Back to blogs

Blog | JUL 22, 2026

83 Tools and Still Exposed: Why Fewer Tools Mean Stronger Guarantees

Data NotarizationIndustrial IoT

83 security tools, and the two attacks that matter most, falsified data flowing up, unauthorised commands flowing down, still get through. Boundary controls and monitoring can't answer the one question that matters: is this data authentic, and is this command authorised? That gets answered only at the data and command layer. Here's what changes, in security and in cost, once data and commands carry their own cryptographic proof.

The stack that never stops growing

The average enterprise now runs 83 security tools, according to IBM's research, and large enterprises almost certainly exceed 100. Yet data manipulation was the most detected attack technique across monitored OT environments in 2024, and the first malware to speak Modbus TCP directly to industrial devices cut heating to over 600 apartment buildings in Ukraine in winter. More spend, more tools, and the two attacks that matter most, falsified data flowing up and unauthorised commands flowing down, still get through.

How did we get here? Every security leader knows the pattern. A gap is identified, a control is added. A new tool, a new policy layer, a new monitoring capability. Each decision is rational on its own. At scale, a familiar dynamic sets in: security tools watch other security tools, alerts feed platforms, platforms feed dashboards, dashboards need dedicated teams. The stack keeps growing not because risks are being resolved, but because each unresolved root cause demands another compensating control. There is no natural ceiling.

For IT/OT and industrial IoT environments, the root cause is specific and consistent: there is no verifiable trust at the layer where data and commands actually exist. Network segmentation, access brokering and monitoring all do necessary work, but none of them can answer the fundamental question: is this data authentic, and is this command authorised by the system that issued it? That question can only be answered at the data and command layer itself, and much of the stack above it exists to compensate for the fact that, until now, it could not be.

The gap is being actively exploited

That data manipulation figure deserves a closer look. In Nozomi Networks' analysis of anonymised customer telemetry covering the second half of 2024, data manipulation was detected three times more often than the next most common attack technique. And research from Palo Alto Networks and ABI Research shows 72% of OT attacks originate in IT environments. As IT/OT interconnection deepens, with more integrations, cloud connectivity and remote operator access, the number of crossing points between the two worlds keeps multiplying, and each one is a path an attack can travel. That puts justified focus on protecting the boundary. But boundary controls can only govern who and what is allowed to connect. They cannot verify the data and commands that cross once a connection is legitimate.

The threat runs in both directions. Manipulated data corrupts what flows upward: the telemetry that operators, analytics platforms and AI systems treat as ground truth. Stuxnet demonstrated the pattern years ago, destroying centrifuges while operators watched perfectly normal replayed sensor readings. Unauthorised commands corrupt what flows downward, and attackers are investing here deliberately: Dragos reports that sophisticated threat actors have moved beyond network prepositioning to actively mapping control loops, learning how to manipulate physical processes. The Ukraine heating outage is what that looks like in practice. And critically, when a compromised but authenticated operator account issues an unauthorised command to a remote asset, access controls pass it through, because the session itself is legitimate. Catching it then depends on behavioural inference after the fact, a probabilistic safety net rather than proof.

The exposure compounds. Every new connection point added for remote monitoring or operational efficiency is a new path through which falsified data or an unauthorised command can enter. Each path demands more controls, more monitoring, more policy management. The compensating stack grows with the number of connections. The underlying gap does not shrink.

What changes when data and commands carry their own proof

Tributech embeds bi-directional zero trust at the data and command layer. On the upward flow, data receives tamper-evident, cryptographic proof of origin and integrity at the moment it is generated. On the downward flow, commands carry a continuous chain of cryptographic proofs from origin to execution: notarized at creation, verified at the middleware, and verified again at the device before execution, scoped to configuration changes, OTA updates and setpoint changes. A policy layer enforces fine-granular control over which systems can access which data streams and execute which commands. For the compromised account scenario above, the picture changes fundamentally: a command injected or altered anywhere along the path fails verification, any command is constrained to what that specific identity's policy permits, and every command leaves a cryptographic trace bound to its origin. The attacker loses the ability to act invisibly, to act beyond the account's scope, or to deny what was done.

When data carries its own proof of integrity and commands carry their own proof of authorisation, the architecture around them changes. Tools that exist purely to compensate for the missing proof become reducible in scope. Tools that address different threat dimensions, such as OT network monitoring, endpoint security and enterprise IAM, remain fully required and work better with verified data to build on. Tributech is complementary to these platforms, not a substitute for them.

Three shifts drive the economics:

A cryptographic alternative to data diodes. Data diodes enforce one-way flow at the cost of the bi-directional communication that automation and AI integrations increasingly require. The bi-directional model addresses both directions of the risk: notarization provides verifiable integrity on outbound data, and verified commands establish trust on an inbound path that diodes could only handle by blocking it entirely. That makes it an alternative to diode deployments where one-way flow is not genuinely required.

Remote access scope shrinks. Today, VPN seats, jump servers, ZTNA policies and PAM sessions carry the full weight of remote operational activity, because reading a sensor stream or triggering a configuration change requires network-level access. Through Tributech's middleware, data consumption and command execution no longer do. What remains for those tools is the genuinely irreducible set of maintenance tasks, a far smaller and more clearly bounded scope. Fewer seats, simpler policies, smaller attack surface.

Compliance evidence generates itself. Audit trails for data provenance and command verification are produced as cryptographic proof, automatically, supporting compliance with frameworks such as IEC 62443, NIS2 and the EU AI Act. Audit preparation for data provenance can move from months of manual reconstruction to days, drawing on verifiable evidence that already exists.

The numbers: a worked example, with the assumptions shown

Cost reduction claims in security are easy to make and hard to trust, so rather than assert a percentage, we show the model. The example below is a representative critical infrastructure operator, and every assumption is stated so you can judge how closely it maps to your own environment.

The organisational profile: 8,000 employees, 29 sites, 15,000 remote IoT/OT assets, 2,700 internal and 80 vendor users with OT/IT access, and 30 IT/OT integrations.

What the baseline covers, and what it does not. The annual baseline of $8.18M consists of $7.58M in licensing and subscription spend across the thirteen tool categories analysed, plus $600K in operational overhead for managing those tools, based on market benchmarks at this scale. This is in-scope spend only. It is not the operator's total security budget, and the reduction percentages below apply to this in-scope figure, not to overall security investment.

The modelled scope changes by category:

Category

Estimated impact

Data diodes

Cryptographic alternative deployed across all 29 sites

IoT PKI and device enrolment

Standalone enrolment platform consolidated for 15k assets

Jump servers

Reduced from 52 to 35

VPN

60-70% session reduction

PAM

60-70% reduction in managed privileged sessions

SIEM event volume

10-25% reduction

How scope reduction becomes cost reduction. Session and seat reductions convert into savings where licensing is seat-based, session-based or volume-based, and they materialise at contract renewal, not on day one. Multi-year committed agreements delay realisation accordingly. The figures below are annual run-rate savings once implementation is complete and renewals have cycled through.

What drives the range. The single largest sensitivity in the model is the share of operational use cases that can be served through the middleware layer without direct network access. The conservative scenario assumes a lower addressable share; the upper scenario assumes broader coverage.

Scenario

In-scope reduction

Estimated annual saving

Conservative

25%

$2.2M

Base

30%

$2.6M

Upper

35%

$3.0M

What the model deliberately excludes. These are gross savings on the existing stack. The net position depends on the Tributech deployment scope for your environment, and on your current vendor contracts and tool overlap. We model both sides against your specific environment before deployment, so the business case you take to your board is net, not gross.

$2.2M-$3.0M estimated annual saving on an $8.18M in-scope baseline, for the operator profile above.
Want the full category-by-category analysis? The 16-page whitepaper covers all thirteen tool categories, the replacement and reduction logic for each, and the implementation sequence. Download the whitepaper

What the savings actually buy you

The direct cost reduction is the most measurable part of the case. It is not the largest part.

Risk reduction. For notarized data streams and verified command paths, manipulation stops being an undetectable attack vector, reducing exposure to operational disruption, regulatory penalties and recovery costs across the enrolled asset base. For a critical infrastructure operator, even a single low-probability, high-impact incident, on either flow, dwarfs the annual saving range.

AI enablement. Machine learning models and AI agents consume operational data as ground truth, and agentic systems increasingly act on it by issuing commands back to physical infrastructure. If neither the data in nor the command out can be verified, the entire loop runs on faith. Notarized data and verified commands close both ends, removing the trust barrier that currently blocks or limits AI deployment in OT environments. The same investment that reduces your tool spend also builds the foundation for the automation roadmap.

Centralised operations. A single trust infrastructure layer across all sites replaces fragmented, site-level approaches to monitoring, reporting and compliance evidence, and scales as the estate grows.

The bottom line

Most security investments add to the stack: more licences, more integration work, more overhead. A control that closes the foundational gap works in the opposite direction. It reduces what everything around it needs to do.

As automation and AI take more operational decisions without human review, the security of everything built on top depends on whether the data and commands flowing through your infrastructure can be trusted. That is the gap data-layer zero trust closes. It is a gap no perimeter control was designed to fill, and it is the rare security investment that pays you back.

Ready to see what the numbers look like for your environment? Tributech models the full picture against your specific tool stack, contracts and use cases, so the business case you take to your board is net, not gross. Request a tailored analysis.

Not there yet? Download the full whitepaper for the complete category-by-category breakdown.

Download Whitepaper

Read Fewer Tools, Stronger Guarantees: Zero Trust at the Data Layer in IT/OT and Industrial IoT for the full category-by-category cost breakdown and implementation sequence.

Thomas Plank
CEO, Tributech

Blog | JUL 22, 2026

Contact us

You want to unleash the full potential of your data? Contact us for a first discussion about your data strategy.