You think you know your OT asset inventory until a passive tap decodes a forgotten Modbus trunk and lights up decades-old PLCs no one owned. The same traps keep showing up across industrial sites: vendor laptops with default credentials on an HMI VLAN, flat Layer 2 between historians and safety PLCs, and remote access that rides RDP through a jump box.
The cost of getting this wrong is climbing again. The global average breach reached a record $4.99 million in 2026, up 12% year over year, and one in four malicious breaches were AI-enabled at an average cost of roughly $6 million (IBM Cost of a Data Breach Report 2026).
Budgets are following: Gartner projects worldwide end-user spending on information security to grow 12.5% in 2026 to $240 billion, up from $213 billion in 2025 (Gartner forecast).
The problem is that OT programs still lag IT maturity where it counts. Dragos found that only 46% of assessments had adequate OT network monitoring deployed, 81% identified poor IT/OT segmentation, and 73% of all-time incident response cases involved compromised VPN or jump host credentials (Dragos 2026 OT Cybersecurity Year in Review).
Our position is simple: OT defenses that prioritize safe visibility and remote access hardening cut the most risk first. Below is where each platform fits, what it actually does inside an ICS network, and how to avoid expensive rework.
Claroty

Cyber-physical systems security platform covering OT, IoT, and medical devices. It combines asset discovery, exposure management, network protection, secure remote access, and threat detection in one platform.
Claroty raised a $150 million Series F in January 2026 led by Golub Growth, and was named a Leader for the second consecutive year in the 2026 Gartner Magic Quadrant for CPS Protection Platforms published on March 3, 2026 (Claroty Series F announcement). In April 2026 it shipped Visibility Orchestration in xDome, which turns partial asset data into prioritized, measurable remediation actions rather than a raw inventory dump (PR Newswire).
Best for:
Asset-rich industrials that want deep protocol coverage plus brokered secure access for vendors and contractors.
Key Features:
- Multiple asset discovery methods, including passive monitoring and the hardware-free Claroty Edge scan, so teams can match the discovery technique to the risk tolerance of each zone, per vendor documentation and analyst summaries on Gartner Peer Insights.
- Exposure management that scopes CPS assets, prioritizes vulnerabilities, and maps specific attack vectors instead of dumping a raw CVE list (Gartner Peer Insights).
- Network protection that recommends least-privilege communication policies and pushes them to existing firewalls, switches, or NAC, which is what makes a segmentation project finishable (vendor documentation).
- xDome Secure Access, available as SaaS or on-premises, giving agentless, asset-scoped access for third parties instead of the broad network reach a VPN or jump server grants (vendor documentation).
Why we like it:
It builds a trustworthy inventory in brownfield plants without touching processes, then converts that inventory into exposure-reduction work an engineering team will actually approve.
Notable Limitations:
- Full value depends on proper SPAN or tap placement and a segmentation plan you can execute, so the deployment effort is real even though the sensor is passive.
- Behavioral detection needs tuning to reduce noise in plants with irregular process cycles, a common theme across CPS platform buyer feedback.
- Pricing is quote-driven and varies widely by asset count, sites, and modules, which slows budgeting (RFP.wiki).
Pricing:
Not publicly listed. Claroty sells through custom quotes and private offers. Directional 2026 tiers reported from AWS Marketplace private offers run from roughly $100,000 per year for Essential to roughly $1.2 million for Advanced, including bundled technical services, and total cost rises with protected assets, sites, deployment model, and modules such as Secure Remote Access (RFP.wiki). Contact Claroty for a scoped quote.
Tenable OT Security

OT security product that discovers assets passively, maps communication flows, and highlights vulnerabilities and misconfigurations. It feeds the broader Tenable One exposure management platform.
Tenable was named a Challenger in the 2026 Gartner Magic Quadrant for CPS Protection Platforms, and positions OT Security as one input to a unified exposure view spanning IT, cloud, identity, and cyber-physical systems (Tenable analyst announcement). That framing is the whole point of the product: it is built for organizations that already run Tenable on the IT side and want one risk model rather than two.
Best for:
Organizations standardizing on Tenable for IT exposure management who want OT visibility inside the same workflow.
Key Features:
- Passive asset discovery and communication flow mapping across industrial protocols, per vendor documentation and buyer feedback on PeerSpot.
- Vulnerability and configuration insight for OT assets, surfacing exposed services and misconfigurations on gateway devices for targeted hardening (PeerSpot).
- OT and IT exposure correlation through Tenable One, which is what shortens remediation reporting when a single finding spans both domains (Tenable analyst announcement).
- Deployment images available for cloud infrastructure under a bring-your-own-license model (AWS Marketplace listing).
Why we like it:
Clean handoffs into existing Tenable vulnerability and risk workflows mean the OT findings land somewhere a team already looks, instead of in a second console nobody opens.
Notable Limitations:
- Reviewers ask for deeper product integration and more automated response options specific to OT, with the interface and asset metadata depth called out for improvement (PeerSpot).
- Some users report upgrade friction and want broader IoT coverage (PeerSpot).
- OT-native threat intelligence is thinner than at the OT-only specialists, so detection content is a relative weak point compared with visibility.
Pricing:
Not publicly available. BYOL images exist for deployment infrastructure in AWS, but the software is licensed directly (AWS Marketplace listing). Contact Tenable for a custom quote.
Dragos Platform

OT cybersecurity platform with automated asset discovery, threat detection backed by OT-specific threat intelligence, and guided investigation workflows. It is frequently paired with expert services.
Dragos published its ninth annual OT/ICS Cybersecurity Year in Review on February 17, 2026, identifying three new threat groups and documenting adversaries moving from reconnaissance into operational disruption, including KAMACITE mapping control loops across U.S. infrastructure and ELECTRUM targeting distributed energy resources in Poland (Dragos press release). That research is not marketing garnish; it is the same intelligence that shapes the platform's detection content. The report also tracked 119 ransomware groups affecting 3,300 industrial organizations in 2025, a 49% increase from 80 groups in 2024, with manufacturing accounting for more than two-thirds of victims (Dragos 2026 Year in Review).
Best for:
Critical infrastructure operators and large manufacturers that want a platform plus field-proven threat intelligence and incident response services.
Key Features:
- Passive asset discovery and industrial protocol visibility, with an Edge Sensor option for bandwidth-constrained or remote sites, per vendor documentation.
- Intelligence-led and behavioral detections mapped to MITRE ATT&CK for ICS and updated through recurring threat behavior analytics packs (vendor documentation).
- Guided investigation playbooks and integrations into SOC tooling, reflected in third-party listings like Capterra.
- Assessment and OT Watch services that pair the technology with OT-specific responders, which matters because organizations with strong OT visibility contained ransomware in about five days versus a 42-day industry average (Dragos 2026 Year in Review).
Why we like it:
The detection content is downstream of real incident response casework in plants, so what it flags tends to map to how intrusions actually unfold rather than to generic IT anomaly baselines.
Notable Limitations:
- Cost and user experience are the most common improvement requests in buyer feedback.
- Deployments are frequently service-heavy and tuning-intensive relative to buyer expectations (RFP.wiki).
- The OT-only focus means you will still need separate coverage for enterprise IT and identity.
Pricing:
Not publicly available. Third-party directories list contact-vendor pricing (Capterra). Contact Dragos for a custom quote.
ICSForge

Open-source OT and ICS security coverage validation platform. It generates realistic industrial protocol traffic and PCAPs so teams can test whether their detection content, firewall policy, and sensors actually fire.
ICSForge is released under GPLv3 and generates traffic across 10 industrial protocols, including Modbus/TCP, DNP3, S7comm, IEC-104, OPC UA, EtherNet/IP, BACnet/IP, MQTT, IEC 61850 GOOSE, and PROFINET DCP, mapped to 77 distinct MITRE ATT&CK for ICS technique IDs across 627 runnable scenarios and named attack chains (ICSForge). It is built around a sender-receiver architecture that never touches production devices and, by default, restricts live sends to private address ranges.
Best for:
OT security teams and SOCs that want to validate coverage, tune detections, and regression-test changes without touching live plants.
Key Features:
- Scenario generation across 10 industrial protocols with named attack chains modelled on real campaigns, including Industroyer2, Industroyer/CrashOverride, a TRITON-inspired safety system chain, and an Oldsmar-style water treatment sequence (ICSForge).
- Auto-generated Suricata and Sigma detection rules per scenario in three tiers, from lab marker through protocol heuristic to function-code semantic, with the semantic tier recommended for production (ICSForge).
- Offline PCAP generation plus PCAP upload and replay, and a stateful mode that emits a full TCP handshake and teardown so stream-reassembly engines are properly exercised (ICSForge).
- ATT&CK for ICS coverage mapping with a downloadable Navigator layer for gap analysis, plus alert ingestion so witnessed traffic can be diffed against what the sensor actually fired (GitHub repository).
Why we like it:
It brings test-driven thinking to OT detection engineering, which shortens tuning cycles and, more importantly, prevents false confidence in rules nobody has ever seen trigger.
Notable Limitations:
- It is a traffic generator, not a device or session emulator. Traffic is attacker-to-target only, so detections keyed on a device's reply cannot be validated with it (ICSForge).
- Timing, rate, and behavioral analytics that depend on full bidirectional conversation dynamics are out of scope.
- Building scenarios that mirror your local process takes engineering time. That is a people and process cost, not a product gap.
Pricing:
Free and open source under GPLv3 (ICSForge).
OT & ICS Security Tools Comparison: Quick Overview
| Tool | Best For | Pricing Model | Highlights |
|---|---|---|---|
| Claroty | Deep protocol visibility plus secure vendor access | Custom quote, private offers common | Leader in the 2026 Gartner Magic Quadrant for CPS Protection Platforms, $150M Series F in January 2026 |
| Tenable OT Security | Orgs consolidating IT and OT exposure workflows | Custom quote, BYOL images for infrastructure | Challenger in the 2026 Gartner Magic Quadrant, unified exposure view through Tenable One |
| Dragos Platform | Critical infrastructure and large manufacturers | Custom quote | Detection content driven by ninth-year OT threat research and live incident response casework |
| ICSForge | Coverage validation and detection engineering | Free, open source (GPLv3) | 627 scenarios across 10 protocols mapped to 77 ATT&CK for ICS techniques |
OT & ICS Security Platform Comparison: Key Features at a Glance
| Tool | Passive Asset Discovery | Threat Detection Content | Secure Remote Access |
|---|---|---|---|
| Claroty | Yes, plus optional Edge scanning | Yes | Yes, native and asset-scoped |
| Tenable OT Security | Yes | Yes, IT-correlated | Via integrations |
| Dragos Platform | Yes | Yes, OT threat intel led | Via integrations and services |
| ICSForge | Not applicable, generates test traffic | Not applicable, validates coverage | Not applicable |
OT & ICS Security Deployment Options
| Tool | Deployment Model | Air-Gapped Operation | Integration Complexity |
|---|---|---|---|
| Claroty | SaaS (xDome) or on-premise (CTD), hybrid supported | Supported, common in regulated sites | Medium, depends on SPAN or tap strategy and segmentation scope |
| Tenable OT Security | On-premise sensors, cloud images available under BYOL | Supported, common in regulated sites | Medium, lower if Tenable is already the IT standard |
| Dragos Platform | On-premise sensors with Edge Sensor for remote sites | Supported, common in regulated sites | Medium to high, tuning is usually required |
| ICSForge | Local lab or workstation, Docker or pip install | Yes, offline PCAP generation needs no network | Low to medium, scenario authoring is the real effort |
OT & ICS Security Strategic Decision Framework
| Critical Question | Why It Matters | What to Evaluate | Red Flags |
|---|---|---|---|
| How will you gain safe visibility without active scanning? | NIST warns that traditional active scanning can disrupt OT processes | Passive discovery depth, protocol coverage, SPAN or tap strategy, optional safe scanning for quiet zones | Vendor pushes active scans at Level 1, see NIST SP 800-82r3 |
| How is remote access brokered and monitored? | Compromised VPN and jump host credentials featured in 73% of Dragos incident response cases | MFA and hardware keys, session recording, broker placement, asset-scoped rather than network-wide access | Shared vendor credentials, exposed RDP, unpatched VPN appliances, no inventory of who connects in |
| Can the platform operate air-gapped? | Many plants require offline operation | Update mechanics, offline triage, portable collectors, sensor behavior when the cloud link drops | Cloud-only architecture with no offline update path |
| How will you validate detection coverage? | 56% of penetration tests abused living-off-the-land tools without triggering an alert | Ability to replay ICS traffic safely, ATT&CK for ICS mapping, exportable rules, gap reporting | No way to test rules before production, no MITRE mapping, detection claims with no evidence |
| What standards or directives guide your controls? | Alignment drives procurement, audit, and insurer conversations | IEC 62443 zones and conduits, NIST SP 800-82 control families, sector-specific directives | No mapping to IEC 62443 or NIST, standards overview at ISA |
OT & ICS Security Solutions Comparison: Pricing and Capabilities Overview
| Organization Size | Recommended Setup | Monthly Cost | Annual Investment |
|---|---|---|---|
| 50-300 assets, single site | Claroty or Tenable OT Security pilot for passive inventory, plus ICSForge for detection validation | Not publicly listed, quote-driven | Entry CPS platform tiers reported around $100,000 per year directionally, with ICSForge adding no license cost |
| 300-1500 assets, multi-site | Dragos or Claroty for visibility and detections, a formal secure remote access program, ICSForge for regression tests | Not publicly available | Contact vendors for quotes, third-party directories list contact-vendor pricing across all three |
| Regulated critical infrastructure | Platform plus services, architected for air-gapped operation, heavy remote access controls, coverage validation in pre-production | Not publicly available | Advanced tiers reported up to roughly $1.2 million per year including bundled services, budget against the broader $240 billion 2026 security spend trend |
Problems & Solutions
-
Problem: Unknown assets and flat networks increase blast radius.
- Context: NIST highlights the safety and reliability constraints unique to OT and the need for architecture, segmentation, and careful monitoring. Dragos found poor IT/OT segmentation in 81% of assessments.
- Claroty: Builds a high-fidelity inventory passively, then recommends least-privilege communication policies it can push to your existing firewalls, switches, or NAC so segmentation moves from diagram to enforcement.
- Tenable OT Security: Unifies asset and vulnerability views across IT and OT, which improves exposure reporting when a finding crosses the boundary.
- Dragos: Adds OT threat intelligence to detections that flag risky communications between zones that should never talk.
- ICSForge: Lets teams replay realistic ICS traffic across zone boundaries and measure whether the ACL actually blocked it, rather than trusting the firewall rule comment.
-
Problem: Insecure remote access paths drive many OT findings.
- Context: Compromised VPN or jump host credentials appeared in 73% of all-time Dragos incident response cases, and Google's 2026 forecast expects poor hygiene around insecure remote access to keep letting commodity Windows malware into OT networks (IT Brew).
- Claroty: Offers brokered secure access with session controls and asset-scoped permissions, available on-premises for sites that cannot depend on a cloud broker.
- Tenable OT Security: Surfaces exposed services and misconfigurations on gateway devices so hardening effort goes where the exposure actually is.
- Dragos: Detection content aligned to common remote access abuse and ransomware tradecraft, informed by the incident response cases behind the annual report.
- ICSForge: Generates protocol scenarios that cross the remote access path to validate detection logic before rollout rather than during an incident.
-
Problem: It is hard to prove alignment to IEC 62443 and NIST controls without evidence of coverage.
- Context: IEC 62443 is the widely referenced standard for industrial automation and control system security, and auditors increasingly want proof rather than policy documents.
- Claroty and Tenable OT Security: Provide asset and flow baselines that map naturally to 62443 zones and conduits, which helps auditors and engineers use the same vocabulary.
- Dragos: Field findings from the annual report help prioritize which controls matter most this year, including the uncomfortable finding that only 46% of assessments had adequate OT network monitoring.
- ICSForge: Supplies repeatable tests that show detections still work after configuration changes and firmware updates, with an exportable ATT&CK for ICS coverage layer as the artifact you hand the auditor.
Bottom Line on OT & ICS Security
Start where incidents actually begin in real plants: basic visibility and remote access. Deploy a passive sensor to build an inventory, fix the worst misconfigurations on gateways and VPN appliances, and only then invest in advanced detection content.
The 2026 data makes the sequencing argument for us, with ransomware groups reaching industrial organizations up 49% year over year while fewer than half of assessed environments had adequate OT network monitoring in place.
Focus matters more than brand. If you must pick one accelerant, add test-driven detection engineering with an open tool like ICSForge so you can prove coverage before the next outage instead of discovering the gap during it.
For executive context, macro data points on security spending and breach cost remain the most reliable way to anchor an OT investment case, particularly the widening gap between what attacks cost to launch and what breaches cost to resolve.


