Security Stack Logo
Asimily Platform logo

Cyber-Physical Systems (CPS) Security

Asimily Platform

Exposure management that prioritizes and mitigates risk across IoMT, IoT, and OT devices.

Asimily Platform Overview

What it does

Asimily Platform is a comprehensive IoMT security solution designed specifically for healthcare organizations to protect connected medical devices throughout their entire lifecycle. Unlike generic IoT security tools, the platform addresses healthcare-specific challenges including FDA regulatory requirements, patient safety considerations, and the operational constraints of maintaining 24/7 device availability for critical care delivery while implementing security controls.

How it works

The platform provides automated device discovery and classification through passive network scanning and active monitoring to create a complete inventory of all medical devices regardless of manufacturer, age, or network location. Asimily uses behavioral analysis and machine learning to continuously assess vulnerabilities, prioritize risks based on patient impact and organizational context, detect anomalous behavior and emerging threats, and provide actionable remediation guidance including patches, workarounds, configuration changes, and targeted segmentation strategies when patching is not feasible due to regulatory or safety constraints.

Credentials and traction

Asimily maintains SOC 2 Type II attestation and Cloud Computing Compliance Criteria Catalogue (C5) compliance. It ranked #1 among all vendors in the 2026 Best in KLAS Healthcare IoT Security report with a score of 96.6 out of 100, and holds the top rating in Gartner Peer Insights for medical device security. Customers include Methodist Le Bonheur Healthcare, MemorialCare, Tufts Medicine, and St. Lawrence Health, with adoption concentrated among healthcare delivery organizations.

Key Capabilities

mapped to solution categories
Medical Device Security

Maps identified vulnerabilities, network exposure, and control gaps to HIPAA Security Rule safeguards (164.312 technical safeguards), for compliance evidence.

Performs application-layer analysis of HL7 and DICOM communications to detect anomalous queries, data access outside normal patterns, and unauthorized device connections.

Discovers and classifies connected medical devices by device type, manufacturer, model, and firmware version, including devices that do not support standard endpoint agents.

Generates network segmentation recommendations for medical devices based on communication profile, vulnerability exposure, and clinical function, supporting VLAN design for device isolation.

Generates or ingests machine-readable SBOMs for medical devices (CycloneDX, SPDX) covering commercial, open-source and off-the-shelf components, and keeps them current per device model and software version. Serves a manufacturer documenting its own device portfolio for premarket submissions and postmarket management, and a healthcare provider tracking component vulnerabilities across the devices it operates. Required of cyber devices by FD&C Act section 524B and expected under EU MDR.

Assembles the cybersecurity documentation a premarket submission needs (security risk management report, threat model, security architecture views, SBOM, a cybersecurity management plan with vulnerability monitoring sources and patch release timelines, and labeling) in the structure the FDA premarket cybersecurity guidance and FD&C Act section 524B expect, and maps the same evidence to EU MDR cybersecurity requirements for devices sold in Europe.

Attack Surface Management (ASM)

Continuously enumerates internet-exposed assets (domains, IPs, subdomains, certificates, cloud storage, APIs) using passive DNS, certificate transparency logs, and active probing, including assets outside the official inventory.

Ranks discovered exposures by combining exploitability signals, asset business context, and active threat intelligence to produce an actionable remediation queue.

Identifies cloud resources, SaaS applications, and exposed services deployed by business units without IT or security team visibility or approval.

Identifies software stacks, versions, and components running on discovered assets through passive banner analysis and active probing, mapping CVE exposure without authenticated scanning.

Internet of Things (IoT) Security

Discovers and fingerprints purpose-built connected devices (printers, cameras, infusion pumps, smart meters, building systems), classifying make, model, OS, firmware, and function, including unmanaged devices that cannot run an endpoint agent.

Identifies, prioritizes, and helps remediate device vulnerabilities, including outdated firmware and exposed network services, across the connected-device fleet.

Assesses overall device-ecosystem risk (device trustworthiness, exposure, and operational context) as a continuous posture, distinct from per-CVE vulnerability management.

Generates and enforces least-privilege network segmentation and microsegmentation policies for devices, with pre-deployment impact assessment so new policies do not break device operations.

Monitors network traffic and individual device behavior to detect anomalies, exploits and threats targeting connected devices, baselining each device class and rating severity by device criticality and business function. Products differ in whether they cover both network-level and device-level monitoring and whether baselines self-tune over time or need manual tuning.

Monitors device configurations and manages firmware updates and configuration hardening at fleet scale, closing weak or default settings on connected devices.

Forwards device alerts and inventory into SIEM, SOAR, ITSM, CMDB and NAC tooling with device identity, owner, location and business function attached, so that security operations can triage and act on connected-device incidents without a separate device console.

Maps connected-device inventory, vulnerabilities and controls to regulatory and framework requirements such as HIPAA, PCI DSS, NIS2 and IEC 62443, producing audit-ready evidence and gap reports for device fleets.

Executes automated responses to device incidents, such as quarantine through NAC or firewall policy, ticket creation and device-owner notification, through native playbooks or SOAR integration, with impact checks so that automated actions do not take critical devices offline.

Operational Technology (OT) Security

Discovers and identifies OT assets, including nested devices behind controllers, with manufacturer, model, serial number, firmware and version detail, using passive traffic analysis first and, where the product supports them, OT-safe methods such as selective active querying, controller project-file parsing, lightweight host executables and switch or firewall telemetry. Passive-only versus multi-method discovery and the depth of identification vary widely.

Dissects OT protocol payloads at the function code level, detecting unauthorized read/write operations, unusual register ranges, and firmware upload commands in Modbus, DNP3, EtherNet/IP, PROFINET, and OPC-UA traffic.

Baselines normal device communication patterns (command frequency, connection pairs, timing) and operational state, alerts on deviations that indicate reconnaissance, manipulation or lateral movement, and rates severity by asset criticality and process impact rather than by anomaly size alone. Products differ in whether baselines self-tune over time to operational and environmental changes or require ongoing manual tuning.

Identifies and prioritizes vulnerabilities across discovered OT and ICS assets using device, firmware, and exposure context, recommending safe, operationally feasible remediation or compensating controls for environments where patching is constrained.

Models operational risk for each asset, zone and site by combining device vulnerabilities, network access paths, real-world exploitability, detected threats, operational errors and asset criticality, and ranks exposures by their potential impact on safety systems and crown-jewel operational assets rather than by raw vulnerability counts, reflecting that most OT assets cannot be patched on IT timelines. Risk inputs such as controller logic, device lifecycle stage and peer benchmarking vary by product.

Maps the routes an attacker could take from IT, remote access infrastructure or unmanaged assets into control networks and on to safety systems and crown-jewel operational assets, chaining reachable network paths, exploitable vulnerabilities and weak segmentation so that the exposures that actually open a path to critical processes rank first.

Turns observed OT traffic and Purdue zone assignments into least-privilege zone and conduit policies, simulates their effect before rollout so that legitimate control traffic is not blocked, and enforces them either through the vendor's own firewalls and switches or by pushing rules to integrated third-party firewalls, switches and NAC. Native enforcement versus integration-only enforcement is the main difference between products.

Retains OT-specific evidence for investigations, including protocol-level packet captures, controller commands, asset criticality and process context, and guides response with OT-aware playbooks whose containment actions respect safety and uptime constraints rather than defaulting to IT-style isolation.

Tracks OT security posture against IEC 62443, NIS2, NERC CIP and other sector regulations by mapping discovered assets, zones, vulnerabilities and controls to specific requirements and producing audit-ready compliance reports and gap lists. Usability of the tracking workflow varies widely.

Monitors control networks without adding latency or traffic, using passive SPAN or TAP collection and out-of-band sensors, and keeps full detection, analysis and reporting working at disconnected, air-gapped or intermittently connected sites through fully on-premises operation. Cloud-reliant products lose function at isolated sites; isolated-site-capable products do not.

Captures baselines of controller logic, firmware versions and device configurations, alerts on unauthorized changes such as logic downloads, mode changes and firmware updates, and feeds configuration drift and weak settings into risk scoring.

Connects OT security to enterprise security operations either as a single converged console for IT and OT or through integration paths into SIEM, SOAR, ITSM, CMDB, NAC and firewall tooling, forwarding alerts and asset data with OT context (asset criticality, Purdue level, process impact) preserved so that SOC analysts can act without OT specialization. Assign only when integrations preserve OT context or run bidirectionally; basic syslog forwarding is standard across the niche.

Compliance

certifications
SOC 2 Type II

Integrations

compatible tools
AxoniusAzure ADAzure SentinelCisco ISECrowdStrikeOktaPalo Alto NetworksRapid7ServiceNowSplunk

Implementation & support

Deployment model
HybridSaaS
Support channels
24/7 SupportCustomer Success Manager (CSM)DocumentationEmail SupportKnowledge Base

Info last updated on September 7, 2026

Buyers

Start a shortlist with Asimily Platform

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.