Security1 publisher2 min readPublished
Nozomi Compass puts OT change approvals on the asset feed that powers Vantage
Nozomi Networks is selling industrial operators the argument that their remediation backlog is a bookkeeping problem. Compass is the product it wants holding the asset record, the approvals and the audit evidence.
The Watch · Security desk

What happened
- Nozomi Networks announced Nozomi Compass, an OT asset and service management platform for tracking industrial assets, vulnerabilities and exposures in one place.
- The company says the platform pulls asset data, remediation workflows and operational processes together to cut reliance on spreadsheets, IT ticketing systems and manual workflows built for IT.
- Compass runs on the same real-time first-party OT and IoT asset data that feeds Vantage, Nozomi's existing cyber-physical security platform, instead of a retrofitted generic IT platform.
- Nozomi presents the product as the foundation for autonomous and agentic OT and IoT workflows, with a human kept in the process at every step.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Any plant that already runs a CMDB or an ITSM queue has to decide which side holds the authoritative OT asset entry, because Compass wants to own the record and also exports into the six systems that hold competing copies.
- constraint Approvals gated on safety criticality and Purdue level are only as good as the sensor data filling those fields, so a wrong entry now blocks or waves through a change instead of just sitting in a stale sheet.
- exposure Whoever signs the regulator submission is signing a vendor's mapping, and an error in it lands as an audit finding.
- capability Agentic remediation in a plant needs an inventory that says which device can be touched and when. The asset record is the precondition for the automation.
A detection platform tells an operator that a PLC is running vulnerable firmware. A system of record decides whether the fix gets approved, by whom, and in which maintenance window. Nozomi says Compass asset records carry Purdue-level relationships, safety criticality and full lifecycle history, and that the workflow logic reads those fields [4]. Changes move through plan, approve, execute and prove steps, and the platform keeps traceable approvals, consequence-based risk scoring and compensating controls as the record of what was authorized, changed and completed [5].
The announcement also names six kinds of enterprise system the governed OT data is meant to flow into: EAM, CMDB, ITAM, ITSM, SIEM and SOAR [7][8]. Several of those already hold an asset entry for the same device. Nozomi's pitch against them is blunt: stale spreadsheets, imported records and IT-first configuration databases replaced by one current source of truth [13]. A plant running a CMDB ends up with two candidates for the authoritative record and has to pick one.
"Until now, operators have been working with an ineffective IT-native toolset to service their OT assets," Andrea Carcano, CEO of Nozomi Networks, said [9]. CTO Moreno Carullo put the design claim this way: "Nozomi Compass is purpose-built around how industrial operations work, including safety windows, process dependencies, and physical consequences, so teams can finally govern change and prove compliance without forcing OT data into an IT-shaped box" [10].
The compliance side is where the product asks for the most trust. Nozomi says evidence is generated continuously and mapped to frameworks including NERC CIP, IEC 62443, NIS2 and TSA [6]. The same vendor supplies the asset data sitting underneath that evidence [3][6].
None of this changes what an attacker can reach in a plant this week. The claim is about time to close, and Nozomi's own framing is that vulnerability discovery keeps outpacing manual remediation [11]. Where a remediation queue stalls because nobody can say which of four identical drives is safety-critical, an inventory that carries that field on every record removes a real delay. Where it stalls because the process unit runs until the next turnaround, it does not. The announcement lists the key capabilities as things Compass "will include", and Nozomi did not publish pricing, an availability date or a named customer [12].
What to watch
- Pricing, a general availability date, and whether the capability list ships intact or stays roadmap.
- A named customer running Compass as the authoritative asset record in place of an existing CMDB.
- The first NERC CIP or NIS2 audit where continuously generated Compass evidence is submitted and accepted.