OT IDS

Administration

Configuration and backend controls for the OT IDS service — user access, data sources, thresholds, schedules and notifications (demo, non-persistent).

User access & RBAC

roles and access scopes
RoleAccess scopeUsers
ExecutiveOverview, trends, risk summary8
OT Security LeadFull dashboard access5
Site ManagerOwn site only82
SOC AnalystAlerts, incidents, vulnerabilities14
Service Delivery ManagerOnboarding, hypercare, SLA and reporting views9
AdminConfiguration and user management3

Data sources

backend connections feeding the dashboard
Claroty IDS
Assets, alerts, vulnerabilities, sensor health
Connected
Nozomi IDS
Assets, alerts, vulnerabilities, sensor health
Connected
CMDB / Asset inventory
Site details, owners, criticality
Connected
Vulnerability database
CVSS, CVE, EPSS
Connected
Ticketing tool
Incidents, SLA, MTTR
Degraded
Reporting tracker
Schedule & delivery
Connected
Email / workflow
Notifications & acknowledgements
Connected

Report schedule

automated report generation and delivery
Monthly site security report
1st business day
Vulnerability report
Weekly, Monday
Executive summary
Monthly, 3rd
Risk posture
Monthly, 5th

Site master data

scope of the current filter selection
Sites configured
In service scope
154
Regions
Geographic rollout areas
5
Business areas
Business areas covered
4
IDS platforms
Detection technologies in use
2
Site metadata is mastered in the CMDB and synced daily.

Thresholds & KPI formulas

service-wide rules applied to all sites
Critical alert threshold
Alerts at or above this severity page the SOC
Severity ≥ 8
Risk score bands
Composite site risk score, 0–950
Critical ≥ 620 · High ≥ 500 · Medium ≥ 380
Vulnerability SLA
Remediation targets by priority
P1 14 d · P2 30 d · P3 90 d
Priority formula
Inputs to vulnerability prioritization
CVSS + EPSS + asset criticality + exposure + business impact
Sensor offline alarm
Silence window before a sensor is flagged
> 30 min silent
Data refresh
Ingestion cadence from all sources
Every 15 minutes

Notification rules

email and workflow triggers
New CVSS 10 vulnerability
Immediate notification to site and SOC
Sensor offline > 30 min
Alarm to service delivery and site contact
SLA breach warning
Sent 3 days before a remediation deadline
Weekly digest
Summary of alerts and changes, Monday morning
Hypercare exit reminder
Prompt when the hypercare window closes
All times shown in local time of selected region · Data refresh every 15 minutes