Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What should plants do before buying another OT…
Cyber Security

What should plants do before buying another OT monitoring platform?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Cyber Security

They should confirm that the existing telemetry pipeline can collect from all relevant sources, normalise multi-protocol traffic, and deliver it without operational disruption. If those steps are incomplete, a new monitoring tool will still see a partial plant floor and simply cost more to operate.

Check the telemetry pipeline before adding another platform

The first question is coverage, not product count. If the plant cannot reliably collect from the full set of controllers, historians, field devices, and supporting network paths, a second platform will usually duplicate the same blind spots rather than close them.

That means validating source coverage end to end, including whether the pipeline can ingest multi-protocol traffic, handle noisy industrial data, and preserve operational stability while it does so. If those basics are weak, buying another tool increases complexity before it improves visibility.

It is also worth separating “data available in principle” from “data usable in practice.” A pipeline that drops packets, filters too aggressively, or cannot normalise protocol-specific fields will make downstream analytics look healthier than the plant really is.

Why partial visibility is the real failure mode

OT monitoring often fails because teams assume the platform is the control, when the telemetry path is actually the control point. If collection is incomplete, delayed, or disruptive, the monitoring layer cannot support reliable detection, troubleshooting, or incident reconstruction.

That is especially true in mixed environments where legacy protocols, segmented networks, and vendor-specific equipment all behave differently. A platform that only sees the easiest subnet or the most modern protocol gives an incomplete picture that can be mistaken for plant-wide coverage.

For guidance on OT architectures, segmentation, and monitoring considerations, see NIST SP 800-82 Rev 3, OT Security Guide and CISA Industrial Control Systems resources.

What plants should verify before procurement

Before buying, prove that the current telemetry path can do three things at production scale: collect from every relevant source, normalise the traffic into something operators can trust, and deliver it without creating outages or latency that affects operations. If any one of those is unproven, the purchasing decision is premature.

  • Confirm source inventory first, including controllers, remote sites, historians, jump paths, and any protocol converters.
  • Test normalisation against real traffic, not synthetic samples, so protocol diversity and edge cases are exposed.
  • Validate that collection can run continuously without breaking segmentation, overloading links, or interrupting control traffic.

That order matters because visibility problems usually come from collection design, not from lack of analytics features. A better dashboard cannot compensate for missing or distorted upstream telemetry.

Risk and Threat Considerations

Partial plant-floor visibility creates a false sense of assurance. The main risk is that teams optimise for tooling features while the actual sensor-to-platform path still misses assets, drops traffic, or fails under production conditions.

Failure mechanism: Weak source coverage, protocol translation gaps, or operationally unsafe polling leaves parts of the environment unobserved, so alerts and investigations are based on incomplete evidence.

Impact: Detection quality degrades, incident scope is underestimated, and the organisation may spend more on monitoring without materially improving security or operations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-2 — Audit EventsOT monitoring depends on collecting the right events from all relevant sources.
Recommendation — Define and collect the audit events needed for plant-wide monitoring coverage.
NIST CSF 2.0DE.CM-01 — Monitoring for Anomalies and IncidentsThe question is about whether monitoring coverage is sufficient before adding tools.
Recommendation — Validate that continuous monitoring coverage exists before expanding the tool stack.
CIS Controls v8CIS-8 — Audit Log ManagementThe issue is whether telemetry can be collected and normalised reliably enough to support monitoring.
Recommendation — Centralise and validate log and telemetry collection before buying additional monitoring products.
ISO/IEC 27001:2022A.8.16 — Monitoring activitiesThe subject directly concerns whether monitoring activities are effective and complete.
Recommendation — Verify that monitoring activities cover all material OT sources before procurement.

Practitioner Guidance

What to prioritise: Treat telemetry validation as a pre-purchase gate. The buying team should ask whether the current pipeline can prove full-source coverage, trustworthy normalisation, and non-disruptive delivery under real plant conditions before any new platform is scoped.

What to verify: Require evidence from live or representative traffic, including the hardest-to-collect sources and the noisiest protocols. If the proof only covers easy segments, the decision is not ready.

Practitioner takeaway: Buy monitoring only after you have demonstrated that the data path is operationally sound, because visibility gaps in the pipeline will survive every new tool you add.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org