/ Guide / Industrial

OT network security for plants, with the boundary written down.

OT network security is usually sold as a platform. In a plant it only matters as an operated boundary: what is visible, what is allowed across, what is denied, and who is accountable for each part.

Physical operations run equipment that predates modern security assumptions. Surya delivers visibility and security for that layer as part of Surya Fabric, inside a stated boundary.

Check Fit

/ The boundary

Where Surya sits in the stack.

  • Enterprise IT, identity and cloud
  • Surya Control
  • Surya Fabric
  • IT and OT segmentation boundary
  • Claroty: visibility, exposure context and secure access where supported
  • OT and cyber-physical systems
  • The physical operation

The segmentation boundary between the business environment and the operational environment is the product surface. It is designed, deployed and then operated to a released profile, with a defined recovery procedure for the supported network components on either side.

/ Visible and controlled

What the boundary actually gives you.

  • Asset visibility for operational and cyber-physical systems, delivered with Claroty
  • Network segmentation between the business environment and the operational environment
  • Monitoring of the segmentation boundary and the paths permitted across it
  • A defined recovery procedure for the supported network components on either side
  • Evidence of what is connected, what changed and what was denied

Claroty supplies the operational and cyber-physical systems platform behind that visibility. Surya designs the segmentation boundary, deploys and integrates the platform, and operates the result under Surya Control as part of Surya Fabric.

  • Asset visibility. An inventory of operational and cyber-physical assets, how they communicate and what they depend on.
  • Exposure context. Which exposures matter given how the asset is actually used in the operation, rather than an undifferentiated vulnerability list.
  • Secure remote access. Controlled, recorded vendor and engineer access to operational systems where the environment supports it.
  • Operational telemetry. Continuous signal from the operational environment that feeds Surya Control's observation and evidence.

Claroty licensing is a customer requirement where the OT capability is in scope.

/ Not touched

What Surya does not do.

Surya does not perform PLC programming, ladder logic, process engineering, controls engineering, production engineering or machinery optimization, and does not take responsibility for production equipment or its safety systems. Claroty licensing is a customer requirement where the OT capability is in scope.

  • PLC programming and ladder logic.
  • SCADA and control-system changes, process engineering and controls engineering.
  • Machinery optimization, throughput tuning and production equipment behaviour.
  • Responsibility for production equipment or its safety systems.

Those stay with your organization and its equipment vendors and engineers. Surya does not become their implementation staff, and they cannot create obligations for Surya.

/ Accountability

Two sentences that settle most arguments.

Surya is accountable for the segmentation boundary, the paths permitted across it, the supported network components, the deployment and operation of the OT security platform, and the evidence of all of it.

Surya is not accountable for the behavior, programming, tuning, throughput or safety systems of production equipment. Those remain with the customer and its equipment vendors and engineers.

Continuous monitoring is not the same as staffed round-the-clock incident response. Surya Control observes continuously, runs routine allowlisted tested operations under a standing policy, requires explicit authorization for consequential changes, and stops, preserves evidence and raises an exception when a condition is unknown or unsafe.

Check Fit.

Tell us what your plant network reaches today and where the boundary sits.

Check Fit