Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Technology partner

Claroty integrator in Switzerland

We deploy Claroty xDome on industrial networks — equipment inventory, exposure and detection, without installing anything on the controllers or disturbing production.

Why this vendor

IT security tools do not apply to an industrial network, and ignoring that is paid for immediately. An active scan can halt a controller that does not know how to answer an unexpected request. An agent does not install on equipment whose firmware is fifteen years old. An update is not applied on a Tuesday morning to a line that is running. Reflexes acquired on the office side become risks here.

Claroty built its tools for those constraints. Discovery works by passively listening to traffic: the platform learns what exists by observing exchanges, without transmitting. It understands industrial protocols — those of controllers, those of supervision systems — and can therefore tell a legitimate write command from an abnormal manoeuvre, where a generic tool would see only bytes.

The inventory is almost always the revelation of the project. Operators know their machines, rarely everything connected to the network: a maintenance console left by an integrator, a forgotten remote-management modem, a sensor added without security being told. That discovery has value of its own, before any protective measure.

Our contribution is to hold both ends. These environments require speaking to the operations teams in their own terms, where availability comes before confidentiality — the reverse of the usual hierarchy. A project run without that conversation runs into a refusal, and it will be right to.

Claroty
What we bring
  • Passive discovery, transmitting nothing
  • Inventory of what is genuinely connected
  • Dialogue with the operations teams
  • Segmentation between IT and industrial
  • Articulation with the ICT Minimum Standard
Vendor website
Diagram

One platform, four domains

Claroty xDome architecture: unified platform for cyber-physical systems AssetinventoryAsset InventoryExposure andvulnerabilitiesExposure ManagementNetworkprotectionNetwork ProtectionThreatdetectionThreat DetectionClaroty xDomeunified platform for CPSClaroty xDome
Everything starts with the inventory: without knowing what is connected, neither exposure nor detection means very much.

What the platform covers

Claroty xDome is modular: the domains are enabled at the pace of maturity, always starting with the inventory.

Asset inventory

The domain the vendor calls Asset Inventory. Discovery works by passively listening to traffic: Claroty xDome learns what exists by observing exchanges, without sending a single request. Controllers, supervision systems, engineering workstations, sensors and network equipment are identified by make, model and firmware version. It is almost always the step that surprises most.

Claroty xDome

Exposure and vulnerabilities

The Exposure Management domain. Known vulnerabilities are matched against the inventory, but prioritisation obeys different rules here: a controller is not patched, it is worked around. The question is not when to apply the fix, but how to reduce the exposure until the next shutdown window — often distant, sometimes annual.

Claroty xDome

Network protection

The Network Protection domain. The platform helps define the expected zones and conduits between office IT and the industrial side, then spot communications crossing them without authorisation. This is where it meets the Purdue model and the segmentation requirements of the frameworks applicable to critical infrastructure.

Claroty xDome

Threat detection

The Threat Detection domain. Understanding industrial protocols makes it possible to qualify what is actually happening: a write command to a controller from a workstation that never issues one, a program change outside the maintenance window, the appearance of unknown equipment. A generic tool would see traffic; this one sees a manoeuvre.

Claroty xDome
The constraint that governs everything

In office IT, confidentiality is protected first. On a production line, availability comes before everything, and the safety of people before that. Any arrangement that risks halting production will be refused, and rightly so. That is why Claroty xDome starts by observing, and why we enable nothing intrusive without the explicit agreement of the operations teams.

Claroty xDome
Our approach

How we proceed

Passive first, active afterwards and only if accepted. It is the only sequence that wins the operations teams over.

Claroty integration approach, from passive listening to operations ScopingImplementationDuration01Passivelistening02Assetinventory03Exposureanalysis04Zones andconduits05Detectionand alertsOperationsor handover
The inventory comes after several weeks of listening: equipment that only communicates once a month does not appear within three days.
Frequently asked questions

Frequently asked questions

Passive discovery transmits nothing on the network: it merely observes a copy of the traffic. That is precisely why it is the rule in industrial environments. Active functions exist and add information, but they are only enabled on identified equipment, in an agreed window, and with the operators' consent.

That is the normal situation, and the programme is built taking it as given. When the fix is out of reach, you reduce the exposure: segment, restrict remote access, monitor sensitive commands. The vulnerability remains, the path to reach it disappears. That is risk management, not remediation.

No. The platform exists in a hosted version as well as on-premises, and the architecture is chosen according to your constraints. Many organisations send only metadata up from an intermediate zone, without exposing the industrial network itself. That trade-off is settled during scoping, not afterwards.

Yes, on several requirements at once: asset inventory, vulnerability management, segmentation and detection. The tool supplies the material; it does not produce the documentation expected. We run both together, each feeding the other.

Do you know what is connected?

Describe your industrial environment — passive listening answers that question without disturbing anything.