Your plant network runs equipment older than your firewall. You can still see what it does and when it changes — Darktrace OT learns how your plant network normally behaves, flags and contains what departs from it, and lists assets, CVEs, end-of-life kit and attack paths in one IT/OT view.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Darktrace OT — formerly the Industrial Immune System, now filed under Darktrace Hybrid Network on Darktrace’s website. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Sensors learn how your plant normally communicates, then flag and contain what departs from it, alongside an asset and risk view.
What consolidation actually replaces, dimension by dimension.
| Dimension | An audit spreadsheet and firewall logs | Darktrace OT |
|---|---|---|
| Knowing what is on the plant network | A spreadsheet from the last audit | An inventory built from live traffic and active ID |
| Spotting old, unpatched kit | Found when it fails | CVEs and end-of-life status per asset |
| Noticing an intruder | Firewall logs nobody reads | Departures from the plant’s learned baseline |
| Seeing the route from IT to OT | A network diagram on the wall | Attack path modeling across the zones |
| Stopping a live threat | Pulling a cable after a phone call | TCP resets or a firewall action, where you allow them |
| What it is NOT | — | An OT firewall, an India-hosted cloud, or a list price |
The cheapest test is one plant with complete mirroring: run detection only for a month and compare its asset list with your last audit.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Physical Probes and virtual vSensors take a SPAN or mirrored feed from plant switches; Darktrace warns that analysis is severely impacted if that feed is incomplete.
The Master holds the model and the Threat Visualizer console; it can be a physical appliance in your own data centre or a cloud master that Darktrace hosts for you.
Passive observation and active identification build the inventory; CVEs, end-of-life status and modelled attack paths then rank which assets to fix or isolate first.
Actions go out as TCP resets from Probes or vSensors, or through a firewall integration; a hosted cloud master cannot send resets without a probe or firewall link.
Sensors on mirrored plant traffic — a Master on site or hosted, learning normal and containing what departs from it.
Darktrace OT judges plant traffic against a baseline learned from your own estate, then ranks the exposed kit around it.
IT and OT devices sit in one view laid out by Purdue level, so a session from the office network into a control zone stands out.
Devices are named from the traffic they send, and active identification fills gaps for quiet ones; you decide where queries may run.
Darktrace says the product immediately reveals CVEs and end-of-life status for identified assets, without a separate plant scan.
Adaptive AI learns what normal communication looks like in your environment instead of matching a signature list, and flags departures.
Behavioural detection is not the only tool: custom models let your engineers encode conditions specific to one site or one process.
Attack path modeling traces routes from IT into OT zones and shows which exposed asset would open a way to a critical controller.
Inherited from the network product, Autonomous Response sends TCP resets from Probes or vSensors, or acts through your firewall.
OT Risk Management weighs vulnerabilities, end-of-life status and attack paths together, so the next shutdown fixes the riskiest kit.
Darktrace’s separately contracted MDR service covers network, cloud, SaaS and OT alerts from a 24/7 follow-the-sun SOC.
Four 2025 walkthroughs from Darktrace’s official channel: asset discovery, threat and vulnerability management, investigation with attack paths, and ICS incident response.
The longest walkthrough: how the product builds the asset inventory and how devices are managed once found.
Vulnerability and threat views side by side, the part that surfaces CVEs and end-of-life equipment.
Following an incident through the investigation screens, then the attack paths that lead to it.
A brief look at how a response to an industrial incident is handled in the product.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Plant networks repeat themselves: the same controllers talk to the same workstations on a schedule. Darktrace OT learns that pattern for your estate and flags what breaks it, such as a session reaching a control zone from IT. Custom models cover what the baseline would miss.
Passive and active identification build the inventory, and Darktrace says CVEs and end-of-life status appear at once. OT Risk Management and attack path modeling show which exposed device opens a route to a critical controller, turning a long list into a short repair plan.
OT inherits the architecture of Darktrace’s network product, a Gartner NDR Leader in 2025 and 2026, so an estate already running it keeps one console across office and plant. Australia’s IRAP assessment covers Darktrace Network and Darktrace OT, and Darktrace MDR can watch OT alerts.
No public OT price and no OT protocol list. Results are only as good as the traffic you mirror, and resets cannot cross a stateful boundary without a firewall integration. No hosted region is in India, no Indian OT customer is named, and the website files OT under Darktrace Hybrid Network.
List each plant’s Purdue levels, the switches able to mirror traffic, and the zones where active identification is barred.
Set up SPAN or taps for every zone that matters and place Probes or vSensors; any gap in the feed weakens what follows.
Run detection only while the model learns normal plant behaviour, then walk engineers through assets, CVEs and old kit.
Agree zone by zone whether resets or firewall actions may fire, start at the IT/OT boundary, and test the firewall link.
Give your SOC ownership of OT alerts or add Darktrace MDR, and review attack paths before every planned shutdown.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“The baseline caught an engineering laptop polling controllers it had never touched. It turned out to be a contractor’s script.”
“End-of-life controllers listed beside their CVEs gave maintenance a replacement list ready for the annual shutdown.”
“We already ran Darktrace on the corporate side, so adding OT kept one console and one triage routine for both networks.”
“Mirroring at two older substations was patchy and the results showed it. Fix your SPAN coverage before judging the tool.”
“Operators were wary, so response stayed off inside control zones during the pilot and ran only at the IT/OT boundary.”
“Getting a price took several calls, and the quote was hard to set against the OT specialists on our shortlist.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the OT security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted; OT has its own contract specification.
The grid nobody publishes — how freely you can choose where OT data lives, India included, vs how deep the product goes on industrial protocols, threat intelligence and playbooks.
On-site or hosted Master; behavioural detection taken from its NDR.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Claroty xDome, Nozomi Networks Guardian, Dragos Platform, Tenable OT Security and Kaspersky Industrial CyberSecurity — on deployment, discovery, protocols, detection, response, price, India data and services.
| Dimension | Darktrace OT | Claroty xDome | Nozomi Networks Guardian | Dragos Platform | Tenable OT Security | Kaspersky Industrial CyberSecurity |
|---|---|---|---|---|---|---|
| What it is | Behavioural OT NDR | SaaS CPS platform | OT and IoT sensors | OT-native platform | OT inside Tenable One | Native OT XDR |
| Deployment | Appliance or cloud | SaaS, or CTD on-prem | Many sensor forms | Sensors + SiteStore | Cloud, on-prem, hybrid | Installed on site |
| Asset discovery | Passive + active ID | Four discovery methods | Network, wireless, host | Passive-first + agent | Passive + safe active | Traffic + node detail |
| Protocol coverage | No list published | 450+ protocols | Count not published | Knowledge Packs | Count not published | Named protocol list |
| Threat detection | Learned baseline | CPS threat indicators | Detection + AI layer | Four detection types | Change + anomaly alerts | Network + host |
| Vulnerability and risk | CVEs, EOL, attack paths | Risk + segmentation | AI-ranked remediation | Now, Next, Never | Compliance mapping | Not verified |
| Response | Resets or firewall | Through integrations | Detect and respond | Cases + playbooks | Alerts and forensics | Host protection |
| Multi-site scale | No ceiling published | 40M+ assets claimed | 200 sites, one device | CentralStore | Hybrid for global | Not published |
| Pricing model | Quoted per estate | Private offers only | Quote | Quote + services | Quote in USD | Quote |
| Published entry price | Not published | Not published | Not published | Not published | Not published | Not published |
| Integrations | Firewalls, EDR, SOAR | ~60 partners | Asset-platform feeds | Firewalls, SIEM, MCP | Tenable One | Kaspersky stack |
| India data | On-prem Master only | CTD stays on site | Vantage: no India | Your SiteStore | On-prem option | Installed on site |
| Services and support | MDR covers OT | Secure Access | Partner monitoring | OT Watch | You run it | MDR sold apart |
| Best fit | Darktrace estates | Broad CPS estates | Many-site OT and IoT | Threat-intel-led OT | IT and OT in one view | Host-plus-network OT |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no OT security guide yet, so Darktrace OT sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (OT and IoT assets; engineer-hour cost). Estimates model engineering time spent on manual asset audits, checking firmware against advisories and chasing unexplained plant traffic at an assumed 1.5 hours per asset a year, with 70% of it removed by a live inventory and behavioural alerts. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Darktrace OT has its own product specification in Darktrace’s September 2026 contract document but no public price. The AWS Marketplace public offer tiers ($30,000, $60,000 and $100,000 a year) are metered on network bandwidth and hosts, so they do not price a plant. Darktrace shows no rupee price. TechBag maps your zones first, then quotes in INR with GST.
Best for plants that can mirror every key zone
Best for a broader rollout
Best for plants without a night shift in the SOC
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Can every important zone send a SPAN or tap feed to a sensor? Darktrace warns an incomplete feed severely weakens analysis.
Which zones allow active queries and which must stay passive? Agree it in writing with the plant engineers first.
Will the Master be an appliance on site or a Darktrace-hosted master outside India? That decides where OT data lives.
Where may Autonomous Response act, and is a firewall integration in place where resets cannot cross a stateful boundary?
Has Darktrace confirmed support for the protocols your controllers speak? No OT protocol list is published.
Is OT quoted as its own line, now the website files it under Darktrace Hybrid Network? Ask for INR with GST and the term.
Who watches OT alerts at 2 a.m. — your SOC, a partner, or Darktrace MDR at extra cost?
Can Darktrace name OT customers in your sector? Its one verified Indian customer, NKGSB Bank, is a network deployment.
Map your zones and mirroring points first, or let a TechBag advisor get the protocol list, Master location and price in writing before a one-plant pilot.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.