |
How we evaluated OT security platforms
We used four product-page checks: whether it sits on the plant trunk, whether vendor access is in the same product, whether any price is public, and whether the item is allowed to talk to production. Gartner category labels did not move a ranking. Neighbor products sit under What we left out.
TL;DR: The 6 Compared
| Service | Best for | What to check |
|---|---|---|
| Claroty | CPS visibility plus asset-scoped vendor access in one console (xDome or on-prem CTD) |
On the plantPassive discovery plus Edge when a zone will not take a SPAN. Secure Access is the brokered vendor path
PriceAWS 12-month dimensions: Essential $100,000.00; Essential Plus $275,000.00; Enterprise $350,000.00; Advanced $1,200,000.00. Advanced includes Secure Access. Essential does not
Watch-outThe listing does not define what one unit maps to. First-party remains quote-only
|
| Tenable OT Security | Tenable One already owns IT exposure and you want OT findings in that workflow |
On the plantPassive discovery and industrial protocol flows. Feeds Tenable One. Not an OT IR bench
PriceQuote. AWS listings are BYOL images. Software is licensed from Tenable. AWS is just the image
Watch-outDetection content is thinner than a dedicated OT IR platform. No public software price
|
| Dragos | Detection content plus OT incident response, if you will pay for the services layer |
On the plantPassive discovery, ATT&CK for ICS notifications, Edge Sensor, OT Watch / IR retainers
PriceFirst-party is custom. AWS: CentralStore $100,000.00 / 12 months, up to 50 connected SiteStores
Watch-outCost and UX are the usual buyer complaints. Deployments run service-heavy. OT-only
|
| ICSForge | Best validation tool alongside an OT security platform. Prove the detections you already have fire, without touching the plant |
Off the plantNot a sensor. Attacker-to-target traffic and PCAPs on private ranges only
PriceFree, GPLv3
Watch-outDetections that need the device’s reply cannot be proven with it. Authoring scenarios takes engineering time
|
| Nozomi Guardian + Vantage | Multi-site plants that need passive Guardian sensors and a Vantage or CMC trunk. |
On the plantPassive Guardian sensors on the trunk
PriceQuote-only
Watch-outOptional intel subscriptions
|
| Forescout eyeInspect | Plants that want a living OT trunk and, if needed, a path off Defender for IoT sensors into Forescout. |
On the plantAgentless OT NSM on the plant
PriceQuote-only
Watch-outNot Defender for IoT’s retired console
|
Claroty

Claroty is the CPS platform: OT, IoT, and medical devices, with asset discovery, exposure management, network protection, secure remote access, and threat detection. SaaS is xDome. On-prem is Continuous Threat Detection (CTD). xDome Secure Access is the brokered vendor path, SaaS or on-prem, scoped to an asset instead of a jump-box VLAN.
On 14 Apr 2026 it shipped Visibility Orchestration in xDome: a Visibility Score, prioritized tasks to fill attribute gaps, and hooks to trigger Edge scans, EDR, cloud, and SNMP from that queue so the inventory becomes work an engineer will approve. Passive discovery plus hardware-free Claroty Edge (Windows, Linux, Docker) covers zones that will not take a SPAN. The sensor being passive does not make the project small. Value depends on tap placement and a segmentation plan you can actually push.
Best for: Asset-rich industrials that want deep protocol coverage and a replacement for “give the integrator a VPN” in the same console.
What you get:
- Passive discovery plus hardware-free Claroty Edge when a zone will not take a SPAN.
- Exposure management that maps attack paths instead of dumping CVEs.
- Least-privilege communication policies pushed to existing firewalls, switches, or NAC.
- xDome Secure Access, agentless and asset-scoped, on-prem when the site cannot use a cloud broker.
Why we like it: It turns a brownfield inventory into a punch list. Visibility Orchestration is the honest admission that a raw asset list does not reduce risk. Secure Access replaces the shared jump-box password. Read the dimension name: Advanced includes it. Essential does not.
Limits:
- Value depends on tap placement and a segmentation plan you can actually push.
- Behavioral detection needs tuning on irregular process cycles.
- The AWS listing prints four 12-month dimensions and does not define what one unit maps to. Site count and asset count remain a conversation.
Price: First-party is quote-only. The AWS Marketplace listing prints four 12-month dimensions: Essential $100,000.00 (basic XIoT and technical services); Essential Plus $275,000.00; Enterprise $350,000.00 (adds threat detection); Advanced $1,200,000.00 (XIoT, Secure Access, threat detection, and technical services). Private offers are available. Refunds are not. Treat those figures as printed dimensions, not an all-in site quote.
Tenable OT Security

Tenable OT Security is the OT sensor that feeds Tenable One. Passive discovery, communication-flow mapping, vulnerabilities and misconfigs on gateways, then the same exposure view the IT team already uses. That is the product. Tenable is not selling OT incident response. The pitch is one risk model across IT, cloud, identity, and CPS so the plant stays in the same console.
Tenable was named a Challenger in the 2026 Gartner Magic Quadrant for CPS Protection Platforms (report dated 3 Mar 2026). Reviewers want deeper OT-native response and richer asset metadata. Detection content is thinner than Dragos. A second specialist console that nobody opens leaves the plant blind after the POC. That is the reason this sensor exists: OT findings land where someone already looks.
Best for: Organizations already standardized on Tenable for IT vulnerability and exposure who want OT findings in that workflow.
What you get:
- Passive asset discovery and industrial protocol flow mapping.
- Vulnerability and configuration insight on OT assets and exposed gateway services.
- Correlation into Tenable One so a finding that crosses IT/OT has one owner.
- BYOL images on AWS for the management stack. Software is licensed from Tenable. AWS is just the image.
Why we like it: OT findings land where someone already looks. If the plant is already a Tenable shop, a second OT console is how the POC dies after week six.
Limits:
- Reviewers want deeper OT-native response and richer asset metadata.
- Upgrade friction and IoT coverage show up in public reviews.
- No public software price. AWS listings are infrastructure plus BYOL.
Price: Quote. The AWS Marketplace listing for Tenable Core + OT Security, and the newer Core + OT Security Enterprise Manager listing, are BYOL images. Pricing and entitlements are managed through an external license with Tenable. AWS infrastructure is billed separately. No software list rate on the page.
Dragos

The Dragos Platform is OT detection with an intelligence and services bench behind it: passive asset discovery, notifications mapped to MITRE ATT&CK for ICS, guided investigation, and OT Watch / IR retainers. An Edge Sensor exists for constrained or remote sites. The content is downstream of plants Dragos has already been inside. That is a different product than a protocol decoder with a rules file.
The 17 Feb 2026 Year in Review named three new groups (SYLVANITE, PYROXENE, and AZURITE) and tracked KAMACITE mapping U.S. control loops plus ELECTRUM against Polish distributed energy. Dragos counted 1,140 ransomware incidents against industrial organizations in Q2 2026, up 12% from 1,020 in Q1. Manufacturing took 747 of them (65%). Operators stayed short of ICS Stage 2 that quarter. Production still stopped when ERP, virtualization, or remote access died. On the weekend of 26–27 Jul 2026, a coordinated attack hit operational technology at more than 30 Minnesota water utilities. The path CISA named afterward was internet-facing MicroLogix PLCs, lockout by password and IP change.
Best for: Critical infrastructure and large manufacturers that want detections tied to live OT casework, and will pay for the services layer when something pages at 2 a.m.
What you get:
- Passive discovery and industrial protocol visibility, Edge Sensor for thin sites.
- Intelligence-led and behavioral detections, updated through threat behavior analytics packs.
- Guided investigation playbooks and SOC integrations.
- Assessment and OT Watch services. The annual report is the same team.
Why we like it: The detections are downstream of casework, not a rules file someone wrote from a spec. That is the product when the plant will page a process engineer at 2 a.m.
Limits:
- Cost and UX are the usual buyer complaints. Deployments run service-heavy.
- OT-only. You still need IT and identity coverage elsewhere.
- First-party is quote-only. The AWS dimension is a CentralStore unit, not a per-asset plant quote.
Price: Custom on the vendor site. Contact Dragos. The AWS Marketplace listing prints one 12-month dimension: Dragos CentralStore Cloud Subscription $100,000.00, up to 50 connected SiteStores. Add units if you need more than 50 SiteStores. Treat that as a published Marketplace dimension, not an all-in IR retainer.
ICSForge

ICSForge is not an OT security platform or a monitoring sensor. It is an open-source validation lab (GPLv3) on GitHub that generates attacker-to-target industrial traffic and PCAPs so you can see whether the detections, firewall, and SIEM you already have actually fire. It does not talk to production devices. Live sends stay on private address ranges.
The lab covers 10 industrial protocols and 627 scenarios, including 16 named chains (Industroyer2, CrashOverride, a TRITON-inspired safety sequence, and an Oldsmar-style water path) and 77 MITRE ATT&CK for ICS technique IDs. Each scenario can emit three tiers of Suricata and Sigma rules. Semantic is the tier meant for production. Offline PCAP generation and a stateful TCP handshake mode exist so stream-reassembly engines get a real session. Authoring scenarios that match your process takes engineering time. That engineering time is the cost.
Best for: OT detection engineers and SOCs that already have a sensor, firewall, or SIEM and need to prove the rules fire after a firmware or sensor upgrade, without touching the plant. Not a substitute for Claroty, Tenable, or Dragos.
What you get:
- 627 runnable scenarios across 10 protocols, ATT&CK Navigator export.
- Auto-generated Suricata and Sigma rules in three tiers.
- Offline PCAPs plus optional live send on private ranges only.
- Alert ingestion so you can diff what was sent against what the sensor logged.
Why we like it: It is the only item here whose job is to make you less confident. Rules nobody has ever seen fire are how plants fail the next tabletop.
Limits:
- Attacker-to-target only. Detections that need the device’s reply cannot be proven with it.
- Timing and bidirectional behavioral analytics are out of scope.
- Authoring scenarios that match your process takes engineering time.
Price: Free, GPLv3.
Nozomi Guardian + Vantage

Nozomi Guardian is the passive OT and IoT sensor: it sits on a mirrored port or tap, inventories communicating devices, maps protocols and flows, baselines behavior, and flags anomalies and threats without sending traffic onto Level 1. Sensors ship as hardware, VMs, containers, or embedded devices. They feed Nozomi Vantage in the cloud or an on-prem Central Management Console. Air-gap and passive-only modes are product language for NERC CIP, nuclear, and defense sites that will not take an active query.
That is a different plant buy than Claroty or Dragos. Claroty’s Advanced line includes Secure Access in the same console. Dragos is detection content plus an IR retainer. Nozomi is the multi-site trunk: Guardian on the SPAN, Vantage or CMC as the plant-wide view, Guardian Air for wireless, Remote Collectors for thin sites, and Arc endpoint sensors when a host can take one. Vantage is described as a subscription with unlimited sensors. Threat Intelligence and Asset Intelligence are optional subscriptions on top.
Best for: Multi-site plants that need passive Guardian sensors and a Vantage or on-prem CMC trunk, especially where air-gap or passive-only is a hard rule.
What you get:
- Passive DPI on SPANs and taps: asset inventory, protocol map, behavior baseline, anomaly and threat detection, NVD vulnerabilities.
- Vantage cloud management, or an on-prem Central Management Console for air-gapped sites.
- Guardian Air for wireless, Remote Collectors, and Arc endpoint sensors as add-on sensors in the same architecture.
- Optional Threat Intelligence and Asset Intelligence subscriptions.
Why we like it: You can keep a multi-site plant on passive Guardian sensors and still choose Vantage in the cloud or a console that never leaves the site. That is the trunk when you will not put an active query on Level 1, and when vendor access is a different purchase than the sensor.
Limits:
- No public sensor or site rate. Vantage’s “unlimited sensors” line is a subscription description, not a printed plant quote.
- Threat Intelligence and Asset Intelligence are extra. Budget them as separate yeses.
- Vendor access is not in this product the way Claroty Secure Access is on Advanced. You still need a brokered path for Friday’s integrator.
Price: Quote-only. First-party pages are Guardian and Vantage. No public sensor or site dollar.
Forescout eyeInspect

Forescout eyeInspect is the OT and ICS visibility product on the Vistaro platform: agentless discovery, 350-plus protocols, 30-plus discovery methods, and air-gap, on-prem, hybrid, or cloud. It inventories assets, baselines process and network behavior, and detects threats from a CPS-specific library of TTPs and IOCs from Vedere Labs. Change alerts, a curated CPS vulnerability database, and role-based maps are the day-to-day console.
Deployment is the OT network security monitor, not a firewall profile. Segmentation and NAC sit on the wider Vistaro suite (eyeControl, eyeSegment). A Microsoft Sentinel connector extends the plant view into a SOC that already lives there. Microsoft Defender for IoT’s on-prem management console retired 1 January 2025. Forescout publishes a replacement path for eligible sensors. That is a living trunk if you are leaving that console. It is not a reason to treat Defender for IoT as a peer on this list.
Best for: Plants that want agentless OT visibility on the trunk, and that may already run Forescout for NAC or need a path off Defender for IoT sensors.
What you get:
- Agentless OT, IoT, IoMT, and building-system visibility across 350-plus protocols.
- Air-gap, on-prem, hybrid, or cloud, with process and network baselining.
- Vedere Labs threat content, a CPS vulnerability database, and change detection.
- A path into Vistaro NAC and segmentation, plus a Microsoft Sentinel connector and a published Defender for IoT replacement offer.
Why we like it: eyeInspect is the OT monitor that already speaks a wide protocol set and can hand segmentation to Vistaro instead of leaving the plant on a dashboard nobody enforces. If the site is leaving Defender for IoT, the replacement path is a buying reason, not a footnote.
Limits:
- Quote-only. No public sensor or site rate.
- Full NAC and zero-trust value assumes the wider Forescout / Vistaro suite, not eyeInspect alone.
- It is not an OT IR bench and not Claroty Secure Access. Detection content and brokered vendor access are different purchases.
Price: Quote-only. First-party page is forescout.com/products/eyeinspect. A Microsoft Marketplace listing is MACC-eligible and still has no list rate.
Does it sit on the trunk, and is vendor access in the same console?
This grid plots two questions. Across is what you are buying: visibility plus vendor access in one console on the left, detection content or an IT exposure feed on the right. Up is whether it sits on the plant: a sensor on the trunk at the top, a lab that must not touch production at the bottom.
Placement follows product language: xDome / CTD plus Secure Access on Advanced, a Tenable One feed, Dragos Platform plus services, and a GPLv3 lab that must not touch production. Essential does not include Secure Access on the Claroty listing. The grid places products; it does not grade them.
Pricing and usage costs compared
| Service | Published rate | What the quote still hides |
|---|---|---|
| Claroty | Essential $100,000.00; Essential Plus $275,000.00; Enterprise $350,000.00; Advanced $1,200,000.00 / 12 months | What one unit maps to. Site count, asset count, and whether on-prem Secure Access phones a cloud control plane |
| Tenable OT Security | Quote. AWS is BYOL | The software license. AWS bills the image. Tenable bills the product |
| Dragos | AWS CentralStore $100,000.00 / 12 months, up to 50 SiteStores. First-party custom | Whether OT Watch / IR retainers sit on that unit. Per-site sensor count above 50 |
| ICSForge | Free, GPLv3 | Engineering time to author scenarios that match your process. That time is the cost |
| Nozomi Guardian + Vantage | Quote-only | Guardian plus Vantage or an on-prem CMC. Threat Intelligence and Asset Intelligence are extra. Vendor access is a different product |
| Forescout eyeInspect | Quote-only | eyeInspect is the OT monitor. NAC and segmentation sit on the wider Vistaro suite |
What we left out
They sit next door because they lack a CPS sensor that belongs on this page, a public or quoted price, or a lab that proves the other three.
- Armis - The other CPS conversation. Right on a wider CPS shortlist. Not this plant-trunk six.
- Fortinet FortiGate / FortiNAC OT profiles - If the plant is already a Fortinet shop, the work is policy on the existing firewall. A new sensor is a different project.
- Microsoft Defender for IoT - On-prem management console retired 1 January 2025. Keep sensors as a feed if you must. It is not a living multi-site plant trunk. Forescout publishes a replacement path.
Questions before you span a plant
If the quote stays silent on these three, you are still buying a jump-box with a new dashboard.
- Can you see without scanning Level 1? If the answer is no, you have a tap problem. NIST SP 800-82r3 is still the reason active scans at the PLC are a bad first move.
- Who holds the vendor credentials? Shared jump-box passwords are how ransomware walks in without an ICS payload. Ask whether asset-scoped access is in the product on the page, or a separate integration.
- How will you know the new rule fired? A coverage lab is the honest check. Pick the sensor first if you have none. Pick the lab if you already bought one and cannot prove it.
Which OT security platform should you pick
CPS visibility plus asset-scoped vendor access in one console: Claroty, and read Advanced versus Essential - Advanced is the $1,200,000.00 listing that includes Secure Access. Tenable One already owns exposure: Tenable OT Security, knowing the software is quote and AWS is BYOL. Detection content plus OT IR: Dragos, with a $100,000.00 CentralStore dimension on AWS and a services line the listing will not price. Already have a sensor and cannot prove it: ICSForge, free, off the plant. Passive Guardian plus Vantage: Nozomi, quote. Living OT NSM and a Defender for IoT off-ramp: Forescout eyeInspect, quote. Then put the matching page next to a SPAN you can actually place.
Frequently asked questions
Can we see the plant without scanning Level 1?
If the answer is no, you do not have a platform problem yet. You have a tap problem. Passive discovery and an Edge when a zone will not take a SPAN are the answers on this list. NIST SP 800-82r3 is still the reason active scans at the PLC are a bad first move.
Does on-prem Secure Access still phone a cloud control plane?
The Claroty Secure Access page says cloud and on-prem. It does not say whether the on-prem broker still phones a Claroty cloud control plane for policy. Ask before you buy if the site is air-gapped. On the AWS listing, only Advanced includes Secure Access. Essential does not.
Is ICSForge a substitute for a plant sensor?
No. It is a GPLv3 lab that generates attacker-to-target traffic so you can see whether the detections, firewall, and SIEM you already have fire. It does not talk to production. Detections that need the device’s reply cannot be proven with it. Pick the sensor first if you have none.




