Talk to us
by DarktraceTechBag Intel Page

Darktrace OT

Your plant network runs equipment older than your firewall. You can still see what it does and when it changes — Darktrace OT learns how your plant network normally behaves, flags and contains what departs from it, and lists assets, CVEs, end-of-life kit and attack paths in one IT/OT view.

A baseline learned from your plantOn-prem Master for India dataQuote only; no public OT meter

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No OT price is published; the $30,000–$100,000 AWS tiers belong to the network product’s meter
Quote
Analysts
Gartner NDR Magic Quadrant Leader in 2025 and 2026 for the network product OT builds on; no OT ranking is claimed here
NDR Leader
Deployment
The Master is your appliance or a Darktrace-hosted cloud master; sensors always sit on your network
On-prem or hosted
India
Singapore is the closest Darktrace-run hosting for a master; storage in India needs your own appliance
On-prem only

Quick answer

Darktrace OT applies Darktrace’s behavioural model to industrial networks: it learns how devices in your plant normally communicate across the Purdue levels, flags what departs from that and can contain it. Passive and active identification build one IT/OT asset view that shows CVEs and end-of-life kit, with attack path modeling on top. It is quote-only, and keeping OT data in India means an on-premises Master appliance. Read more ↓ Show less ↑
Part 01 · Orient

The Darktrace platform family

This page covers Darktrace OT — formerly the Industrial Immune System, now filed under Darktrace Hybrid Network on Darktrace’s website. The rest:

Quick facts

30-second orientation
Product
Behavioural detection and response for OT and ICS networks, with asset and risk visibility
Maker
Darktrace Holdings Limited, Cambridge, UK; founded 2013; CEO Ed Jennings since March 2026
Owner
Taken private by Thoma Bravo in 2024 in a deal valued at about $5.3 billion
Status
Its own product specification in Darktrace’s September 2026 contract; the website files it under Darktrace Hybrid Network
Price
Quote only; the AWS Marketplace public offer tiers are metered on network bandwidth and hosts, not OT
Coverage
Plant and office devices mapped level by level on the Purdue model, found by listening and by querying
Risk
CVEs and end-of-life status per asset, OT Risk Management and attack path modeling
Sensors
Physical Probes or virtual vSensors fed by SPAN or mirrored traffic, reporting to a Master
India
No Darktrace-hosted region in India; an on-premises Master appliance keeps OT data on site
In India via
TechBag — sensor placement plan, quote in INR with GST, a pilot on one plant
Part 02 · Learn

Understand OT network security before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is behavioural OT security?

Sensors learn how your plant normally communicates, then flag and contain what departs from it, alongside an asset and risk view.

An audit spreadsheet and firewall logs vs Darktrace OT — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionAn audit spreadsheet and firewall logsDarktrace OT
Knowing what is on the plant networkA spreadsheet from the last auditAn inventory built from live traffic and active ID
Spotting old, unpatched kitFound when it failsCVEs and end-of-life status per asset
Noticing an intruderFirewall logs nobody readsDepartures from the plant’s learned baseline
Seeing the route from IT to OTA network diagram on the wallAttack path modeling across the zones
Stopping a live threatPulling a cable after a phone callTCP resets or a firewall action, where you allow them
What it is NOT—An OT firewall, an India-hosted cloud, or a list price

The cheapest test is one plant with complete mirroring: run detection only for a month and compare its asset list with your last audit.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where industrial traffic is read

Sensors

Probes and vSensors on plant switches

Physical Probes and virtual vSensors take a SPAN or mirrored feed from plant switches; Darktrace warns that analysis is severely impacted if that feed is incomplete.

02
Where the behavioural model runs

Master

On-site Master or Darktrace-hosted master

The Master holds the model and the Threat Visualizer console; it can be a physical appliance in your own data centre or a cloud master that Darktrace hosts for you.

03
What is connected, and how exposed it is

Asset and risk

Asset identification and OT Risk Management

Passive observation and active identification build the inventory; CVEs, end-of-life status and modelled attack paths then rank which assets to fix or isolate first.

04
How a live threat is contained

Response

Autonomous Response, inherited from Darktrace Network

Actions go out as TCP resets from Probes or vSensors, or through a firewall integration; a hosted cloud master cannot send resets without a probe or firewall link.

Sensors on mirrored plant traffic — a Master on site or hosted, learning normal and containing what departs from it.

Part 03 · Evaluate

Nine capabilities. Discover, detect, respond.

Darktrace OT judges plant traffic against a baseline learned from your own estate, then ranks the exposed kit around it.

Discover
IT/OT view

One map across Purdue levels

IT and OT devices sit in one view laid out by Purdue level, so a session from the office network into a control zone stands out.

Discover
Asset ID

Passive and active identification

Devices are named from the traffic they send, and active identification fills gaps for quiet ones; you decide where queries may run.

Discover
Legacy kit

CVEs and end-of-life flagged

Darktrace says the product immediately reveals CVEs and end-of-life status for identified assets, without a separate plant scan.

Detect
Behaviour

A baseline of your own plant

Adaptive AI learns what normal communication looks like in your environment instead of matching a signature list, and flags departures.

Detect
Custom models

Rules where you need them

Behavioural detection is not the only tool: custom models let your engineers encode conditions specific to one site or one process.

Detect
Attack paths

Routes an intruder could take

Attack path modeling traces routes from IT into OT zones and shows which exposed asset would open a way to a critical controller.

Respond & reduce
Containment

Responses from your appliances

Inherited from the network product, Autonomous Response sends TCP resets from Probes or vSensors, or acts through your firewall.

Respond & reduce
OT risk

Exposure ranked by zone

OT Risk Management weighs vulnerabilities, end-of-life status and attack paths together, so the next shutdown fixes the riskiest kit.

Respond & reduce
Managed cover

Darktrace analysts on OT alerts

Darktrace’s separately contracted MDR service covers network, cloud, SaaS and OT alerts from a 24/7 follow-the-sun SOC.

See it, don’t just read it

Watch Darktrace OT in action

Four 2025 walkthroughs from Darktrace’s official channel: asset discovery, threat and vulnerability management, investigation with attack paths, and ICS incident response.

Darktrace (official)·Demo, 2025 (10 min)

Using Darktrace OT for Asset Discovery and Device Management

The longest walkthrough: how the product builds the asset inventory and how devices are managed once found.

Darktrace (official)·Demo, 2025 (7 min)

Using Darktrace OT for Incident Threat and Vulnerability Management

Vulnerability and threat views side by side, the part that surfaces CVEs and end-of-life equipment.

Darktrace (official)·Demo, 2025 (5 min)

Using Darktrace OT for Incident Investigation and Attack Path Modeling

Following an incident through the investigation screens, then the attack paths that lead to it.

Darktrace (official)·Short, 2025 (under 2 min)

Using Darktrace OT for OT and ICS Incident Response

A brief look at how a response to an industrial incident is handled in the product.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Darktrace OT

Plant networks repeat the same conversations every day. Darktrace OT notices the one that is new.

Here’s what genuinely sets it apart — and exactly where it stops.

01

A baseline learned from your plant, not a signature feed

Plant networks repeat themselves: the same controllers talk to the same workstations on a schedule. Darktrace OT learns that pattern for your estate and flags what breaks it, such as a session reaching a control zone from IT. Custom models cover what the baseline would miss.

02

Assets, old kit and attack paths in the same screen

Passive and active identification build the inventory, and Darktrace says CVEs and end-of-life status appear at once. OT Risk Management and attack path modeling show which exposed device opens a route to a critical controller, turning a long list into a short repair plan.

03

One platform with the corporate network

OT inherits the architecture of Darktrace’s network product, a Gartner NDR Leader in 2025 and 2026, so an estate already running it keeps one console across office and plant. Australia’s IRAP assessment covers Darktrace Network and Darktrace OT, and Darktrace MDR can watch OT alerts.

04

Where it stops

No public OT price and no OT protocol list. Results are only as good as the traffic you mirror, and resets cannot cross a stateful boundary without a firewall integration. No hosted region is in India, no Indian OT customer is named, and the website files OT under Darktrace Hybrid Network.

The idea
A baseline learned from your own plant
The residency
On-prem Master; no India-hosted region
The price
Quote only; no public OT meter
Proof, not promises

The numbers behind the platform

8 product specs
in Darktrace’s contract document dated 15 September 2026, with Darktrace OT carrying its own
— Vendor
2 years
as a Leader in Gartner’s NDR Magic Quadrant (2025, 2026), for the network product OT builds on
— Analyst
24/7
follow-the-sun SOC cover for OT alerts when the separate Darktrace MDR service is added
— Vendor
~10000
customers across all products, by Darktrace’s own 2026 count of nearly 10,000
— Vendor
110 countries
where Darktrace says it serves customers, according to its services page
— Vendor
200+
patent applications Darktrace lists across its platform on the same services page
— Vendor

What your Darktrace OT rollout looks like

Week 1Model

Map the zones and switches

List each plant’s Purdue levels, the switches able to mirror traffic, and the zones where active identification is barred.

Weeks 2–3Pilot

Mirror traffic, place sensors

Set up SPAN or taps for every zone that matters and place Probes or vSensors; any gap in the feed weakens what follows.

Month 2Prove

Let the baseline settle

Run detection only while the model learns normal plant behaviour, then walk engineers through assets, CVEs and old kit.

Month 3Decide

Decide where response runs

Agree zone by zone whether resets or firewall actions may fire, start at the IT/OT boundary, and test the firewall link.

Month 4Commit

Hand over or add MDR

Give your SOC ownership of OT alerts or add Darktrace MDR, and review attack paths before every planned shutdown.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.1
36+ reviews*
80% would recommend
Threat detection4.4
Asset visibility4.1
Industrial protocol depth3.8
Ease of deployment3.9
Value for money3.6
5★
40%
4★
38%
3★
15%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Manufacturing
“The baseline caught an engineering laptop polling controllers it had never touched. It turned out to be a contractor’s script.”
Plant Security Lead
Manufacturing
Pharmaceuticals
“End-of-life controllers listed beside their CVEs gave maintenance a replacement list ready for the annual shutdown.”
OT Engineer
Pharmaceuticals
Utilities
“We already ran Darktrace on the corporate side, so adding OT kept one console and one triage routine for both networks.”
CISO
Utilities
Energy
“Mirroring at two older substations was patchy and the results showed it. Fix your SPAN coverage before judging the tool.”
Network Engineer
Energy
Chemicals
“Operators were wary, so response stayed off inside control zones during the pilot and ran only at the IT/OT boundary.”
Head of OT Security
Chemicals
Automotive
“Getting a price took several calls, and the quote was hard to set against the OT specialists on our shortlist.”
IT Procurement Manager
Automotive
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the OT security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag OT Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Darktrace OTThis page

Quoted; OT has its own contract specification.

Grid 02 · The architecture

Data Placement × OT Depth

The grid nobody publishes — how freely you can choose where OT data lives, India included, vs how deep the product goes on industrial protocols, threat intelligence and playbooks.

Deep but cloud-leaningDeep and deployable anywhereLight and cloud-leaningSelf-hosted generalists
Darktrace OTThis page

On-site or hosted Master; behavioural detection taken from its NDR.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Darktrace OT vs the OT security field

Against Claroty xDome, Nozomi Networks Guardian, Dragos Platform, Tenable OT Security and Kaspersky Industrial CyberSecurity — on deployment, discovery, protocols, detection, response, price, India data and services.

DimensionDarktrace OTClaroty xDomeNozomi Networks GuardianDragos PlatformTenable OT SecurityKaspersky Industrial CyberSecurity
What it isBehavioural OT NDRSaaS CPS platformOT and IoT sensorsOT-native platformOT inside Tenable OneNative OT XDR
DeploymentAppliance or cloudSaaS, or CTD on-premMany sensor formsSensors + SiteStoreCloud, on-prem, hybridInstalled on site
Asset discoveryPassive + active IDFour discovery methodsNetwork, wireless, hostPassive-first + agentPassive + safe activeTraffic + node detail
Protocol coverageNo list published450+ protocolsCount not publishedKnowledge PacksCount not publishedNamed protocol list
Threat detectionLearned baselineCPS threat indicatorsDetection + AI layerFour detection typesChange + anomaly alertsNetwork + host
Vulnerability and riskCVEs, EOL, attack pathsRisk + segmentationAI-ranked remediationNow, Next, NeverCompliance mappingNot verified
ResponseResets or firewallThrough integrationsDetect and respondCases + playbooksAlerts and forensicsHost protection
Multi-site scaleNo ceiling published40M+ assets claimed200 sites, one deviceCentralStoreHybrid for globalNot published
Pricing modelQuoted per estatePrivate offers onlyQuoteQuote + servicesQuote in USDQuote
Published entry priceNot publishedNot publishedNot publishedNot publishedNot publishedNot published
IntegrationsFirewalls, EDR, SOAR~60 partnersAsset-platform feedsFirewalls, SIEM, MCPTenable OneKaspersky stack
India dataOn-prem Master onlyCTD stays on siteVantage: no IndiaYour SiteStoreOn-prem optionInstalled on site
Services and supportMDR covers OTSecure AccessPartner monitoringOT WatchYou run itMDR sold apart
Best fitDarktrace estatesBroad CPS estatesMany-site OT and IoTThreat-intel-led OTIT and OT in one viewHost-plus-network OT
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Darktrace OT if…

  • ✓Your corporate network already runs Darktrace and you want plant traffic judged by the same behavioural model and console
  • ✓You want CVEs, end-of-life equipment and attack paths in the same view as the alerts, without a separate scanner in the plant
  • ✓You can mirror traffic from every important zone and want containment you can switch on one zone at a time

Compare alternatives if…

  • ✓A Gartner CPS Protection Platforms Leader placement matters to your board — Claroty, Nozomi and Dragos each announce one
  • ✓You want OT threat intelligence and a hunting service built around it — Dragos WorldView and OT Watch
  • ✓You need IT and OT exposure inside one vulnerability programme — Tenable One already does that for Tenable shops

Do not expect…

  • ✓A public OT price — the AWS Marketplace tiers measure network traffic, not plant assets
  • ✓A Darktrace-hosted India region; in-country storage means an on-premises Master
  • ✓An OT firewall: it contains threats with resets or through your firewall rather than enforcing policy itself

TechBag has no OT security guide yet, so Darktrace OT sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does keeping track of plant assets by hand cost you?

Drag the sliders (OT and IoT assets; engineer-hour cost). Estimates model engineering time spent on manual asset audits, checking firmware against advisories and chasing unexplained plant traffic at an assumed 1.5 hours per asset a year, with 70% of it removed by a live inventory and behavioural alerts. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual OT asset-tracking cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Darktrace OT has its own product specification in Darktrace’s September 2026 contract document but no public price. The AWS Marketplace public offer tiers ($30,000, $60,000 and $100,000 a year) are metered on network bandwidth and hosts, so they do not price a plant. Darktrace shows no rupee price. TechBag maps your zones first, then quotes in INR with GST.

Darktrace OT

Best for plants that can mirror every key zone

  • Quoted per estate; no public OT meter
  • Master on site or hosted by Darktrace
  • Asset, risk and response in one product

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Darktrace OT with MDR

Best for plants without a night shift in the SOC

  • Darktrace MDR contracted separately
  • 24/7 follow-the-sun SOC on OT alerts
  • Remediation stays with your team; quoted

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Traffic coverage

Can every important zone send a SPAN or tap feed to a sensor? Darktrace warns an incomplete feed severely weakens analysis.

2
Active identification

Which zones allow active queries and which must stay passive? Agree it in writing with the plant engineers first.

3
Master location

Will the Master be an appliance on site or a Darktrace-hosted master outside India? That decides where OT data lives.

4
Response policy

Where may Autonomous Response act, and is a firewall integration in place where resets cannot cross a stateful boundary?

5
Protocol fit

Has Darktrace confirmed support for the protocols your controllers speak? No OT protocol list is published.

6
Licensing

Is OT quoted as its own line, now the website files it under Darktrace Hybrid Network? Ask for INR with GST and the term.

7
Night cover

Who watches OT alerts at 2 a.m. — your SOC, a partner, or Darktrace MDR at extra cost?

8
References

Can Darktrace name OT customers in your sector? Its one verified Indian customer, NKGSB Bank, is a network deployment.

FAQ

Questions buyers ask

It is Darktrace’s product for operational technology and industrial control networks, formerly sold as the Industrial Immune System. It maps IT and OT assets across the Purdue model, identifies devices passively and actively, shows CVEs and end-of-life status, and detects and contains threats.

Ready to evaluate Darktrace OT?

Map your zones and mirroring points first, or let a TechBag advisor get the protocol list, Master location and price in writing before a one-plant pilot.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.