Security Stack Logo
Claroty Platform logo

Cyber-Physical Systems (CPS) Security

Claroty Platform

Cyber-physical systems protection with 450+ protocol coverage across OT, IoT, and IoMT.

Claroty Platform Overview

What it does

Claroty Platform is a unified cyber-physical systems (CPS) protection solution from Claroty, founded in 2015 by Derek Phillips, Amir Zilberstein, and Benny Porat, and headquartered in New York City. Led by CEO Yaniv Vardi, the company has raised $740M in total funding from investors including SoftBank Vision Fund 2, Bessemer Venture Partners, Schneider Electric Ventures, Rockwell Automation, and Temasek Holdings, reaching unicorn status with a $2.5B valuation in July 2022. Claroty was named a Leader in the inaugural 2025 Gartner Magic Quadrant for CPS Protection Platforms, positioned highest for Ability to Execute and furthest for Completeness of Vision among 17 vendors evaluated, and recognized as a Strong Performer in the 2024 Forrester Wave for Operational Technology Security Solutions.

How it works

The platform delivers comprehensive protection across Extended Internet of Things (XIoT) environments including industrial OT, healthcare IoMT, enterprise IoT, and building management systems, providing five core capabilities: Asset Inventory, Exposure Management, Network Protection, Secure Access, and Threat Detection. Available as cloud-based Claroty xDome (modular SaaS) or on-premise Claroty Continuous Threat Detection (CTD), the platform leverages unmatched protocol coverage of 450+ industrial protocols and multiple AI-powered asset discovery methods including passive monitoring, patent-pending Edge collector, and third-party integrations. Backed by award-winning threat research from Team82 (the company's research arm), the platform automatically correlates assets with vulnerability intelligence, provides business-impact risk scoring, and delivers network segmentation policies enforceable through existing firewall infrastructure.

Credentials and traction

Claroty holds SOC 2 Type II certification and is certified to ISO 27001:2022 and ISO 27701:2019, and maintains HIPAA and GDPR compliance. It was named a Leader in the 2026 Gartner Magic Quadrant for CPS Protection Platforms (published March 3, 2026, the report's second year) and a Leader in The Forrester Wave: IoT Security Solutions, Q3 2025. Claroty won Best in KLAS for Healthcare IoT Security in 2025 for the fifth consecutive year. The platform is deployed by over 1,000 customers at thousands of sites globally, including 24 of the Fortune 100 and US federal agencies.

Key Capabilities

mapped to solution categories
Operational Technology (OT) Security

Discovers and identifies OT assets, including nested devices behind controllers, with manufacturer, model, serial number, firmware and version detail, using passive traffic analysis first and, where the product supports them, OT-safe methods such as selective active querying, controller project-file parsing, lightweight host executables and switch or firewall telemetry. Passive-only versus multi-method discovery and the depth of identification vary widely.

Dissects OT protocol payloads at the function code level, detecting unauthorized read/write operations, unusual register ranges, and firmware upload commands in Modbus, DNP3, EtherNet/IP, PROFINET, and OPC-UA traffic.

Baselines normal device communication patterns (command frequency, connection pairs, timing) and operational state, alerts on deviations that indicate reconnaissance, manipulation or lateral movement, and rates severity by asset criticality and process impact rather than by anomaly size alone. Products differ in whether baselines self-tune over time to operational and environmental changes or require ongoing manual tuning.

Maps actual traffic flows between IT and OT zones and between Purdue model levels, revealing unauthorized cross-zone connections and segmentation failures.

Classifies discovered assets and traffic flows into Purdue Model levels (Level 0-4), supporting IEC 62443 zone and conduit documentation and compliance assessment.

Connects OT security to enterprise security operations either as a single converged console for IT and OT or through integration paths into SIEM, SOAR, ITSM, CMDB, NAC and firewall tooling, forwarding alerts and asset data with OT context (asset criticality, Purdue level, process impact) preserved so that SOC analysts can act without OT specialization. Assign only when integrations preserve OT context or run bidirectionally; basic syslog forwarding is standard across the niche.

Identifies and prioritizes vulnerabilities across discovered OT and ICS assets using device, firmware, and exposure context, recommending safe, operationally feasible remediation or compensating controls for environments where patching is constrained.

Models operational risk for each asset, zone and site by combining device vulnerabilities, network access paths, real-world exploitability, detected threats, operational errors and asset criticality, and ranks exposures by their potential impact on safety systems and crown-jewel operational assets rather than by raw vulnerability counts, reflecting that most OT assets cannot be patched on IT timelines. Risk inputs such as controller logic, device lifecycle stage and peer benchmarking vary by product.

Maps the routes an attacker could take from IT, remote access infrastructure or unmanaged assets into control networks and on to safety systems and crown-jewel operational assets, chaining reachable network paths, exploitable vulnerabilities and weak segmentation so that the exposures that actually open a path to critical processes rank first.

Turns observed OT traffic and Purdue zone assignments into least-privilege zone and conduit policies, simulates their effect before rollout so that legitimate control traffic is not blocked, and enforces them either through the vendor's own firewalls and switches or by pushing rules to integrated third-party firewalls, switches and NAC. Native enforcement versus integration-only enforcement is the main difference between products.

Controls local and remote user access to OT assets through brokered, identity-verified sessions with live monitoring and full audit trails, either as a native platform capability or by integrating with and monitoring third-party secure remote access tools. Native access management versus monitoring of customer-selected tools is the main difference between products.

Captures baselines of controller logic, firmware versions and device configurations, alerts on unauthorized changes such as logic downloads, mode changes and firmware updates, and feeds configuration drift and weak settings into risk scoring.

Internet of Things (IoT) Security

Discovers and fingerprints purpose-built connected devices (printers, cameras, infusion pumps, smart meters, building systems), classifying make, model, OS, firmware, and function, including unmanaged devices that cannot run an endpoint agent.

Identifies, prioritizes, and helps remediate device vulnerabilities, including outdated firmware and exposed network services, across the connected-device fleet.

Assesses overall device-ecosystem risk (device trustworthiness, exposure, and operational context) as a continuous posture, distinct from per-CVE vulnerability management.

Generates and enforces least-privilege network segmentation and microsegmentation policies for devices, with pre-deployment impact assessment so new policies do not break device operations.

Monitors network traffic and individual device behavior to detect anomalies, exploits and threats targeting connected devices, baselining each device class and rating severity by device criticality and business function. Products differ in whether they cover both network-level and device-level monitoring and whether baselines self-tune over time or need manual tuning.

Forwards device alerts and inventory into SIEM, SOAR, ITSM, CMDB and NAC tooling with device identity, owner, location and business function attached, so that security operations can triage and act on connected-device incidents without a separate device console.

Maps connected-device inventory, vulnerabilities and controls to regulatory and framework requirements such as HIPAA, PCI DSS, NIS2 and IEC 62443, producing audit-ready evidence and gap reports for device fleets.

Executes automated responses to device incidents, such as quarantine through NAC or firewall policy, ticket creation and device-owner notification, through native playbooks or SOAR integration, with impact checks so that automated actions do not take critical devices offline.

Compliance

certifications
GDPRHIPAAISO 27001SOC 2 Type II

Integrations

compatible tools
Active DirectoryAuvesyAWSAxoniusBluecatCheck PointCiscoColorTokensCrowdStrikeFirewallsForescoutFortinetGoogle SecOpsIBM QRadarInfobloxMicrosoft Defender ATPMicrosoft IntuneMicrosoft SCCMMicrosoft SentinelNAC SolutionsNuvoloOktaPalo Alto NetworksRapid7 InsightIDRRockwell AutomationServiceNowSIEM PlatformsSOAR PlatformsSplunkSwimlaneTenableTRIMEDX RSQ

Implementation & support

Deployment model
Air-GappedCloudOn-PremisesSaaS
Support channels
24/7 SupportCustomer Success Manager (CSM)DocumentationKnowledge BaseTechnical Account Manager (TAM)Ticketing PortalTraining / Academy

Info last updated on September 7, 2026

Buyers

Start a shortlist with Claroty Platform

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.