The original post: /r/cybersecurity by /u/Stunning_One1213 on 2024-11-07 22:41:18.

I work for a Utility. We have all IT and OT devices forwarding syslog to SIEM. I discovered a few ICS cybersecurity tools like Scadafence or Dragos which are saying to deploy a tiny vendor appliance that can connect to mirror network/SPAN port traffic at sub-stations. What advantage will I have with these OT cyber tools when I am already forwarding syslog from Engineering devices like Schneider Electric to SIEM?