In Forrester's evaluation of this market, one vendor was the only participant to earn maximum scores across threat and anomaly detection, vulnerability management, and product security simultaneously.

It placed as a Strong Performer. The Leaders were two of the largest IT security companies in the world.

That vendor, Dragos, then published a response advising industrial organisations to view the report within what it called its IT-oriented context, on the grounds that OT environments are different: different threats, different systems, different adversaries.

A participating vendor publicly questioning an evaluation's frame is unusual. Whether the critique is right is the most useful question a buyer in this category can ask, because the answer determines which kind of vendor you should be shopping for.

Why operational technology is not just unusual IT

The distinction is not a matter of degree.

An IT system's worst outcome is data loss. An OT system's worst outcome is physical: a pressure vessel, a turbine, a chemical process, a rail signal, a hospital ventilator. Safety instrumented systems exist specifically to prevent that, and they are the systems security tooling must not disturb.

That inverts the standard priority order. IT security weights confidentiality, integrity, and availability roughly in that sequence. OT weights safety first, then availability, then integrity, with confidentiality frequently last. A plant that stops is losing money by the minute and may be in a hazardous state.

The equipment lifespan compounds it. Industrial controllers run for twenty to thirty years. A modern plant contains devices older than the engineers maintaining them, running firmware from vendors that no longer exist, communicating over protocols designed before network security was a consideration.

Patching is frequently not an option. A controller running a continuous process does not stop for a security update, and the vendor may not have issued one. Compensating controls, segmentation, and monitoring replace remediation as the primary strategy.

And the protocols are different. Modbus, DNP3, PROFINET, EtherNet/IP and their industrial siblings carry no authentication in their original forms. A command to change a setpoint looks like a legitimate command because there is no mechanism to establish otherwise.

Inside The Forrester Wave: Operational Technology Security Solutions, Q2 2024

Published on 11 June 2024 and authored by Brian Wrozek, the evaluation scored fifteen providers against twenty two criteria across current offering, strategy, and market presence, roughly three years after Forrester's first Wave on the topic.

Palo Alto Networks placed as a Leader with the highest scores in both current offering and strategy. Forrester described its vision as seamless integration of IT and OT in a comprehensive platform tailored to the unique challenges of industrial systems, and its offering as a compelling end-to-end OT security platform with a full stack spanning security operations, network, cloud, endpoint, and threat intelligence.

Cisco also placed as a Leader, with Forrester describing Industrial Threat Defense as a comprehensive solution to protect, detect, and remediate threats across IT and OT environments.

Claroty placed as a Strong Performer with maximum scores in asset discovery and identification, privileged remote access, risk posture management, and policy and rule management, alongside vision, roadmap, and adoption. It took the highest roadmap score of any participant. Forrester recorded its product vision as facilitating a shift from network-centric to asset-centric OT security grounded in zero trust principles, fitting the macro trends of device proliferation and the collapse of traditional network boundaries.

Dragos placed as a Strong Performer with the detection scores described above, plus maximum marks for adoption, OT security services, and community.

The critique, and what the scorecard supports

Dragos's argument is that an evaluation constructed from an IT security perspective will reward platform breadth over domain depth, and that in OT the domain depth is what protects you.

The scorecard partly supports it. The two Leaders are companies whose primary business is enterprise IT security, credited for end-to-end platforms and IT/OT integration. The vendor with the strongest OT-specific detection, vulnerability, and product security scores placed a tier below.

That is not evidence of a flawed evaluation. It is evidence that the criteria weighted platform completeness, and reasonable people disagree about whether they should.

Both positions have merit and they suit different organisations.

The platform argument is that IT and OT are converging whether anyone wants them to or not. Industrial systems now connect to enterprise networks, cloud analytics, and remote support. Attacks reach OT through IT in the overwhelming majority of documented cases. A security operation running separate tooling for each side has a seam, and seams are where incidents live.

The specialist argument is that OT threat detection requires knowing industrial adversaries, protocols, and process behaviour at a level general tooling does not encode. Recognising that a command sequence is malicious rather than merely unusual requires knowing what the process is supposed to do, which is engineering knowledge rather than security knowledge.

The practical resolution most mature organisations reach is both, with a platform providing coverage and a specialist providing depth in the environments where a failure would be physical. That is not a satisfying answer for a procurement process built around selecting one winner.

Remote access is where the risk concentrates

The most specific and actionable finding across this market is that remote access into operations is the top risk in OT cybersecurity.

The mechanism is easy to see once stated. Industrial equipment requires vendor support, and the vendor is rarely on site. So the plant has a remote access path for the controls vendor, another for the equipment manufacturer, another for the integrator, and often several established informally over the years by engineers who needed to check something from home.

Those paths frequently bypass the segmentation everything else depends on. A jump host with a shared credential, a modem nobody documented, a remote desktop tool installed for a commissioning project in 2018 that still works.

Claroty's maximum score in privileged remote access reflects where vendors are competing, and it is the right place. Replacing ad hoc access with brokered, identity-bound, session-recorded, time-limited connections addresses the single largest entry vector without touching the control systems themselves.

For an organisation that can only fund one OT security initiative, this is generally the one with the best ratio of risk reduced to disruption caused.

Discovery without breaking anything

Asset discovery is the foundational capability and it is technically harder here than in IT for a reason that gets underestimated.

The standard IT approach is active scanning: send probes, see what responds, fingerprint the device. Applied to industrial equipment that can crash a programmable logic controller, and controllers crashing means a process stopping, which in some environments means a hazardous state.

So OT discovery historically relied on passive monitoring: tap the network, observe traffic, infer what exists from what it says. That is safe and incomplete, because a device that is not talking does not appear, and passive observation reveals less about firmware versions and configuration than a query would.

The middle ground is selective active querying using native industrial protocols in the way the equipment expects, which is safer than generic scanning and requires the vendor to have done protocol-specific engineering per device family.

That work is unglamorous, deep, and difficult to fake, which is why asset discovery scores separate vendors in this category more than the criterion name suggests. Claroty taking a maximum score there alongside its remote access mark is a coherent profile: know what exists, control who reaches it.

Convergence is organisational before it is technical

The IT and OT convergence that both Leaders position around is real, and the obstacle to it is not networking.

Plant operations and corporate IT have different reporting lines, different objectives, and a history of mutual suspicion that is usually earned on both sides. Operations has watched IT propose changes that would have stopped production. IT has found unpatched systems that operations refused to touch.

A security operations centre monitoring OT needs alerts it can interpret, which requires process context it does not have. A plant engineer receiving a security alert needs to know whether acting on it will interrupt production, which security cannot tell them.

Where this works, it works because someone with authority over both sides established a joint operating model: agreed change windows, agreed escalation, agreed authority over what can be isolated and when. That is the same authority-to-act question that decides managed detection and response engagements, and it is harder here because the wrong containment action has physical consequences.

The regulatory pressure is pushing organisations toward resolving it. European network and information security requirements extend to industrial and critical entities, with incident reporting obligations and governance expectations that assume somebody is accountable for the whole estate. That accountability requirement forces the organisational question whether or not the technology is ready.

What this leaves a buyer

The Forrester evaluation is genuinely useful and it is one input rather than an answer, which is roughly what Dragos's response argued and what any evaluation of a domain-specific market deserves.

Three questions decide more than the tier.

What would a failure actually cost. An organisation where a compromised controller means lost production is in a different position from one where it means a safety event, and the second should weight OT-native depth considerably more heavily.

Where the remote access paths are, including the undocumented ones. That inventory is worth compiling before evaluating anything, because it usually reframes the priority.

And whether the organisation can act on what the tooling finds. An OT security platform generating alerts that nobody is authorised to act on during production produces exactly the outcome this series keeps encountering, with the additional feature that the unaddressed risk is physical.

Analyst Source

Forrester Research

Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of operational technology security. The Q2 2024 Wave, authored by Brian Wrozek, scored 15 providers against 22 criteria across current offering, strategy, and market presence, roughly three years after Forrester's first evaluation of this market.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.