Resources · FAQ
Questions OT and security teams ask us.
Straight answers about the platform, how it works on a plant network, and how it is deployed and licensed.
About Synaptic OT
What is Synaptic OT?
Synaptic OT is a passive, air-gap native security operations platform for industrial control systems (OT/ICS). One product detects attacks across eight industrial protocols, records network traffic for forensics, tracks engineering changes against approved project files, guides a human-approved response and produces compliance evidence, entirely on-premises.
Who is Synaptic OT for?
It is built for operators of critical infrastructure and industrial plants that cannot send operational data to a cloud: oil and gas, power generation and grid, water and wastewater, manufacturing, airports and buildings, and energy utilities. Managed security service providers (MSSPs) can also run it for many clients from one console.
What makes Synaptic OT different from other OT security vendors?
It combines intrusion detection, packet-level forensics, project-file drift detection, human-approved response and compliance evidence in one licence, and it is designed to run fully air-gapped. Detection is deterministic rather than AI-driven, it never sends a packet to a controller, and every response action requires a person to approve it.
Is Synaptic OT a cloud service?
No. Synaptic OT runs on your own hardware or virtual machines on-premises. The default deployment (Tier 1) has no internet connection at all, and installation, updates, threat intelligence and licensing all work offline.
Can Synaptic OT work alongside Nozomi Networks or Claroty?
Yes. Synaptic OT ingests alerts from existing Nozomi Networks and Claroty sensors and adds packet recording, investigation, response and compliance around them. A Dragos connector is in development.
How it works
Does Synaptic OT send any traffic to PLCs or controllers?
No. Synaptic OT is strictly passive: it reads mirrored traffic from a SPAN port, network TAP or uploaded PCAP files, and an automated check in the build blocks any software component that could open a connection to an industrial device.
Which industrial protocols does Synaptic OT decode?
Eight: Modbus TCP, DNP3, OPC UA (wire traffic and audit log), IEC 60870-5-104, Siemens S7comm, MQTT, BACnet/IP and EtherNet/IP. Each is decoded down to function codes, objects and register values.
How does Synaptic OT detect attacks?
With three independent, deterministic layers: protocol anomaly detection against learned per-asset baselines, correlation against 27 documented real-world OT incidents from the Idaho National Laboratory CyOTE corpus (6,076 observables mapped to 71 MITRE ATT&CK for ICS techniques), and protocol-compliance rules that flag specification violations.
Does Synaptic OT use AI to detect threats?
No. Detection is rule-based and repeatable. An AI assistant that runs inside your deployment writes plain-language summaries and explanations afterwards, but it cannot create, suppress or re-prioritise alerts.
Which PLC and engineering project files can Synaptic OT read?
Ten formats: Rockwell L5X and ACD, Schneider XEF and ZEF, PLCopen XML (from Siemens TIA Portal, CODESYS, Omron and EcoStruxure), IEC 61850 SCD, PROFINET GSDML, EtherNet/IP EDS, AutomationML and CSV tag databases.
What is the Synaptic OT Wire DVR?
It is continuous packet recording for OT networks. The traffic around every incident is locked and indexed, can be replayed on a timeline, searched with retro-hunt for newly discovered indicators, and sealed into evidence packs signed with Ed25519 that anyone can verify offline.
Can Synaptic OT block attacks automatically?
No, by design. It prepares playbooks, remediation cards and ready-to-apply firewall rules for Fortinet FortiOS, Cisco ASA, Palo Alto PAN-OS or CSV, but a person must approve every action and your team applies firewall changes.
Capabilities
Does Synaptic OT need agents on PLCs or HMIs?
No. It works entirely from mirrored network traffic (SPAN or TAP) and from project files you upload. Nothing is installed on controllers.
Does it ever send traffic to OT devices?
No. The product contains no active PLC drivers, and an automated check in the build blocks any dependency that would open a connection to a device.
Is AI used to decide what is an attack?
No. All three detection layers are deterministic. AI is used only afterwards to write a plain-language summary, and it cannot change an alert or its severity.
Do we have to scan the network to build the inventory?
No. The register is built from passive traffic, your engineering project files and existing inventory exports. Nothing is scanned.
How do you count licensed assets?
Real devices only: PLCs, RTUs, workstations, servers, switches and controllers. Integrations such as your SIEM or ticketing system never count.
Do project files leave our site?
No. Project files are treated as more sensitive than live traffic and are always analysed locally, even in deployments where some outbound traffic is allowed.
Do you connect to TIA Portal or Studio 5000?
No. Synaptic OT reads the open export formats your engineers already produce. It never connects to engineering software or controllers.
Does the AI need internet access?
No. The assistant runs inside your deployment, including fully air-gapped sites. If it is unavailable, analysts get template explanations and detection carries on unaffected.
Can the AI suppress an alert?
No. It only annotates. Severity and detection come from deterministic rules.
How long is traffic kept?
You set the recording policy per sensor. Incident clips are locked for as long as the incident record is retained. Connected deployments can move older recordings to your own S3-compatible storage.
Is a recording admissible as evidence?
Synaptic OT gives you tamper-evident, signed packs with documented integrity checks. Whether they are admissible is a question for your legal counsel and jurisdiction.
Does retro-hunt need the Wire DVR?
Yes. Retro-hunt searches the traffic the DVR has recorded and indexed, so how far back you can hunt depends on your recording policy.
Can Synaptic OT push rules to our firewalls?
No, by design. It produces the rule text for your team to review and apply. This keeps change control in your hands.
Which ticketing tools are supported?
ServiceNow today, plus email and Slack notifications. Generic webhooks reach other tools.
Do we need IEC 62443 certification to use this?
No. The verifier is useful for any zone design. If you are working towards IEC 62443-3-2 or 3-3, the evidence maps directly to those controls.
Does using Synaptic OT make us compliant?
No product can make you compliant on its own. Synaptic OT produces the monitoring, records and evidence these frameworks ask for, and maps them to controls so your assessor can review them quickly.
Which regulations do you support in the Gulf and India?
NESA (UAE IA) is mapped today. IEC 62443 mappings are commonly used alongside national frameworks such as NCA OTCC and CERT-In requirements; tell us which you report against.
Deployment and licensing
How is Synaptic OT licensed?
One licence covers the full suite. It is priced per site and per monitored asset, with no per-seat fees, no usage metering, and integrations never count toward the asset limit. Pricing is available on request.
What deployment options does Synaptic OT offer?
Four tiers with the same product: Tier 1 full air gap, Tier 2 semi air gap with allow-listed outbound only, Tier 3 hybrid multi-site with a read-only HQ view, and Tier 4 for MSSPs with a consent-gated multi-tenant console.
Which compliance frameworks does Synaptic OT map to?
Seven: NESA (UAE Information Assurance), IEC 62443-3-2, IEC 62443-3-3, IEC 61511, NERC CIP, NIST SP 800-82r3 and NIS2. It also applies retention aligned with NERC CIP-007-6, NIST 800-92, ISO 27001 and AWIA 2018.
How do I evaluate Synaptic OT?
Request an evaluation licence at synapticot.com/evaluate. An engineer agrees success criteria with you, issues a signed time-limited licence that works offline, and you run the full product on mirrored traffic or PCAPs from your plant.
Didn't find your answer?
Ask an engineer, or request an evaluation licence and see it on your own traffic.