This website does not use cookies. Cookies Policy.

Contextual Threat Intelligence for OT Security

Safetybits introduces Contextual Threat Intelligence, so you see exactly where your network traffic goes, and act before it turns into a breach. It shows live traffic by country on your plant dashboard, tells you which device talked to whom, evaluates every packet on the spot with rules built on Zero Trust philosophy that flag any destination outside your allow-list of countries, and marks connections to IPs with poor reputation, showing you how that IP is actually used. It could be a datacenter, a CDN, or a botnet.

Other OT cybersecurity tools don’t have this. The few that do, run it as a separate threat intelligence feed you have to subscribe to and cross-reference by hand with your inventory and your alerts. Three tabs, three tools, no shared context.

At Safetybits we coined the OTSPM philosophy (Operational Technology Security Posture Management). In short: monitor the industrial environment around the clock, and correlate what happens across inventory, vulnerabilities, compliance, and threat detection, instead of treating them as separate tools.

Contextual Threat Intelligence applies that same idea to threat detection. It connects traffic geolocation, device inventory, and IP reputation on the same platform. That shared context is exactly what let us tell the legitimate CDN apart from the malicious IP, without opening a single extra tool.

Let’s see it in action.

Something on the map didn’t add up

A CISO at an industrial company (name withheld for confidentiality) suspected part of their traffic was going out to countries where they had no operations. No proof, just a hunch. We opened their plant dashboard.

The traffic map for the last 24 hours showed activity in the usual countries: the United States, Germany, France. But there was a point in Africa that shouldn’t have been there.

Network traffic map showing activity in Kenya

One country stood out. One reason to keep looking.

Who talked to Kenya?

Clicking the country opened the detail panel: two resources on the network had exchanged traffic with that IP. One was a production server with no reason to talk outside Europe.

Detail panel showing inbound and outbound traffic per resource

It wasn’t just a hunch anymore. We had a specific device to investigate.

Detecting unauthorized countries

Zero Trust starts from a simple idea: don’t trust anything by default, not even traffic you already recognize. Instead of trying to list every possible threat (a list that’s never complete), you define the only thing that’s allowed. Everything else gets blocked or investigated.

That’s the same idea behind how we design our rules. Instead of asking you to anticipate every possible attack, we ask something much simpler: which countries does it actually make sense for your plant to talk to? We set up the Traffic to Unauthorized Country Detected rule with the exact list of countries where the customer operates. Everything else, automatic alert.

Rule configuration with a list of allowed countries

The rule doesn’t just warn you. It evaluates every packet in real time, so the moment it detects traffic outside the list, it can act on its own: send the alert to the team’s notification channel, start a network capture for evidence, or tag the affected resource. The capture is saved as a .pcap file, so you can open it directly in Wireshark, no extra steps. No need to wait for tomorrow’s report to react.

That tag isn’t just for visibility, either. Safetybits shares your inventory with your firewall, so the same tag can trigger a rule that blocks the traffic right at the perimeter. Detection turns into enforcement, without anyone writing a firewall rule by hand.

Days later, the rule did its job on its own: it caught outbound traffic to Sweden, outside the list, and fired that response instantly.

The IP we didn’t like

Not all out-of-place traffic is equally serious. With High-Risk External IP Communication Detected, every external connection is checked against threat intelligence databases in real time.

One of the IPs had a 90% abuse score: a history of scanning and brute-forcing. That one was a real signal.

Just like the country rule, this one also evaluates in real time and can respond instantly: alert, a .pcap capture ready for Wireshark, or tagging the resource, no need to wait for someone to review a log.

Alert showing a high-risk IP reputation

A CDN is not automatically safe

With two alerts on the table, it was tempting to use the same shortcut twice: “it’s a CDN, so it’s fine.” The Kenya IP was exactly that: legitimate traffic from a known CDN provider, just misplaced on the allowed-country list, no malicious intent.

The IP with the 90% abuse score was also tagged as a Content Delivery Network, riding on well-known cloud infrastructure. Same label, same “trusted” category. But the abuse score told a different story: a track record of scanning and brute-forcing, active right now, against a production resource. Legitimate cloud infrastructure gets rented too, and the label on the box doesn’t change when it does.

That’s the one we escalated. An infrastructure tag tells you what neighborhood an IP lives in. Reputation tells you what it’s actually doing. You need both to tell them apart.

See further

The CISO’s hunch was right. But without the map, without knowing which device was generating the traffic, and without context on the IP, we would have chased the wrong lead.

With Contextual Threat Intelligence, you don’t have to chase hunches blind anymore.


Expand your reach with OTSPM

The narrower your view, the less risks you can detect. Discover how an OTSPM platform leverages correlation to expand your reach.

Discover more →