Darktrace is a Cambridge, UK-based firm concentrating on the mitigation of cyber disruptions globally. The company employs a unique AI technology used by thousands of businesses globally to counteract, identify, react to, and recover from cyber-attacks. With a team of over 2200 people spread over 30 global offices, Darktrace is dedicated to containing the global impacts of cyber threats.
Do You Manage Peer Insights at Darktrace?
Access Vendor Portal to update and manage your profile.
Visibility - Our Darktrace/OT appliances discover OT assets and communicate with our master appliance to provide a unified view of all IT and OT assets. ICS Threat Detection Models - AI-based models are used to learn the pattern of life of OT assets and detect deviations from the normal behaviour. Great for detecting unknown threats. Risk Modeling - The OTRM module combines IT and OT vulnerability data to map critical attack paths across the IT and OT networks. This helps us to prioritise vulnerabilities and identify our weakest points.
Live status Restore function ('Heal' feature) Strong deployment support
Like other products of this manufacturer, it starts in a passive position, learning about what is happening on the network, letting us to determine what is suspicious and what is a lawful traffic before to starts locking traffic.
Pricey - It's a great tool, but it's not cheap. Not ideal for small companies with tight cybersecurity budgets. False-Positives - There is a good deal of false positives which can lead to alert fatigue. You'll learn to filter out the noise as you go along though. Info clarity - There's no simple way to list assets by OT site. While using tags offers a way to link assets to their OT site after initial discovery, organizing asset groups and their vulnerabilities based on the originating OT sensor would be a great improvement in terms of information clarity.
More expensive than some - a more difficult business case Broken up into modules with different functionality - both a strength and a weakness
It is necessary time till the system and technicians has a valid traffic scenario, that could be longer or shorter depending on the number of devices on the network and false positive errors can cause problems in the manufacturing process when it is in active mode.