IT Brief UK - Technology news for CIOs & IT decision-makers
Network server room industrial control panels secure integration cybersecurity

Claroty & Google unite to boost OT & IT threat response

Wed, 6th Aug 2025

Claroty has revealed a new collaboration with Google Security Operations designed to provide enhanced threat detection and response for organisations managing both IT and operational technology environments.

The partnership allows organisations responsible for securing cyber-physical systems (CPS) to leverage high-fidelity, context-rich alerting and vulnerability data from Claroty's xDome and Continuous Threat Detection (CTD) platforms, integrating this information within Google's cloud-native security operations platform.

Operational challenges

Security operation centres (SOCs) are increasingly tasked with managing the convergence of IT and OT, leading to unique security obstacles.

These include reduced visibility into threats affecting physical systems, a proliferation of unfiltered alerts, mounting compliance requirements, and slower incident response times attributed to legacy architectures and proprietary protocols commonly found in OT environments.

The new integration promises to address these challenges by unifying threat detection across both IT and OT, enabling accelerated incident response, streamlining compliance, and focusing on risk-based remediation.

Key features

The integration is characterised by several capabilities. Notable among these is the ingestion of Claroty-generated alerts and vulnerability data into Google Security Operations, which allows for the correlation of Claroty insights with wider enterprise data.

This correlation is intended to enrich context for threat detection and enable SOC teams to focus on prioritised, risk-based responses.

Additionally, the combination seeks to enable earlier detection of OT, IoT, and other CPS-specific risks that may go unnoticed by traditional IT security tools, and facilitate rapid, intelligence-driven incident responses.

According to Claroty, this should significantly reduce mean time to resolution (MTTR) by empowering security teams with actionable insights tailored to operational environments.

Industry perspective

"The CPS threat landscape is quickly expanding and is a high-value target for bad actors looking to exploit potential vulnerabilities as digital transformation takes shape across enterprises," said Tim Mackie, Vice President of Worldwide Channel and Alliances at Claroty. "By combining the verticalised expertise of Claroty and our deep understanding of CPS, from deep protocol expertise to complete asset context, with Google Security Operations' ability to prioritise threats, automate response workflows, and correlate complex attack patterns across domains, we're able to increase operational uptime, simplify compliance across hybrid environments, and above all else, reduce risk."

The evolving landscape sees IT security teams increasingly responsible for a broader array of physical assets, including IoT devices, medical equipment, building management systems and elements of supply chain automation.

Given the diversity of assets and associated risks, there is growing demand for integrated approaches that provide a single operational view and simplified workflows for SOC teams.

McCall McIntyre, Head of Security Product Partnerships at Google Cloud, commented on this trend:

"IT security teams are increasingly taking on the responsibility of securing physical assets, from IoT, to medical devices, to building management systems, to supply chain automation. They need a fully integrated solution in their SOC that leverages the unrivaled knowledge of CPS delivered by Claroty and the intelligence-driven workflows of Google Security Operations that together empower SOC teams with a unified view of threats across environments, enabling earlier detection of attacks and accelerating response times."

Risk reduction

By feeding high-fidelity data from Claroty's platforms into Google Security Operations, organisations are expected to strengthen their ability to detect and mitigate risks targeting their operational assets.

The combined capability is positioned as supporting both compliance requirements and operational efficiency, particularly in environments where critical infrastructure is managed alongside enterprise IT systems.

The companies state that the joint solution is intended to enable security teams to detect threats more quickly, remediate vulnerabilities at an earlier stage, and correlate threats across disparate systems while prioritising actions that reduce risk exposure most significantly.

The integration has been designed to accommodate both cloud-based and on-premise security deployments across hybrid organisational infrastructures.

Follow us on:
Follow us on LinkedIn Follow us on X
Share on:
Share on LinkedIn Share on X