Tec Nikan
فارسی
Talk to us
All news

Nozomi Builds an OT Service-Management Layer on Its Asset Data

Compass adds workflows, approvals and compliance evidence on top of the asset inventory that already feeds Vantage — an attempt to govern OT change without forcing OT data into an IT-shaped tool.

OT securityasset managementNozomi NetworksIEC 62443NIS2

Nozomi Networks announced Nozomi Compass on 16 September, an OT-native asset and service management platform built on the same real-time asset intelligence that powers Vantage, the company's cyber-physical security platform.

The argument behind it is one most plant teams will recognise. AI and automated tooling have cut vulnerability discovery from months to minutes, while remediation still runs on spreadsheets, email and IT ticketing tools that were never designed around a maintenance window. Compass is positioned as a real-time OT system of record, with workflows that account for safety windows, process dependencies and physical consequences, governed change with traceable approvals, and consequence-based risk scoring.

The compliance angle is explicit. Continuous evidence is mapped to NERC CIP, IEC 62443, NIS2 and TSA frameworks, and the platform integrates outward to EAM, CMDB, ITAM, ITSM, SIEM and SOAR systems rather than trying to replace them. CEO Andrea Carcano described Compass as the foundation that allows teams to move quickly with confidence. Co-founder and CTO Moreno Carullo put the design principle more sharply: teams can finally govern change and prove compliance without forcing OT data into an IT-shaped box. General availability is stated for January.

Whether the category holds is a fair question. Most plants already know roughly what is on their network; what they cannot do is turn that list into approved, scheduled work that produces evidence when the auditor arrives. Attempts to solve it by extending an IT service desk into the plant have a poor record, largely because a change request that ignores a safety window is not a change request anyone can action.

If the purchase happens, NIS2 and IEC 62443 audits are likely to be what drives it rather than the security case.

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.