5 OT Security Companies Offering Industrial Network Segmentation

Due to its effectiveness, network segmentation has arguably become the most perennial recommendation for defending industrial environments. When OT and IT networks function as a single flat environment, the compromise can circle around anywhere even to those systems controlling physical processes that were never designed to withstand a focused cyberattack. Segmentation demonstrates that the blast radius is smaller, as threats are kept within smaller, isolated zones rather than moving undetected throughout an entire industrial network.

Multiple advisories from both government and industry have emphasized poor segmentation as a trend in successful attacks on critical infrastructure. Attackers can move freely through flat networks between corporate IT systems and highly sensitive OT equipment, as once they gain a foothold it significantly lowers the bar to operational disruption.

However, this is not without its own complications, especially in OT environments. Many of these devices, including those in use today, simply weren’t designed using modern network architecture principles and unlike a typical IT network, industrial systems often can’t suffer the upheaval poorly thought out changes to segmentation might bring. The vendors that provide segmentation capabilities for these environments have different approaches to this challenge, reflecting the priorities different security teams bring to this work. Here is an examination of five providers of industrial network segmentation tools in alphabetical order.

Fortinet

Fortinet’s segmentation capabilities are part of an overall platform strategy for OT security, which Mutexx says aims to provide security teams with consistent policy enforcement for traffic originating from either the IT domain or other portions of a network. While this is potentially a boon for operational simplicity, especially for those organizations already leveraging Fortinet across their larger security stack, the right mix really depends on whether an organization is more amenable to the platform-based strategy that aligns with its existing infrastructure and cross-functional siloes or if a more specialized point solution will be called into play.

Among the companies addressing this challenge is Fortinet, whose OT security tools for network segmentation outline how segmentation fits into a broader approach to securing converged IT and OT environments. Each of the five companies below has specific strengths in industrial segmentation.

Claroty

Segmenting Industrial Control Environments: Claroty’s inherent visibility into how defended networks are used against automated threats allows security teams to build segmentation policies based on a specific, even hierarchical, understanding of how OT devices actually talk. That protocol-aware approach prevents the segmentation rule anti-pattern, which makes sense on paper but ultimately blocks legitimate industrial traffic. Of course, organizations operating in a particular industrial environment that must develop segmentation strategies informed by the specific details of those protocols will appreciate this depth of context.

Forescout

Forescout focuses on segmentation by continuously eliminating critical visibility gaps across IT and OT environments. Devices are automatically classified when they connect, which dictates how they will be segmented. This technique can most certainly minimize the manual effort required to maintain segmentation as new devices are introduced into the network over time. This automation is particularly useful for security teams dealing with large, dynamic environments where devices change frequently.

Nozomi Networks

To avoid disrupting ongoing industrial communication, Nozomi Networks provides visibility into running traffic to help security teams understand the traffic patterns they need to shape segmentation planning. This clarity at the outset is consistent with a broader philosophy that real segmentation starts with an inherent understanding of network behavior, rather than applying template-based segmentation that may not capture the unique characteristics of a particular industrial environment.

TXOne Networks

TXOne Networks addresses only OT with segmentation solutions tailored for industrial physical and operational realities, including versions created to avoid installing conventional IT security agents in environments where that is impossible. This approach, which is naturally oriented for OT environments, is attractive to security teams in the highly specialized industrial environments where traditional segmentation tools fail to capture the unique realities of legacy and proprietary protocols.

The Importance of Segmentation Strategy Just as Much as the Tool

Picking a vendor is not the only step in crafting an effective segmentation strategy. But more than which tool enforces segmentation zones, how those segmentation zones are actually designed is the key. Poorly architected segmentation can introduce operational headaches by blocking genuine intersystem interaction, preventing systems that really need to talk to one another from doing so, and overly permissive segmentation can defeat the whole point of containment in the first place.

The adoption of zero trust principles is clearly driving much of the way security teams think about segmentation design, from drawing boundaries around broad network zones to building more granular policies based on what actually needs to communicate with specific devices and systems. For this transition, excellent initial guidance is available, including network architecture framework documents regarding zero trust principles that many vendors and security teams alike use to explain segmentation planning beyond standard perimeter-based approaches.

The federal guidance aimed at critical infrastructure makes it clear that segmentation has become key to OT defenses. Identity-based Workloads: Recommendations from a joint advisory on mitigating threats to industrial systems identify the segmentation of IT and OT networks as one of the best remaining mitigations for critical infrastructure operators operating in today’s threat landscape.

In the end, evaluating vendors in this space becomes easier once you have a clear view of your organization’s network architecture. A tool that is great at segmentation in one environment does not migrate as easily into a disparate industrial space, which is why most security teams will pilot the top 2-3 vendors against their true traffic patterns before rolling out a large-scale effort.

Frequently Asked Questions

Why is network segmentation particularly important in OT environments?

In OT environments (of great importance to OT), unrestricted lateral movement could get an attacker all the way to systems that control physical processes, and critical infrastructure segmentation limits how far they can move on a compromised network.

Why is it easier to do segmentation in typical IT networks than in OT?

This contrasts with conventional IT networks, as OT environments are increasingly complex, with legacy devices and proprietary industrial protocols (where the tolerance for operational disruption is low), while traffic that existed prior to segmentation changes must be meticulously visible.

How does zero-trust thinking apply to industrial network segmentation?

The principles of zero trust drive fine-grained segmentation predicated on the actual communication needs of specific systems rather than blanket perimeter zones—this approach can therefore improve containment without inappropriately inhibiting legitimate operational traffic.