Claroty integrator in Switzerland
We deploy Claroty xDome on industrial networks — equipment inventory, exposure and detection, without installing anything on the controllers or disturbing production.
Why this vendor
IT security tools do not apply to an industrial network, and ignoring that is paid for immediately. An active scan can halt a controller that does not know how to answer an unexpected request. An agent does not install on equipment whose firmware is fifteen years old. An update is not applied on a Tuesday morning to a line that is running. Reflexes acquired on the office side become risks here.
Claroty built its tools for those constraints. Discovery works by passively listening to traffic: the platform learns what exists by observing exchanges, without transmitting. It understands industrial protocols — those of controllers, those of supervision systems — and can therefore tell a legitimate write command from an abnormal manoeuvre, where a generic tool would see only bytes.
The inventory is almost always the revelation of the project. Operators know their machines, rarely everything connected to the network: a maintenance console left by an integrator, a forgotten remote-management modem, a sensor added without security being told. That discovery has value of its own, before any protective measure.
Our contribution is to hold both ends. These environments require speaking to the operations teams in their own terms, where availability comes before confidentiality — the reverse of the usual hierarchy. A project run without that conversation runs into a refusal, and it will be right to.
- Passive discovery, transmitting nothing
- Inventory of what is genuinely connected
- Dialogue with the operations teams
- Segmentation between IT and industrial
- Articulation with the ICT Minimum Standard
One platform, four domains
What the platform covers
Claroty xDome is modular: the domains are enabled at the pace of maturity, always starting with the inventory.
Asset inventory
The domain the vendor calls Asset Inventory. Discovery works by passively listening to traffic: Claroty xDome learns what exists by observing exchanges, without sending a single request. Controllers, supervision systems, engineering workstations, sensors and network equipment are identified by make, model and firmware version. It is almost always the step that surprises most.
Exposure and vulnerabilities
The Exposure Management domain. Known vulnerabilities are matched against the inventory, but prioritisation obeys different rules here: a controller is not patched, it is worked around. The question is not when to apply the fix, but how to reduce the exposure until the next shutdown window — often distant, sometimes annual.
Network protection
The Network Protection domain. The platform helps define the expected zones and conduits between office IT and the industrial side, then spot communications crossing them without authorisation. This is where it meets the Purdue model and the segmentation requirements of the frameworks applicable to critical infrastructure.
Threat detection
The Threat Detection domain. Understanding industrial protocols makes it possible to qualify what is actually happening: a write command to a controller from a workstation that never issues one, a program change outside the maintenance window, the appearance of unknown equipment. A generic tool would see traffic; this one sees a manoeuvre.
In office IT, confidentiality is protected first. On a production line, availability comes before everything, and the safety of people before that. Any arrangement that risks halting production will be refused, and rightly so. That is why Claroty xDome starts by observing, and why we enable nothing intrusive without the explicit agreement of the operations teams.
How we proceed
Passive first, active afterwards and only if accepted. It is the only sequence that wins the operations teams over.
This service in practice
Frequently asked questions
Do you know what is connected?
Describe your industrial environment — passive listening answers that question without disturbing anything.