News

Forrester Wave Q3 2026: Market leaders in operational technology (OT) security

News | 11.09.2026

Modern operational technology (OT) environments are tightly interconnected with corporate IT networks, cloud platforms, and third-party service provider infrastructure. This architectural evolution fundamentally changes the risk profile: cyber incidents are no longer confined to data breaches, but directly threaten the continuity of physical and industrial operations.

A compromise in the IT segment, remote access channels, or unmanaged devices can propagate to the OT infrastructure within minutes, turning a security incident into a production shutdown. Traditional defense methods based solely on perimeter controls and passive asset discovery have exhausted their effectiveness.

The modern approach to OT security requires continuous risk management, attack path analysis, and deep contextual analytics aligned with operational safety and uptime constraints. In The Forrester Wave™: Operational Technology Security Solutions, Q3 2026 report, experts evaluated leading technology network security providers.

The Forrester Wave: Operational Technology Security Solutions, Q3 2026

Three pillars of a modern OT security strategy

Chief Information Security Officers (CISOs) and IT professionals should consider the following key priorities when building a defense system for operational segments:

  • Risk prioritization and reduction: Asset inventory and discovery are just the first step. It is crucial to evaluate risks within each zone or site, identifying vulnerabilities that could impact safety systems and operational assets ("crown jewels").
  • IT and OT convergence: An increasing number of organizations are integrating their IT/OT security monitoring and management processes into a single centralized Security Operations Center (SOC) for end-to-end threat intelligence sharing.
  • Balancing innovation and reliability: The primary goal of OT security is to protect systems that simply cannot go offline. The adoption of new security capabilities must be balanced with covering basic attack vectors.

Solutions from research leaders in the Softprom portfolio

Vendors available for ordering and implementation through the official distributor Softprom secured top positions in the Forrester Wave Q3 2026 report.

Claroty — market leader and customer favorite

Claroty was recognized as a Leader and achieved Customer Favorite status. The solution provides maximum visibility into cyber-physical systems (CPS), contextual vulnerability analysis, and secure remote access capabilities.

  • Deep inventory: Complete coverage of all types of operational assets without the risk of process disruption.
  • Vulnerability management: Automated mapping of discovered devices against vulnerability databases and risk prioritization.
  • Secure Remote Access (SRA): Native, secure remote access for vendors and engineers to the OT infrastructure.

Cisco — scale, convergence, and infrastructure protection

Solutions from Cisco hold strong positions by integrating network security and OT protection capabilities. Cisco enables visibility and segmentation without requiring a complete overhaul of existing network hardware.

  • Integration with network equipment: Built-in traffic analysis directly at the switch and router level (Cisco Cyber Vision).
  • Microsegmentation: Automated access policy enforcement and isolation of compromised segments.
  • Unified SOC: Seamless data transfer from OT to IT monitoring systems (SIEM/XDR).

OPSWAT — perimeter defense, removable media protection, and isolation

The platform from OPSWAT protects operational networks from threats introduced via physical media (USB) and isolated data transmission channels.

  • Security kiosks (MetaDefender Kiosk): Inspection and malware sanitization on removable media before connection to the OT network.
  • CDR technology (Content Disarm and Reconstruction): Neutralization of hidden threats in files without compromising their functionality.
  • Unidirectional gateways (Data Diodes): Physical isolation of critical segments while maintaining a one-way data flow.

Transformation of approaches: classical vs. modern OT security

Classical approach to OT security

  • Focus: Perimeter protection and passive device inventory
  • Incident response: Isolated actions by local engineers
  • Integration: Complete air-gapping of OT from IT infrastructure

Modern approach (Forrester Wave 2026)

  • Focus: Continuous contextual risk analysis and attack path management
  • Incident response: Automated OT-aware response aligned with process safety requirements
  • Integration: IT/OT SOC convergence and unified risk monitoring