We use it for asset management, threat detection, and vulnerability management.
Claroty xDome Security Platform
ClarotyExternal reviews
External reviews are not included in the AWS star rating for the product.
Custom rules that help reduce noise and ensure we receive meaningful alerts and events
What is our primary use case?
How has it helped my organization?
Since industrial systems prioritize availability and we can't actively scan or query the network, Claroty helps us passively monitor the OT network.
It provides an inventory, alerts us to the latest threats through cloud-integrated threat intelligence, and offers a detailed detection mechanism.
Additionally, it identifies vulnerabilities that we can then address with the industrial teams.
What is most valuable?
Threat detection and vulnerability management are the most valuable features. There are also custom rules that help reduce noise and ensure we receive meaningful alerts and events.
The vulnerability management capabilities that helped mitigate potential threats have been very helpful. Claroty identifies all vulnerabilities available in our environment, and while the tool provides the information, a skilled team is needed to manage and address these vulnerabilities effectively. It can also be integrated with third-party vulnerability management tools for a unified view, where all the vulnerabilities can be displayed and prioritized based on asset criticality.
It is easy to integrate Claroty into our existing system.
What needs improvement?
There are a few protocols that Claroty doesn't currently support.
For how long have I used the solution?
I have been using it for five years.
What do I think about the stability of the solution?
I don't face stability issues often but there have been a few issues during upgrades that Claroty's support team has addressed.
What do I think about the scalability of the solution?
It's all right in terms of scalability. I would rate the scalability an eight out of ten.
How are customer service and support?
The customer service and support are really good and helpful, both in terms of response time and knowledge.
Which solution did I use previously and why did I switch?
I've worked with Tenable OT, Defender for IoT, and Nozomi Networks, as I've been in this field for seven to eight years.
What's my experience with pricing, setup cost, and licensing?
It's a bit expensive compared to other solutions.
What other advice do I have?
Overall, I would rate it a nine out of ten. Claroty is a good tool for anyone wanting to get started with understanding their OT network risk posture. It provides valuable insights into vulnerabilities without disrupting the network.
I would recommend it to others.
Provides good visibility of the devices in a user's environment
What is our primary use case?
Our company has designed a project with Claroty Platform being used for the cybersecurity audit. Suppose our company needs to collect information about the systems in Indian Oil, HPCL, or other oil refineries. In that case, we collect the data and gather the information to look at the vulnerabilities, see how the firmware and networks look, and look at the protocols used in a particular environment. Our company gathers the aforementioned type of information with the help of Claroty Platform.
What is most valuable?
The most valuable feature of the solution stems from its visibility section since, within a very short amount of time, the tool provides visibility for users to see the devices that are connected to the systems in an environment and to see how the communication is going on while keeping a tab over other areas like alerts and insights, which can be useful for the system.
What needs improvement?
The product fulfills our company's needs. Currently, Claroty Platform focuses on industrial control systems and OT. If Claroty Platform expands to the IT network side, it will benefit Claroty and those who want the tool for their IT network part.
Information related to zero-day attacks, which are difficult to detect in a system, is an area of concern that needs to be improved over time by the Claroty Platform. Sometimes, the weaknesses in certain systems cannot be captured by Claroty Platform because it lacks knowledge about zero-day attacks.
The product's integration capabilities are an area of concern where improvements are required.
For how long have I used the solution?
I have been using Claroty Platform for two to three years. My company is in partnership with Claroty Platform.
What do I think about the stability of the solution?
Stability-wise, I rate the solution a seven out of ten.
With the Claroty Platform in place, at times, my company is not able to connect some of the data with some other systems, which don't actively communicate with another system. Claroty Platform can't detect systems that don't actively communicate with other systems, so we have to use active queries. However, in passive detection, one can't detect systems. There needs to be some improvements in the product.
What do I think about the scalability of the solution?
When it comes to scalability, the tool performs well in some areas, while it doesn't perform well enough in certain other areas. Scalability-wise, I rate the solution an eight out of ten.
How are customer service and support?
As my company has a partnership with Claroty Platform, the seniors in my organization communicate with Claroty's support team if required.
How was the initial setup?
The data is private, and we have to keep it on our company's server, so the solution is deployed on an on-premises model.
The solution is deployed for one day in our company within three to four hours to get the data and create a report consisting of the details of the vulnerabilities and what needs to be improved in the systems. In short, my company has not implemented the product on a timely basis. It is generally implemented for a day, together with the data, to analyze the data and for another communication part.
Which other solutions did I evaluate?
Tenable has also been expanding its OT security technology, so we can't compare Claroty Platform with it to decide on which would be the best tool for our company.
What other advice do I have?
In terms of the product's ability to enhance cybersecurity in our company, I would say that I have three technical certificates of Claroty, including technical support and Claroty implementation certificates. Claroty Platform provides courses through its partner portal, from which others can learn about the tool and its implementation process.
The product helps mitigate potential threats, especially if its users have signature rules. The product also provides alerts.
My company is able to integrate the Claroty Platform with another product to get data from it. Claroty Platform's integration capabilities have some limitations since it can only be integrated with a limited number of systems. A tool like Tenable offers good integration and can be integrated with many external products, like SIEM, SOAR, or firewall products.
I recommend the product to those who plan to use it. My company also suggests our customers deploy the Claroty Platform.
Claroty Platform is a product that focuses on industrial control systems, and if people want to save their company's OT systems and cater to the needs related to the security area, then they can use the product.
I rate the overall tool an eight out of ten.