Manufacturing machines, control units, sensors, cameras, access systems, and building technologies are connected to the network just like computers and servers. However, managing them tends to be more complicated. Often, it is not possible to install a security agent on them, updates depend on the manufacturer, and taking them offline can disrupt operations.
In practice, this isn’t just about the IoT. The same problem applies to industrial equipment, operational technology (OT), building systems, and medical devices. What they have in common is a direct link to a company’s physical operations and the long lifecycle of the equipment.
1. Devices the company is unaware of
A new camera was installed during the renovation of the facility. The service company added a communication gateway to the cooling system. The production machine includes an industrial computer that was never entered into the central registry.
The device is operational, but it is not listed in the inventory. It is unclear who is responsible for it, what firmware it uses, or what devices it communicates with. In the event of a security incident, the first step is to determine its location, what it controls, and whether it can be disconnected.
NIST therefore considers the unique identification of devices to be a fundamental security capability. Without reliable records, it is difficult to implement vulnerability management, access control, and network monitoring. (nvlpubs.nist.gov)
2. Outdated systems for which no fixes are available
A laptop can be replaced after a few years. A manufacturing machine, a laboratory instrument, or a building control system can operate for ten years or more. Meanwhile, the operating system inside will lose support much sooner.
A patch may not exist. In other cases, its installation requires the manufacturer’s approval or the shutdown of a downstream process. Although NIST considers a secure update mechanism to be one of the core capabilities of IoT devices, not all older technologies offer it. (nvlpubs.nist.gov)
What about devices that can’t be updated? The risk must be mitigated in another way. Isolating the device in a separate network zone, allowing only essential communications, tightening access controls, and implementing more detailed monitoring will help. The device can then remain in operation until it is repaired or replaced as planned.
3. Default Passwords and Improper Configuration
Many problems arise as early as the installation phase. The default account remains active, an unnecessary service continues to listen on the network, or the device ends up in the same VLAN as the office computers.
Such a configuration can work for years without any apparent problems. The risk only becomes apparent when someone exploits known login credentials or an exposed interface.
A case study by the Canadian healthcare organizations PHSA and FHA describes systems located in unsegmented or unsecured VLANs. For a new children’s hospital facility, 28 recommendations were made—ranging from changing default passwords to implementing patch management. All of them were approved. (Claroty)
4. A flat network that facilitates the spread of an attack
Network infrastructure changes gradually. The production system needs data from the corporate server, the building management system communicates with the cloud, and the vendor requires remote access. Meanwhile, older rules often remain active even after they are no longer needed.
A compromised device may not remain an isolated problem. An attacker can use the camera, service gateway, or control unit to find a way into other systems.
Segmentation must be based on actual communication, not just on outdated documentation. Claroty maps the connections between devices and provides the basis for rules that can be enforced using existing firewalls, switches, or NAC solutions. (Claroty)
5. Remote service without clear boundaries
Manufacturers and service partners need access to technology for diagnostics and maintenance. A problem arises when a technician gains access to the entire operational network via a VPN, uses a shared account, or when their access remains active even after they finish their work.
Furthermore, without an audit trail, it is difficult to determine who logged in, which device they used, and what changes they made during the session.
Secure remote access should be limited to specific users, devices, times, and purposes. Claroty Secure Access is designed specifically to control third-party access to operational technologies. (Claroty)
6. Lack of Data and Delayed Detection of the Incident
On a standard computer, EDR monitors processes, files, and configuration changes. However, it is often not possible to install such an agent on a PLC, sensor, camera, or analyzer.
The device can continue to function even if it has started communicating with an unknown address or if the way it accesses the network has changed. The security team will not learn of the problem until the consequences become apparent.
NIST therefore includes an overview of a device’s cybersecurity status among its core capabilities. This information helps with incident detection, compromise investigations, and resolving operational issues. (nvlpubs.nist.gov)
Claroty monitors device communications and supplements alerts with information about the technology in question and how it relates to surrounding systems.
7. Manual record-keeping and fragmented accountability
Operational equipment often does not have a single owner. The equipment was purchased by the operations department, connected to the network by the IT department, updated with the manufacturer’s approval, and serviced by an external partner.
Information is scattered across the CMDB, spreadsheets, project documentation, and the knowledge of several employees. A change in the location or decommissioning of a device may not be reflected in all records.
Before implementing automated detection, PHSA and FHA maintained their records manually. Claroty subsequently helped identify overlooked infusion pumps and correct discrepancies involving devices listed as decommissioned or relocated. (Claroty)
A centralized inventory won’t automatically resolve accountability issues, but it will provide IT, security, and operations with a consistent view of the environment.
8. A technical issue with a direct impact on the business
A control unit failure can bring a production line to a halt. A disruption in warehouse automation will slow down shipping. A cooling problem will jeopardize data center operations. The unavailability of a medical device can affect the delivery of care.
When does a technical vulnerability become a business risk? When a device compromise affects service availability, people’s safety, production quality, or the company’s ability to meet its obligations.
Therefore, it is not enough to base decisions solely on the CVE score. Other important factors include the device’s network accessibility, the potential for exploitation, its communication links, and its importance to operations. Claroty Exposure Management integrates this data and recommends specific remediation steps. (Claroty)
Why We Added Claroty to Our Portfolio
The risks described cannot be addressed with a single scanner or a static list of devices. A company needs a dynamic inventory, knowledge of network traffic, exposure assessments, and control over remote access.
That is why we have added the Claroty platform to the System4u portfolio. It complements our expertise in device management and cybersecurity in areas where standard endpoint management is not sufficient.
The platform brings together several areas:
Overview of the Environment
Claroty identifies devices and supplements the available information about the manufacturer, model, operating system, firmware, and communication protocols. It uses multiple detection methods to adapt to different types of networks and traffic patterns. (Claroty)
Priorities Based on Actual Impact
It links detected vulnerabilities to specific devices, attack vectors, and operational context. This allows the team to see what can be fixed with an update, where a configuration change will help, and which devices need to be isolated or scheduled for replacement. (Claroty)
Segmentation and Protection of Unpatched Devices
A network map will show which connections are essential for operations and which pose an unnecessary risk. This data can be used to develop segmentation strategies and mitigation measures for devices that cannot yet be updated.
Monitoring and Controlled Access
Claroty monitors changes in communication, adds device context to alerts, and enables the management of service partner access. This information can be integrated into existing security processes and tools. (Claroty)
Claroty in Practice
PHSA and FHA: More Accurate Data Collection and Better Segmentation
The Provincial Health Services Authority and the Fraser Health Authority manage an extensive network comprising 127 clinical sites and nearly 300 integrated facilities.
Manual record-keeping led to discrepancies, and a government audit highlighted shortcomings in the monitoring of healthcare facilities and network segmentation. Claroty helped locate missing devices, correct discrepancies in the records, and identify systems placed in inappropriate VLANs. The organization used the data obtained during the audit as well as in a subsequent microsegmentation project. (Claroty)
This case shows that an inventory is not an end in itself. It only has value when it leads to a password change, an adjustment to a network policy, or the relocation of a device to a more secure zone.
Ohio State: Less Manual Work, Faster Repairs
Ohio State University Wexner Medical Center addressed a backlog of 11,000 CVEs and hundreds of hours of manual inventory and ad hoc patching.
David Brown, Cybersecurity Engineering Lead, briefly described the platform’s benefits:
“Claroty’s ability to automatically identify and classify medical devices on our network has been a valuable feature.” (Claroty)
After implementing Clarota, the organization, according to the case study:
- reduced the time spent on manual inventory by 70%,
- reduced the time required for risk management and response related to IoMT by 60%,
- increased CVE remediation by 76% over the course of the year,
- identified equipment with an estimated replacement cost of 13 million USD.
In addition, the team reduced the number of staff members dedicated to patching from three to one. Claroty estimates annual savings of approximately $250,000. (Claroty)
Where IoT Management Is Applied
In manufacturing, it helps protect PLCs, HMIs, industrial computers, and robotic workstations. In logistics, it covers conveyors, sorters, and automatic stackers. In buildings, it covers HVAC systems, cameras, access control systems, and energy management. In healthcare and laboratories, it provides the necessary overview of devices that cannot be managed in the same way as a standard computer.
The common goal is not just greater information security. The company gains better control over the devices on which its day-to-day operations depend.
Using the Claroty platform, we design and implement solutions for companies that want to gain control over the devices that affect their day-to-day operations.




































