Dragos and Claroty will show you the attack surface. Hardening is the work of shrinking it.
The OT security market is dominated by monitoring platforms that inventory assets and raise alerts. The infrastructure hardening from the cybersecurity group we represent starts from the same protocol depth and goes further into the control systems themselves, on grids and payment networks that cannot be rebooted.
This is live work on running infrastructure, not a pilot: 3 GW or more of generation defended, 7.5 billion financial accounts secured, substation-security technology validated by a government laboratory and deployed in the field. The teams work on systems where a false positive has a cost.
Side by side
| Attribute | Represented by UnstratInfrastructure hardening | DragosDragos Platform12United States | ClarotyxDome3United States / Israel |
|---|---|---|---|
| What you buy13 | Assessment and hardening of control systems, delivered as engineering work with substation-security technology behind it | A software platform for asset visibility, OT network monitoring with deep packet inspection, vulnerability management, threat detection, investigation and response | A modular SaaS platform covering asset discovery, vulnerability and risk management, network protection, threat detection, asset management and change management |
| Industrial protocol coverage published23 | IEC 61850, Modbus and DNP3, including air-gapped networks | Published coverage list includes IEC 61850 GOOSE, IEC 60870 (101 and 104), DNP3, Modbus RTU and TCP, OPC UA and OPC DA, plus vendor-specific protocols from ABB, OMRON, Phoenix Contact, Johnson Controls and others | Data sheet claims the broadest and deepest portfolio of XIoT protocol coverage but does not name individual protocols |
| How assets are discovered13 | Not published | Passive-first discovery with safe active collection when required, via physical sensor appliances, virtual sensors and a lightweight collector on Windows and edge hosts | Three methods used separately or combined: passive monitoring, Claroty Edge querying of hard-to-reach segments, and integration with CMDB and asset management tools |
| Air-gapped networks13 | Covered, with zero tolerance for false positives stated as a design condition | Not published in the platform brochure | Not published in the data sheet; the platform is described as SaaS-powered |
| Deployment model13 | Not published | Sensor and virtual appliances deployed across the environment, described as flexible deployments | Modular SaaS platform |
| Original vulnerability research13 | 2 CVEs credited on the US NIST register | OT cyber threat intelligence produced in-house and injected into the platform, updated continuously | Team82 research group, with findings correlated to assets alongside a CVE database |
| Published operational scale13 | 3 GW or more of generation defended, 7.5 billion financial accounts secured | Not published as a customer or capacity figure in the brochure; cites being named a Leader in the 2025 Gartner Magic Quadrant for CPS Protection Platforms | Deployed by hundreds of organisations at thousands of sites globally |
| Independent validation13 | Substation-security technology validated by a government laboratory and live-deployed | Gartner Magic Quadrant leader placement for CPS Protection Platforms, 2025 | Not published in the data sheet |
| Sectors addressed13 | Power and energy, financial infrastructure, industrial control systems, national infrastructure | Industrial infrastructure broadly, covering OT systems, IT, IoT, IIoT and cyber-physical systems | Industrial, healthcare and commercial organisations across the extended internet of things |
| Jurisdiction of the supplier13For grid and payment infrastructure, the question of which government can compel a supplier is part of the risk assessment. | Independent, non-aligned origin | Privately held, headquartered in the Washington DC area with presence in Canada, Australia, New Zealand, Europe and the Middle East | Headquartered in New York City with presence in Europe, Asia-Pacific and Latin America |
| Intelligence sharing arrangements13Anonymous or automatic telemetry sharing is a benefit in a trusted community and a question to ask in a national-infrastructure context. | Not published | Neighborhood Keeper enables anonymous threat intelligence sharing across the OT community | Automatic detection updates for new signatures, vulnerabilities and malicious IPs; MITRE ATT&CK for ICS alert mapping |
Competitor values are quoted from the vendor documents listed under Sources, as published on the date shown. Configurations vary, so treat every row as a starting point for the evaluation rather than a like-for-like test result.
What the table means
Visibility and hardening are different purchases
Dragos and Claroty both sell you knowledge of your environment: what is on the network, what is vulnerable, what looks wrong. Both do it well, and Dragos publishes a protocol list detailed enough to check against your own substations. Neither document promises to change the configuration of a relay or reduce the attack surface of a settlement network. That work still has to be done by engineers who understand the plant, and it is the work our cybersecurity group sells.
The false-positive problem is an operations problem
In an office network, a noisy alert costs an analyst an hour. In a substation or a payments switch, acting on a bad alert can trip generation or stop settlement, and not acting on a real one can do worse. That is why our brief states zero tolerance for false positives on air-gapped networks rather than treating detection breadth as the goal. Ask any OT vendor, us included, what their false-positive rate looks like on your protocols and who carries the operational risk when an alert is wrong.
Who can be compelled to talk about your grid
Both comparison platforms are US-headquartered companies, and Dragos additionally offers a community intelligence-sharing scheme. For a private manufacturer, that is a benefit. For a ministry whose grid topology and vulnerability register are state secrets, the location of the vendor's legal home and the flow of telemetry out of the country are procurement questions, not paranoia. A non-aligned supplier removes that clause from the argument.
Questions buyers ask
What is the best alternative to Dragos for a government protecting national grid infrastructure?
Dragos is a strong OT monitoring platform with genuinely deep published protocol coverage, including IEC 61850 GOOSE, IEC 60870-5-101 and 104, DNP3 and Modbus. If the concern is that a US-headquartered platform vendor sits in your grid telemetry, or that monitoring alone does not reduce exposure, our infrastructure hardening is the alternative: the same protocol families, work performed on the control systems themselves, substation-security technology validated by a government laboratory, and a non-aligned supplier. Many operators end up running both a monitoring platform and a hardening programme, and that is a defensible answer too.
How does the cybersecurity group we represent compare with Claroty xDome on cost of ownership?
Neither party publishes prices. The structural difference is that xDome is a modular SaaS subscription, so the cost recurs and scales with sites and assets, while hardening is scoped engineering work with a defined end state plus whatever ongoing monitoring you choose to run. A SaaS platform in an air-gapped or nationally sensitive environment also carries a hosting and data-residency conversation that has to be priced. Compare total programme cost over five years, not licence against day rate.
Can OT security tools work on air-gapped SCADA networks?
Partly. Passive monitoring works anywhere you can span a switch, which is why every serious vendor leads with it. What breaks in air-gapped environments is the cloud dependency: Claroty's xDome data sheet describes a SaaS platform, and Dragos describes sensor and virtual appliances without stating air-gap operation in its brochure. Our brief specifically covers air-gapped networks with zero tolerance for false positives. If you run isolated networks, make air-gap operation a written requirement and ask each vendor to describe the update path for signatures and intelligence.
Does a vulnerability-research record actually matter when choosing an OT security supplier?
It matters as evidence that the supplier can read the protocols rather than resell someone else's signatures. Claroty publishes its Team82 group, Dragos publishes its own OT threat intelligence feeding the platform, and the cybersecurity group we represent has 2 CVEs credited on the US NIST register. All three are real credentials. What separates them for a buyer is scope: a register entry proves original discovery, a threat-intelligence feed proves sustained coverage. Ask for both, and ask which of your protocols each one has actually broken.
Sources
- 1. Dragos, The Dragos Platform: A Cybersecurity Platform Built for OT Environments (brochure, September 2025) (copy held on this site)Retrieved: 2026-07-31
- 2. Dragos, Dragos Platform Protocol Coverage (datasheet, September 2025) (copy held on this site)Retrieved: 2026-07-31
- 3. Claroty, Claroty xDome (data sheet) (copy held on this site)Retrieved: 2026-07-31
