September 29, 2026 Global Pulse

OT and Industrial Cybersecurity Has Become the Critical Infrastructure Risk That Cannot Be Patched With Enterprise IT Tools

By Isabelle Fontaine | Senior Analyst, Cross-Sector Equity & Market Intelligence
9 min read

The Network That Was Never Designed to Be Connected to the Internet and Now Is

Operational technology, the hardware and software that monitors and controls physical industrial processes in power plants, water treatment facilities, oil refineries, chemical manufacturing plants, pharmaceutical production facilities, and transportation infrastructure, was designed and deployed in an era when the industrial control systems, programmable logic controllers, distributed control systems, and supervisory control and data acquisition systems that constitute the OT environment were either entirely isolated from external networks or connected only through carefully controlled, single-purpose communication links whose security was assumed to derive from physical and logical isolation rather than from the cryptographic authentication and access controls that information technology security relies on. The past decade's convergence of IT and OT networks, driven by the operational efficiency benefits of connecting plant floor systems to enterprise data systems, remote monitoring and predictive maintenance applications, and the cloud analytics platforms that extract value from the sensor data that industrial systems generate in abundance, has progressively eroded the air gap that constituted OT security's foundational assumption, creating the network-connected industrial control system whose connectivity enables the operational intelligence that drives efficiency and the cyberattack surface that the OT security market exists to defend. The consequence of this convergence has been the emergence of the industrial cyberattack as a practical threat whose real-world materialisation in the Stuxnet destruction of Iranian uranium enrichment centrifuges in 2010, the Ukraine power grid attacks of 2015 and 2016, the Triton safety system attack on a Saudi Aramco petrochemical facility in 2017, and the Colonial Pipeline ransomware attack of 2021 that disrupted US fuel supply across the east coast, established the industrial cyberattack as an operational and national security risk whose consequence, unlike a data breach, is physical disruption of critical infrastructure rather than the loss of data.

The OT and industrial cybersecurity market, valued at approximately $22 billion in 2026 and growing at over nineteen percent annually toward $52 billion by 2031, encompasses the asset visibility and network monitoring products that create the inventory and behaviour baseline for industrial environments whose security cannot be managed without first knowing what devices are connected and what constitutes normal communication, the threat intelligence services whose industrial-specific threat actor tracking and vulnerability research differs from enterprise IT threat intelligence in the specificity of OT protocols, device types, and attacker objectives it must address, and the security operations centre capabilities that industrial environments require to detect, triage, and respond to OT threats without disrupting the continuous industrial processes whose interruption creates the physical and economic consequences that justify the security investment.

Claroty and the Asset Visibility Foundation

Claroty, the US-Israeli OT security company backed by Rockwell Automation, Schneider Electric, and Siemens, has built the market leadership position in OT asset visibility and network monitoring through the passive network monitoring approach that creates a comprehensive inventory of every OT device, its communication patterns, and its vulnerability profile without sending active scanning traffic that could disrupt the sensitive industrial processes that safety-critical OT systems manage. Its Platform, which encompasses the Medigate healthcare IoT security product acquired in 2022 alongside its industrial OT capabilities, serves the convergence of industrial, healthcare, and commercial building OT environments whose common characteristic of managing critical physical processes with legacy devices that cannot be patched without extended maintenance windows creates the security visibility and monitoring requirement that Claroty's passive discovery approach addresses without the operational disruption risk that active scanning creates. Dragos, the US industrial threat intelligence and OT security company founded by former NSA and US Cyber Command OT security specialists, provides the threat intelligence whose specificity to industrial control system threat actors, the OT attack tools they use, and the industrial protocols and devices they target differentiates Dragos's intelligence from the enterprise IT threat intelligence whose IT-specific threat actor tracking and malware analysis does not address the industrial-specific threat landscape that OT security teams must defend against.

Its Neighborhood Keeper collective defence programme, which allows Dragos industrial customers to share anonymised threat data with each other through the Dragos platform, creates the collective intelligence mechanism that the widely dispersed industrial security community, whose expertise is concentrated in a small number of specialist companies and government agencies, needs to benefit from the threat observations that each individual industrial operator's security team cannot generate at the breadth and depth that adversary tracking requires. Nozomi Networks, the US-Swiss OT and IoT security company, provides the network visibility and anomaly detection platform that the operational technology security team uses to monitor industrial networks for the deviations from normal communication patterns that indicate either misconfiguration, equipment failure, or cyberattack activity whose distinction from each other requires the OT-specific protocol knowledge that enterprise IT security tools whose understanding of OT protocols is limited cannot provide. Waterfall Security Solutions, the Israeli OT security company whose Unidirectional Security Gateway technology creates hardware-enforced one-way data flows from OT to IT networks that are physically incapable of transmitting attack traffic from the IT network into the OT environment, provides the technology whose mathematical security guarantee derives from the physical impossibility of reverse data flow through a system that contains no components capable of transmitting data in the IT-to-OT direction, offering the highest available assurance for the OT environments whose risk tolerance for network-borne attack is lowest.

The NERC CIP Compliance Driver and the IT Tool Inadequacy

The regulatory compliance framework whose mandatory requirements are the primary procurement driver for OT security investment in the North American electric utility sector is the NERC Critical Infrastructure Protection standards, whose version 7 requirements for supply chain risk management, physical security, and electronic security perimeter protection create the compliance programme that North American electricity transmission and generation operators must implement and audit to avoid the civil monetary penalties whose maximum per-violation-per-day fine level creates the financial incentive for compliance investment that voluntary security best practice guidance cannot generate. The inadequacy of enterprise IT security tools for OT environments derives not from the tools' technical limitation in detecting network anomalies but from their lack of understanding of the industrial protocols, Modbus, DNP3, EtherNet/IP, PROFINET, and OPC-UA, whose communication patterns define normal OT network behaviour and whose deviations require OT-protocol-aware detection logic to distinguish the legitimate process control communication from the attacker's lateral movement and command-and-control traffic that uses the same protocols.

Top 10 Companies in OT and Industrial Cybersecurity Globally

  1. Claroty: US-Israeli OT security company backed by Rockwell, Schneider, and Siemens with passive OT asset discovery and network monitoring; its industrial and healthcare OT convergence platform and its strategic investor ecosystem create the OT security company whose passive visibility approach and its automation vendor backing give it the industrial customer trust that pure cybersecurity startups without operational technology heritage must work harder to establish.
  2. Dragos: US industrial threat intelligence company founded by former NSA specialists with ICS-specific threat actor tracking; its Neighborhood Keeper collective defence and its industrial-specific threat intelligence create the OT security company whose threat intelligence specificity to industrial control system attack techniques and adversary groups is the deepest available from any commercial source.
  3. Nozomi Networks: US-Swiss OT and IoT security company with OT-protocol-aware network monitoring; its Guardian network sensor and its Vantage cloud management platform create the OT security company whose protocol-specific anomaly detection addresses the gap between enterprise IT security monitoring tools and the industrial protocol environment they cannot interpret.
  4. Waterfall Security Solutions: Israeli OT security company with hardware-enforced Unidirectional Security Gateway; its physically one-way data flow technology and its critical infrastructure deployments create the OT security company whose hardware-guaranteed security model provides the highest assurance level for the nuclear, power grid, and oil and gas facilities whose risk tolerance for network-borne OT attack is lowest.
  5. Honeywell (Forge Cybersecurity): US industrial automation company with Forge Cybersecurity Suite for OT environments; its process automation heritage and its installed base of Honeywell DCS and safety systems in oil and gas, petrochemical, and power generation create the automation vendor whose OT cybersecurity offering serves the existing Honeywell process control customer base whose familiarity with Honeywell systems creates the preferred vendor relationship for cybersecurity services.
  6. Siemens (OT Security): German industrial automation company with OT security services for its SIMATIC and energy management installed base; its automation system market share in European manufacturing and power generation and its Claroty investment create the industrial automation company whose OT security offering is most deeply integrated with its own control system product portfolio.
  7. Microsoft (Defender for IoT): US technology company with Defender for IoT OT security monitoring acquired from CyberX; its Azure cloud integration and its enterprise IT security platform create the technology company whose OT security entry through the CyberX acquisition allows enterprise IT security teams to extend their Microsoft security tooling into OT environments whose monitoring the IT team must manage alongside the enterprise security operations.
  8. Tenable (OT Security): US cybersecurity company with OT security asset management acquired from Indegy; its vulnerability management heritage and its OT asset inventory and risk scoring create the cybersecurity company whose OT offering extends its enterprise IT vulnerability management into the industrial environment for the customers whose converged IT-OT security programme prefers a single vendor's visibility across both environments.
  9. OTORIO: Israeli OT security company with OT risk management and compliance platform; its risk quantification and its NERC CIP and IEC 62443 compliance management create the OT security company whose risk-based approach to OT security investment prioritisation addresses the resource constraint that most industrial operators face when determining which OT vulnerabilities to remediate first within the maintenance window limitations that continuous production imposes.
  10. Radiflow: Israeli OT security company with CIARA OT risk management and network monitoring; its threat modelling and its industrial sector segmentation across energy, manufacturing, and water create the OT security company whose risk management and network monitoring combination serves the smaller industrial operators whose security team cannot maintain the specialist OT security expertise in-house that the largest critical infrastructure operators develop through dedicated OT security programmes.

Back to All Insights
×