Forrester's 2024 evaluation of this market put Dragos a tier below the Leaders, and Dragos responded publicly. Its argument was that an evaluation built from an IT security perspective rewards platform breadth over the domain depth that protects physical processes, and that in operational technology the depth is what keeps a plant safe.

A participating vendor questioning an evaluation's frame is unusual, and the useful question at the time was whether the critique was right.

The Q3 2026 edition answers it. Dragos is a Leader and holds the highest strategy score of the eleven vendors scored. Forrester's own summary of the vendor ends with a recommendation written in the critique's own distinction: customers who want to approach OT security "from the operations side, and not as a subtask under IT security operations, will do well to partner with Dragos."

That is the evaluation adopting the argument as a reason to buy.

Why operational technology is not just unusual IT

The distinction is not a matter of degree.

An IT system's worst outcome is data loss. An OT system's worst outcome is physical: a pressure vessel, a turbine, a chemical process, a rail signal, a hospital ventilator. Safety instrumented systems exist specifically to prevent that, and they are the systems security tooling must not disturb.

That inverts the standard priority order. IT security weights confidentiality, integrity, and availability roughly in that sequence. OT weights safety first, then availability, then integrity, with confidentiality frequently last. A plant that stops is losing money by the minute and may be in a hazardous state.

The equipment lifespan compounds it. Industrial controllers run for twenty to thirty years. A modern plant contains devices older than the engineers maintaining them, running firmware from vendors that no longer exist, communicating over protocols designed before network security was a consideration.

Patching is frequently not an option. A controller running a continuous process does not stop for a security update, and the vendor may not have issued one. Compensating controls, segmentation, and monitoring replace remediation as the primary strategy.

And the protocols are different. Modbus, DNP3, PROFINET, EtherNet/IP and their industrial siblings carry no authentication in their original forms. A command to change a setpoint looks like a legitimate command because there is no mechanism to establish otherwise.

Inside The Forrester Wave: Operational Technology Security Solutions, Q3 2026

The evaluation scores eleven providers across current offering, strategy, and customer feedback, where the Q2 2024 edition scored fifteen. It is authored by Paddy Harrington with three contributors, and vendors supplied their materials by 4 June 2026.

The Leaders are Claroty, Dragos, Nozomi Networks, and Palo Alto Networks. The Strong Performers are Forescout, Armis, Cisco, and TXOne Networks. The Contenders are OPSWAT, Honeywell, and Tenable. Claroty is also named a Customer Favorite, the designation for the vendor whose reference customers were most positive.

The scored products are The Claroty Platform, Dragos Platform v3.2, The Nozomi Networks Platform Vantage v5b239, Palo Alto Networks OT Device Security, Forescout Vistaro Platform 26.2, Armis Centrix Cyber Exposure Management Platform 26.2, Cisco Industrial Threat Defense, TX One Networks OT Security Platform, OPSWAT MetaDefender Platform, Honeywell OT Cybersecurity Suite 2.05, and Tenable OT Security.

Set that against the 2024 edition, for the four vendors that page followed. Palo Alto Networks was a Leader and still is. Cisco was the other Leader and is now a Strong Performer, and the report's recommendation for it has narrowed to an attachment purchase: customers who already use Cisco for switches and firewalls should start with Cisco. Claroty and Dragos were both Strong Performers in 2024 and are both Leaders now, with Claroty taking the customer halo that no vendor carried in the 2024 field as this page described it.

The inclusion criteria explain why the field is eleven rather than everything on the market. A vendor needs more than 25 million dollars in OT security product revenue over the past four quarters, significant business across several industry verticals and multiple regions, technical coverage of asset identification, threat and anomaly detection and exposure management, and demonstrated safety, reliability and availability expertise across several levels of the Purdue model. Forrester points readers to The Operational Technology Security Solutions Landscape, Q1 2026 for the wider field.

One methodology detail is worth recording, because it affects how much weight the customer axis deserves. Vendors may provide up to three reference customers. For Palo Alto Networks, only one of its reference customers responded to Forrester's outreach. The same was true of TXOne Networks and of Honeywell.

The critique, and what the scorecard now says

The 2024 argument was that criteria weighted platform completeness, and that in this domain platform completeness is not the same thing as protection. The scorecard partly supported that reading then: the two Leaders were companies whose primary business is enterprise IT security, credited for end-to-end platforms and IT/OT integration, while the vendor with the strongest OT-specific detection scores sat a tier lower.

The 2026 edition has moved. Its headline finding is that operational technology security is more than asset discovery or edge network security, and Forrester's companion commentary states the position directly. Leading providers, it says, "are increasingly differentiated by how effectively they translate technical findings into operational risk decisions."

The report is equally explicit that the point is not capitulation to IT. Forrester writes that this does not mean OT security is becoming an extension of IT security and that the opposite is true, because the most effective solutions preserve OT context while enabling collaboration across enterprise security teams. Dragos is credited with integrating well with IT security operations centers while preserving that context, and Forescout's vision is described as recognizing that protecting critical OT infrastructure requires integrated operations. The convergence is expected. Losing the process context on the way through it is the failure mode being warned against.

What the 2026 field shows is that the two positions were never mutually exclusive, and that the evaluation now holds both. A large platform vendor still holds a Leader seat on the strength of enforcement it owns. Three OT-focused companies hold the other three. The critique did not have to win outright for the specialist to stop being penalized for specializing.

Cisco's movement is the clearest evidence that the weighting changed. It led the 2024 edition on the strength of networking and platform breadth and took the highest possible score in the vision criterion. In 2026 its strategy is described as aligned to the use of its own networking equipment as the base for the offering, which Forrester notes benefits customers who use that equipment and makes the solution harder to use for those who do not.

Remote access is where the risk concentrates

The most specific and actionable finding in this market remains that remote access into operations is the top risk in OT security, and the 2026 edition shows vendors competing on it directly.

The mechanism is easy to see once stated. Industrial equipment requires vendor support, and the vendor is rarely on site. So the plant has a remote access path for the controls vendor, another for the equipment manufacturer, another for the integrator, and often several established informally over the years by engineers who needed to check something from home. Those paths frequently bypass the segmentation everything else depends on. A jump host with a shared credential, a modem nobody documented, a remote desktop tool installed for a commissioning project in 2018 that still works.

Cisco's secure access management is now a standout strength, credited with extensive flexibility for local and remote user connections along with auditing and session recording. Claroty's OT-specific secure remote access applies zero trust principles with live session monitoring and full audit trails. Both are on the Leader rung.

The more useful signal for a buyer is on the other side of that criterion. Two of the 2026 Leaders do not have a native secure access management capability at all. Forrester records that Nozomi does not offer one, calling the lack a detraction for customers who want an OT-native solution, and that Dragos does not provide one either, preferring to monitor customer-selected tools for threats. That is a defensible product decision and it is also a gap a buyer can miss, because a vendor can lead the strategy axis and still leave the largest entry vector to be solved by something else.

For an organization that can only fund one OT security initiative, brokered, identity-bound, session-recorded, time-limited remote access remains the one with the best ratio of risk reduced to disruption caused.

Discovery stopped being the differentiator

Asset discovery was this market's first product and the criterion that separated vendors in 2024, when Claroty took a maximum score there. The 2026 edition retires that distinction.

Asset discovery, Forrester writes, "is no longer a key differentiator among leading OT security solution providers," because most of them now deliver solid visibility and identification. The question the report puts in its place is what happens after the assets are found: whether the solution can uncover communication paths and align them to operational processes, whether it can show attack paths and close them, and whether it can support responses that are safe to run in a plant.

The technical constraint that made discovery hard has not gone away, and it is worth restating because it is why the capability took a decade to commoditize. The standard IT approach is active scanning, which can crash a programmable logic controller, and a controller crashing means a process stopping. So OT discovery relies on passive monitoring, which is safe and incomplete, or on selective active querying using native industrial protocols the way the equipment expects. That per-device-family protocol engineering is unglamorous and difficult to fake, which is why vendors that did it well could charge for it. It is also the kind of work that eventually becomes table stakes once enough of the field has done it.

What replaced it as the differentiator is risk reasoning, and the vendors are taking different routes to it. Claroty's vulnerability and risk posture management is credited with deep context, including configuration assessments and benchmarking against similar customers. Forescout's risk modeling combines device vulnerabilities, network access paths, exploitability, detected threats and operational errors into one view. Armis tunes device baselines automatically over time and can simulate segmentation before applying it. Nozomi scores risk using factors including controller logic and where a device sits in its lifecycle, and offers an embedded agent for low-level devices. TXOne's distinction is deployment: it supports complete non-SaaS approaches for sites with the strongest data-isolation standards.

The unifying point is that the field is no longer selling a map. It is selling decisions about which of the things on the map matter.

What this leaves a buyer

Three questions still decide more than the tier.

What would a failure actually cost. An organization where a compromised controller means lost production is in a different position from one where it means a safety event, and the second should weight OT-native depth considerably more heavily.

Where the remote access paths are, including the undocumented ones. That inventory is worth compiling before evaluating anything, because it usually reframes the priority, and because the 2026 Leaders include two vendors that will not solve it for you.

And whether the organization can act on what the tooling finds. An OT security platform generating alerts that nobody is authorized to act on during production produces the outcome this series keeps encountering, with the additional feature that the unaddressed risk is physical.

The 2026 edition adds a warning of its own to that list. Buying primarily on asset inventory capability, Forrester writes, risks investing in technology that provides awareness without meaningful risk reduction. The same caution runs through its treatment of innovation: automation relieves a security team unless the automated action interferes with a process, at which point it has created a problem for the operations team, and industrial environments have little tolerance for disruption.

That leaves this market in a different place from where the 2024 page found it. The complaint then was that an IT-shaped evaluation undervalued the specialists. The 2026 edition puts three of them on the Leader rung, gives one the highest strategy score, and states that a converged security operation should preserve OT context rather than absorb it. The argument that mattered turned out to be winnable. The question that remains is the one the report now asks instead, which is what any of it does once the assets have been found.

Analyst Source

Forrester Research

Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of operational technology security. The Forrester Wave: Operational Technology Security Solutions, Q2 2024, published 11 June 2024 and authored by Brian Wrozek, scored 15 providers against 22 criteria across current offering, strategy and market presence, and named Palo Alto Networks and Cisco as Leaders. The Forrester Wave: Operational Technology Security Solutions, Q3 2026, authored by Paddy Harrington with three contributors, scores 11 providers across current offering, strategy and customer feedback. The Leaders are Claroty, Dragos, Nozomi Networks and Palo Alto Networks, and Claroty is also a Customer Favorite. Inclusion requires more than 25 million dollars in OT security product revenue in the past four quarters, multi-vertical and multi-region business, and OT expertise across several levels of the Purdue model. Vendors supplied evaluation materials by 4 June 2026. Forrester notes that only one reference customer each responded to its outreach for Palo Alto Networks, TXOne Networks and Honeywell. The Operational Technology Security Solutions Landscape, Q1 2026 covers the wider market.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.

A close neighbor in Forrester's own coverage is Mobile Threat Defense Solutions, where forrester's first ever Wave on this market treats mobile as the endpoint the enterprise does not own, and the phone is now where most identity compromise begins.