Skip to content
§
§ · build vs buy

OT Network Security Monitoring Software: Build vs Buy

Buy. One site with a reasonably modern control system speaking mainstream protocols should deploy Nozomi Networks or Claroty and have an asset inventory within weeks.

Custom software architecture and database illustration for OT Network Security Monitoring Software Build vs Buy Guide.
The short answer

Buy. One site with a reasonably modern control system speaking mainstream protocols should deploy Nozomi Networks or Claroty and have an asset inventory within weeks. Building only earns its place when your most critical lines speak protocols the products parse poorly, when process telemetry cannot leave the plant, or when per asset licensing across a growing multi site estate stops making sense.

What the off-the-shelf products actually do well

Most plants should buy, and you should hear that before anything else. One site, a reasonably uniform control system, mainstream protocols, no restriction on where telemetry goes: deploy Nozomi Networks or Claroty and you will have an inventory in weeks. A custom build would take two quarters to reach the same place.

These products are good. Dragos carries genuine threat intelligence specific to industrial control systems, written by people who have handled real incidents in this environment. Claroty and Nozomi both parse Modbus TCP, DNP3, EtherNet/IP, PROFINET and the common vendor protocols competently, and their interfaces are mature in ways a first release never is. Armis and Forescout come at it from device visibility across the whole estate and suit an organisation where the boundary between office and plant has already blurred. Tenable OT Security is the sensible answer if your vulnerability programme already runs on Tenable and you want one console.

They also get the safety decision right. Discovery is passive by default: a network tap or a switch mirror port feeds a sensor that infers device identity, role and communication relationships from traffic it watches rather than traffic it generates. Nobody responsible scans a network where an older controller can fault on unexpected packets, and a fault on a running process is a production stop or a safety event.

Then the operational part. Someone else writes the parser when a vendor revises a firmware identity string. Someone else tracks CISA industrial advisories against your firmware versions. Someone else has an engineer reachable when a sensor stops collecting during your outage week. None of that is free in a build, and buying it back later costs more than buying it now.

Where they stop: the line you cannot patch and cannot parse

Every vendor covers the mainstream protocols well. Coverage thins at the edges, and the edge is where your risk lives.

Think about which line worries you most. It is almost never the new one. It is the packaging line from 1998 whose controller runs firmware nobody will touch, programmed by software that only runs on a workstation with an operating system out of support since before the engineer who maintains it was hired. That line often speaks something proprietary, or something old enough that public documentation does not exist. If the sensor cannot parse the traffic, the inventory goes silent exactly where you needed it, and a demonstration will not reveal that because the demonstration runs on the new line.

The second gap is detection quality, and it is structural rather than a product failing. Normal on a process network means something specific: the sequence of operations, the expected value ranges, and the fact that a setpoint write from an engineering workstation at 02:00 is unusual while the identical write at 10:00 during a changeover is routine. Generic baselining learns statistics without understanding intent, so it fires on shift patterns and stays quiet on the thing that matters. The detections that earn trust in a control room get written jointly with your process engineers, and no vendor can do that for you from a cloud.

The third is where the data goes. Process telemetry reveals production rates and recipes. Some operators are contractually barred from sending it anywhere, and product licensing frequently assumes a connected model even where an on premise option exists.

The arithmetic: cost per monitored asset versus a build

Licensing here is usually priced per monitored asset or per site sensor, as an annual subscription rather than a perpetual licence. Get your renewal quote broken out that way before modelling anything, because the shape of the fee matters more than the headline number.

One site, 400 monitored assets: the annual subscription costs less than the engineer who would run a build, and it arrives working. Buy without hesitation.

Now extend the model. Take the per asset figure across every site you intend to bring into scope over five years, including the ones you have not acquired yet. Industrial estates grow by acquisition, and each acquired plant arrives with its own controller vintages and its own asset count. A subscription priced per asset grows with a number you do not control and cannot reduce, because you will not decommission controllers to save licence fees.

The crossover in our experience sits somewhere between eight and fifteen sites, or roughly 5,000 to 8,000 monitored assets, depending on how a given vendor prices. Below that, a build almost never wins on money alone. Above it, the five year subscription total starts to approach a build plus five years of support, and the decision moves onto the non financial factors instead.

One more line belongs in the model. Count the engineer hours currently spent reconciling the drawing set from the last upgrade, the spreadsheet a contractor left behind, and the maintenance asset register. That work happens either way, and a product only removes it if the inventory becomes trusted enough to serve as the engineering record.

What a custom build actually costs

Bands, from delivery. A first release covering passive collection at one representative site, parsers for the protocols actually present there, an asset inventory carrying process context, and the core engineering integrity detections runs $120,000 to $240,000 and ships in 16 to 24 weeks. A full platform adding multi site aggregation, process aware detection developed with your engineers, exposure and compensating control context, security operations centre integration and regulatory reporting runs $300,000 to $700,000 phased across 9 to 18 months.

Data migration adds 10 to 25 percent, and here it is not a database export. It is reconciling four partial records into one: the drawings, the contractor spreadsheet, the maintenance register and the discovered inventory. A plant engineer then adjudicates every disagreement and attaches the process criticality that turns a device list into a decision tool. That adjudication cannot be automated and it is the part that slips.

Year two runs 15 to 20 percent of build cost annually. Parsers need maintenance when vendors revise firmware identity strings, advisory feeds change format, and each new site brings a device family nobody has met.

Four things push the number up. A proprietary protocol with no public documentation is genuinely expensive and sometimes needs the vendor to cooperate. Sensor placement is a survey per plant, because in a Purdue style architecture the interesting traffic between the supervisory layer and the control layer rarely crosses a single point. Safety instrumented systems carry extra constraint and often a hard prohibition on any active interaction. Hazardous area classification changes what hardware you may physically install.

The schedule constraint nobody budgets is your own engineers. You enter the plant when the plant lets you, and validation waits for a maintenance window.

The four situations where building wins

  • Regulatory fit. If your driver is NERC CIP evidence as an electric utility, price the products first, because several have invested directly in that reporting and you may be buying a solved problem. The build case appears where the obligation is unusual: a water system carrying risk assessment duties under the America's Water Infrastructure Act across a mixed estate, or a manufacturer aligning zones and conduits to IEC 62443 whose assessor wants the zone model to be the structure of the inventory rather than a label applied afterwards.
  • Scale economics. Per asset subscriptions across a growing multi site estate, where every acquisition adds licence cost you cannot negotiate away and cannot avoid by decommissioning. That is the clean money case and it needs the site count above.
  • A workflow that is your competitive advantage. If process knowledge is what makes your plants perform, detections encoding your operating sequence, your recipe boundaries and your change control rules are not something to rent. That logic is commercially sensitive, which is a second reason to keep it inside.
  • Integration sprawl across three or more systems. The inventory earns its keep joined to other records: the computerised maintenance management system, the historian, the change management workflow, and the identity system that says which integrator holds remote access this week. When four teams each maintain a partial asset list, reconciliation is the actual project, and a separate security console adds a fifth list rather than removing four.

Two of those true is a build conversation. One of them is a negotiation with your current vendor.

How to decide in a week

Do not start with a vendor demonstration. Start with a protocol census.

Monday and Tuesday: with plant engineering present and approving, put a tap or a mirror port on the most awkward cell in your most awkward plant and capture 48 hours of traffic. No analysis yet. Just the capture file.

Wednesday: send that capture to two product vendors and ask one question. How many distinct devices can you identify from this file, with vendor, model and firmware, and which conversations can you not parse. Insist on an answer against your traffic rather than their reference data. A vendor who will not run your capture has answered a different question.

Thursday: take the unparsed conversations to your controls engineer and ask which lines they belong to and what those lines produce. If the silence sits on a spare compressor, buy the product. If it sits on the line carrying half your output, you have found the reason a build exists.

Friday: price both paths across five years, including the sites you plan to bring into scope, and make the call with your plant lead in the room rather than only your security team.

If it goes the build way, the next step is a paid discovery phase rather than a proposal. Three to four weeks, fixed fee, including a plant walkdown, producing a signed product requirements document covering sensor placement per site, the parser list, the inventory data model, the one way data path out of the plant, and acceptance criteria. You own that specification whoever builds it.

Who we are wrong for: single site operators with uniform modern controls, anyone shopping for a body count rather than a specification, and anyone who wants coding to begin before a walkdown. Digital Heroes writes that requirements document before any code, with more than fifty specialists and India LLP, US LLC and UK LTD entities so intellectual property assigns under your own law. ShopScore, HeroCheckout and Section Vault are our own products, over 2,000 projects sit behind us, and you meet the named team before signing. We are listed on Clutch, Trustpilot, Fiverr Vetted Pro and D-U-N-S.

Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Retailers improving Core Web Vitals saw measurable gains: Vodafone improved LCP by 31% for 8% more sales, Lazada saw a 16.9% mobile conversion increase, and Cdiscount saw a 6% Black Friday revenue uplift. Source: web.dev (Google Chrome team) (2021) →
  2. Technology 'Leaders' grow revenue at more than twice the rate of 'Laggards'; laggards surrendered 15% in foregone annual revenue in 2018 and stood to miss out on as much as 46% in revenue gains by 2023 if they did not change their enterprise technology approach. Based on a survey of more than 8,300 organizations across 20 industries and 20 countries. Source: Accenture (2019) →
  3. Flexera's 2025 State of the Cloud Report (survey of 750+ technical and executive leaders) found that 84% of respondents believe managing cloud spend is the top cloud challenge for organizations today, with cloud budgets already exceeding limits by 17%. Source: Flexera (2025) →
  4. APQC's Open Standards Benchmarking data on the monthly financial close found median performers take about 6.4 calendar days to close the books, while top performers (top 25%) do it in 4.8 days or fewer and bottom performers (bottom 25%) take 10 or more days. Source: APQC (2018) →
FAQ

Frequently asked questions

How long before a custom OT monitoring build is actually useful?

Sixteen to 24 weeks to a first release at one site covering passive collection, the protocols present there, the asset inventory and core engineering integrity detections. That is longer than an equivalent office project and the reason is access rather than code. You enter the plant when the plant permits it, and every validation step waits for a maintenance window your production schedule controls.

Who owns the sensor code and the captured network traffic?

You should, from the first commit, with the repository and the cloud or on premise infrastructure in your own accounts. Captured process traffic reveals production rates and recipes, so treat it as commercially sensitive rather than as telemetry. Write retention, deletion and access terms into the development contract before kickoff, and confirm no copies persist in the developer environment after handover.

What happens if a passive sensor quietly stops collecting?

That is the worst failure mode in this category, because it produces confidence without coverage. Any build or product should hold a heartbeat per sensor and alert on absence of traffic as loudly as it alerts on suspicious traffic. Ask a vendor directly how you would learn that a mirror port was reconfigured during a switch replacement, because that is how coverage usually disappears.

Can we build the asset inventory and buy detection separately?

Yes, and it is often the cheapest sensible split. The inventory is the deliverable your engineers will use daily, and once it carries process area, line and criticality it becomes the engineering record rather than a security artefact. Detection can then run on a product feed or on your own rules. Building the inventory first also proves your protocol coverage before you commit further money.

What is the difference between passive discovery and active scanning?

Passive discovery watches traffic and infers what devices are, generating nothing itself. Active scanning sends queries, which older controllers can and do fault on. Passive misses devices that never transmit, and quiet devices genuinely exist, so the honest approach layers passive collection with targeted read only queries in approved maintenance windows and reconciles both against a physical walkdown record.

Should we let a vendor cloud see our process telemetry?

That is a commercial question before a security one. Traffic patterns reveal production rates, batch timings and recipe structure, and some contracts with your own customers prohibit sending it anywhere. Check the customer agreements first. If cloud is barred, ask each vendor what the on premise deployment actually costs and what features it loses, because the answer is rarely nothing.

Can a custom build satisfy NERC CIP evidence requirements?

It can, but check the products first if that is your main driver. Several vendors have invested specifically in NERC CIP reporting, and buying a solved problem beats rebuilding it. A custom build makes sense when your evidence needs to join the asset inventory to your own change management and maintenance records, which is exactly the join a separate security console cannot make.

What happens if the engineer who wrote our protocol parsers leaves?

This is the real key person risk in a build and it is manageable if you plan for it. Require parser test fixtures built from captured traffic, written specifications for each protocol implemented, and at least two people who have modified every parser. Without those, a firmware revision two years later becomes a research project instead of an afternoon.

Should a single plant operator ever build this?

Rarely on cost, occasionally on coverage. One site with mainstream protocols should buy every time. The exception is a single site whose most critical process runs something no product parses, where the choice is not build versus buy but build versus having no visibility on the line that matters most. Start with a traffic capture before assuming which case you are in.

Can safety instrumented systems be monitored the same way?

Not casually. Systems governed by functional safety requirements carry additional constraints and frequently a hard prohibition on any active interaction, so passive observation with no injected traffic is the only acceptable approach, and even that needs written sign off from the safety authority for the site. Treat any developer who is relaxed about this as disqualified rather than as needing guidance.

What is a discovery phase, and is it worth paying for separately?

Pay for it, and treat the output as yours. A discovery phase runs two to three weeks, typically 5 to 10% of the eventual build budget, and produces a written scope, wireframes, and a fixed quote you can take to any vendor, including a competitor of the agency that wrote it. Skipping it is how projects end up quoted from a two-paragraph email and delivered at twice the price.

How do I work out whether custom software will pay for itself?

Do the arithmetic on hours before anything else: if the system saves three staff eight hours a week at a $35 loaded hourly cost, that is about $43,700 a year against, say, a $70,000 build plus 15 to 20% annual maintenance, a payback around two years. Add revenue effects only if you can name them specifically, like faster quotes or fewer abandoned orders, not as vague growth. In our delivery experience the businesses that see payback inside 24 months are the ones automating a process they already measure.

How many SaaS seats do we need before building custom becomes cheaper?

The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.

If an agency builds my software, who actually owns the code?

You should own everything, assigned in writing: the contract transfers full IP to you on final payment, the code lives in your GitHub organization, and hosting runs in cloud accounts you control. The red flag is a proposal that mentions the agency's proprietary platform or framework, which usually means you are renting, not buying. Digital Heroes structures every build this way precisely so a client can fire us and lose nothing but the relationship.

Can we migrate years of data out of our current system into new custom software?

Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.

Should I ask for a fixed price or pay the agency hourly?

Fixed price for the first version, hourly or retainer for what comes after launch. A fixed-scope, fixed-price V1 puts the estimation risk on the agency, which is exactly where you want it while trust is unproven; hourly billing on an unscoped greenfield build is a blank check. After launch, flip it, because maintenance and small features arrive unpredictably and fixed-pricing every ticket wastes everyone's time.

Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply