AI

Nozomi Compass Targets OT Security as AI Speeds Vulnerability Discovery

Zaara Abbas

By: Zaara Abbas

6 min read

Nozomi Networks has unveiled Nozomi Compass, an asset and service management platform built specifically for operational technology. It is designed to help utilities, manufacturers, and pipeline operators plan, approve, and document fixes to industrial equipment as AI floods security teams with newly discovered vulnerabilities.

Nozomi Networks, the San Francisco company whose software watches over the networks that run power plants, pipelines, factories, and water systems, built its business on highlighting to industrial operators what is connected to those networks and when something on them looks wrong. On Thursday it moved into what comes after that warning, announcing Nozomi Compass, a platform for planning, approving, and documenting the fixes and changes those findings demand. The company, which Mitsubishi Electric acquired for about $1 billion earlier this year, says Compass will be available to customers in January.

What is notable is that AI has made it virtually impossible to ignore certain problems. A flaw in the firmware of an industrial controller can now surface in minutes, flagged by a model that works round the clock. For instance, at a refinery, a hospital campus, or a municipal water plant, a fix may have to wait for a scheduled outage, a vendor sign-off, a safety review, and an engineer with the right credentials standing in front of the right cabinet. Compass treats that work, known as operational technology (OT) asset and service management, as its own discipline rather than an extension of IT help desk software.

Why AI is Widening the OT Remediation Backlog

In June, Microsoft shipped fixes for a record 206 vulnerabilities in a single Patch Tuesday release, a surge Dark Reading tied to AI-assisted discovery. A study by the security company Tuskira of an AI-driven open-source research program run by Anthropic found verified vulnerabilities arriving at roughly 25 a day, while credited repairs landed at about one and a half, a ratio near 16.5 to one.

Industrial environments feel that imbalance more sharply than most. As one consultant put it in CSO Online, “Discovery now runs at machine speed. Remediation in OT still runs at plant speed.” Controllers that run turbines, compressors, and chemical dosing pumps cannot simply be rebooted on a weeknight. Many stay in service for a decade or longer, and a poorly timed change can halt production or create a genuine safety hazard.

Yet the tools used to govern those changes are often improvised as asset lists live in spreadsheets that drift out of date. Change requests pass through IT ticketing systems designed around laptops and servers, not safety instrumented systems. Compliance evidence is also frequently assembled by hand in the weeks before an audit.

“Nozomi Compass underpins our vision to provide a single source of truth for visibility, threat detection, governed workflows, compliance evidence, and trusted AI-enabled operational decision-making,” said Andrea Carcano, CEO and Co-Founder of Nozomi Networks. “Until now, operators have been working with an ineffective IT-native toolset to service their OT assets. As industrial organizations incorporate AI automation to keep pace with today’s threat and regulatory landscape, they cannot live in the unknown. Compass is the foundation that allows teams to move quickly with confidence.”

How Nozomi Compass Works

Compass is built on the same real-time asset data that feeds Vantage, Nozomi’s cyber-physical security platform, which monitors industrial networks to catalog devices and detect threats. Instead of importing records into a separate database, Compass uses that live inventory as the system of record. Each asset carries its position in the Purdue model, the layered reference architecture engineers use to separate field devices from enterprise networks, along with its safety criticality and full lifecycle history.

Teams can plan a change, route it for approval, execute it within a safety window, and keep a traceable record of who authorized what. Risk scoring is weighted by physical consequence, so a vulnerable controller on a chlorine feed line ranks differently from one on a warehouse conveyor. Where a patch is not possible, compensating controls such as network segmentation can be documented as the accepted mitigation.

Compass generates audit evidence continuously and maps it to NERC CIP, the mandatory reliability standards for North American grid operators; IEC 62443, the international framework for industrial automation security; the European Union’s NIS2 directive; and Transportation Security Administration directives covering US pipelines and rail.

“OT and IT service management have always spoken different languages,” said Moreno Carullo, Co-founder and CTO at Nozomi Networks. “Nozomi Compass is purpose-built around how industrial operations work, including safety windows, process dependencies, and physical consequences, so teams can finally govern change and prove compliance without forcing OT data into an IT-shaped box.”

How Compass Compares with IT Service Management Platforms

ServiceNow, the dominant IT service management vendor, has spent $7.7 billion on Nozomi rival Armis, a deal widely read as an effort to pull OT and IoT asset visibility into an IT workflow platform. Accenture has also moved into the category through its reported $4.1 billion acquisition of Dragos.

Nozomi is taking the opposite route. Rather than retrofitting an IT platform, it is building service management outward from the OT data it already collects, then passing that governed data into the enterprise asset management systems, configuration management databases, ITSM platforms, and SIEM and SOAR tools that large companies already run.

For chief information security officers and plant leaders, this reflects two competing philosophies: one holds that a single enterprise platform should govern every asset; the other argues that industrial equipment carries physical consequences that general-purpose tools model poorly. Many large operators will likely end up running both, which means the integration layer may prove as consequential as Compass itself.

Why Does Clean OT Data Matter for AI Agents?

Nozomi also positions Compass as groundwork for agentic AI that could eventually propose or carry out remediation in industrial environments, with a human kept in the approval chain. An autonomous agent working from a stale asset list could push a change to the wrong device, and in OT the cost is measured in lost production or damaged equipment rather than a failed login. Accurate, current, and contextual data is a precondition for trusting any of that automation.

US Federal agencies warned in 2024 that the state-linked group Volt Typhoon had embedded itself in American energy, water, and transportation networks. Water utilities, many with small technical staffs, remain among the most exposed. Regulators increasingly want proof that a known risk was assessed and handled.

Nozomi Compass Arrives in January with Key Details Still Open

Compass is scheduled to reach Nozomi customers in January, and its real value will depend on details the announcement leaves open. Pricing has not been disclosed, nor has the depth of integration with incumbent maintenance platforms such as IBM Maximo. Adoption by plant engineers, not only security teams, will matter just as much. OT staff have long resisted tools that feel imposed by corporate IT, and any new workflow system has to earn credibility on the plant floor. As AI keeps accelerating the discovery of flaws, advantage in industrial security is shifting from spotting problems to proving they were resolved safely. For Nozomi, Compass is the step from warning customers about risk to helping them document that the risk was dealt with, and early deployments next year will test how far operators trust one vendor with both jobs.

Related Articles

The Middle East’s Next Battle May Be Fought in Code

Siemens and IFS Want to End the Gap Between How Factories Are Designed and How They Actually Run

Building Modern Security as Infrastructure, Governance and Design Come Together

Share this article

Related Articles