Operational technology

You cannot install
an agent on a PLC.

Everything that makes IT monitoring straightforward — agents, scans, patch windows, rebooting a thing to see if it helps — is unavailable or forbidden on the plant floor.

OT network monitoring has to be passive: it observes a copy of the traffic and never touches the devices. Industrial controllers cannot host agents, frequently respond badly to active scanning, and run on maintenance cycles measured in years. That leaves the network itself as the only safe place to watch from — and it is a good one, because every command, every reading and every configuration change had to cross it. Passive capture gives you a device inventory, a communication baseline and evidence of what changed, without introducing any risk to the process.

Why OT is different

Six constraints that rule out normal tooling.

01

Active scanning is a hazard

Older controllers can and do fail on unexpected traffic. A discovery scan that is routine in IT is a change to a live process here, and it needs an approval nobody wants to sign.

Passive observation carries no such risk, which is why it is the default rather than a compromise.

02

Availability outranks everything

In IT the usual priority is confidentiality first. In OT it is availability, then integrity. That inversion changes what a sensible monitoring tool is allowed to do.

Any tool that might interrupt the process is disqualified regardless of what else it offers.

03

The traffic is unusually predictable

An industrial network talks in cycles — the same devices, the same protocols, the same intervals. That regularity makes baselining far more effective here than in a general-purpose network.

A new conversation on an OT segment is a much stronger signal than the same event on a corporate LAN.

04

Nobody has a complete inventory

Equipment accumulates over decades through integrators, projects and replacements. Passive observation builds the list from what is actually communicating rather than from documentation.

The first inventory almost always contains devices nobody currently employed knew about.

05

IT and OT meet somewhere

The boundary between the corporate network and the plant is where most incidents cross. It is also, routinely, the least instrumented link in the building.

If you monitor one place first, monitor there.

06

Detection alone is not enough

A security platform saying a device behaved unusually raises a question that only the traffic can close. Retained packets turn a flag into a finding.

The two are complementary: detection points, evidence proves.

What Net-Monitor adds on an OT network

  • Entirely passive. A copy of the traffic from a mirror port or TAP. Nothing is installed, nothing is probed, nothing is asked of the controllers.
  • Inventory built from observed communication. Every device that talks appears, including the ones missing from every drawing.
  • A baseline of who talks to whom, and when. On a cyclical network this is unusually precise, so a genuinely new relationship stands out.
  • Packet evidence retained alongside. When a security platform flags something, the traffic that explains it is already recorded.
  • Runs fully isolated. No outbound connectivity needed, which is how it works on a segmented plant network at all.
Common questions

Short answers.

What is OT network monitoring?

Monitoring of the network that carries industrial control traffic — PLCs, SCADA systems, HMIs, sensors and the links between them. Because the devices cannot host agents and often react badly to active probing, it is done passively, from a copy of the traffic, so that observation carries no risk to the process.

Is passive monitoring safe for industrial equipment?

Yes, because it does not interact with the equipment at all. The monitoring point receives a copy of traffic from a mirror port or a TAP and transmits nothing back onto the segment. From the controller's perspective, nothing has been added to the network.

Does this replace an OT security platform?

No — they answer different questions and work well together. A security platform is built to identify industrial protocols and flag risky behaviour. What it usually cannot do is hand you the traffic that proves what actually happened. Retained packets are the evidence layer underneath the alert.

Can it work on a network with no internet access?

Yes, and this is normally a requirement rather than a bonus. The platform runs entirely on-premise with no outbound connectivity, which is what makes it deployable on an isolated plant network in the first place.

Want to see what is actually talking on your OT segment?

A passive listen for a day is risk-free and usually produces a surprise. We will set it up with you.

Chat with an engineer