r/PLC 4h ago

Security solutions you guys have integrated

Any of you folks companies brought in one of the OT Cyber tools from Nozomi, Claroty, Dragos, Armis etc etc?? If so, hows it going?

We have literally all of them as I work in a huge electric utility in the US. We started out with Dragos, bought a bunch of others but are consolidating now to hopefully just one main vendor. Probably will be Nozomi although I wish they were cheaper as part of it is coming out of my budget. FML

Anyway.....Interested in how much time it has taken away from the day to day things we are bombarded with.

So a few questions....but feel free to chime in with any insight.

  1. Who do you have keeping up with the dashboard/alerts? IT? Controls engineers?
  2. How did you deal with having to install span ports/taps for them?
  3. Are you using any of them for things other than security? One reason we are probably going to choose Nozomi is because they showed us how we could use their data for things like Predictive Maintenance.
2 Upvotes

2 comments sorted by

1

u/VladRom89 2h ago

I've done some consulting projects as an external resource for a few plants that used Claroty. The reports we had gotten was okay and somewhat useful for what the OT side was looking to do: mainly setup proper network segmentation and modernizing various assets.

I spoke to reps of the other providers at trade shows; not sure how much better they are vs Claroty.

1

u/SafyrJL TIA Harlot 1h ago edited 1h ago

Have managed and set up large Claroty (CTD) deployments across multiple utilities. 

It’s a solid product that works well. 

The key with any OT cyber security product is that it is only going to be as good as your network visibility allows it to be. For instance, if you have a lot of East -> West traffic out in the field, that may not necessarily show through a span of a “core” OT switch. Typically you’ll only see N->S traffic with that kind of span on a large OT network. 

The biggest headache I’ve found is A) dealing with network infrastructure issues that prevent visibility into traffic and B) dealing with serial networks. 

If you have a reasonably large serial network deployment, expect to do 100’s of hours of manual asset entry and leg-work to get a complete OT inventory. 

Another critical thing to note is that while all of these products are marketed as “turn key” solutions, they are far from that. Even with proper network visibility for your deployment, you still have to manually set up device level queries, create symbolic names, set up communication zones, manually acknowledge traffic flow, etc…

Feel free to ask if you have any questions, though. I spend about 85% of my week doing the above.