CYBERSECURITY FAQ

What Is a Cyber-Physical System (CPS)?

A cyber-physical system (CPS) is a system is which digital networks and physical systems are tightly connected. Gartner began using the term in 2022, and in 2025 published its first Gartner® Magic Quadrant for CPS Protection Platforms, where Nozomi Networks is named a Leader. We were named a Leader again in 2026 and received the highest scores in all four Use Cases in the companion guide: Critical Capabilities for CPS Protection Platforms.

The term cyber-physical systems goes back nearly two decades, however. It was first coined in 2006 by Helen Gill at the U.S. Nation Science Foundation. Her work helped launch a new field of research into complex systems in which computational, networking and physical processes are deeply intertwined.

Despite the re-emergence of CPS, the terms industry control system (ICS), industrial automation and control system (IACS) and simply operational technology (OT) are more commonly used to describe networks and devices that automate, monitor and control physical processes in the real world. With so many terms already used interchangeably, why is CPS taking hold now? That question may be best answered by looking at the growing array of point solutions and platforms designed to protect these complex systems and their increasing attack surfaces.

Examples of Cyber-Physical Systems

Cyber-physical systems can include the connected assets, control systems and operational technologies that monitor or control physical processes. In industrial and mission-critical environments, this may include manufacturing lines, power generation systems, building management systems, transportation systems, medical devices, robotics, HVAC and cooling systems, cameras, access control systems and other connected operational assets.

What these systems have in common is that cyber activity can affect physical outcomes. A change in network behavior, device configuration or system availability may influence production, safety, service delivery or operational continuity.

What Is a CPS Protection Platform?

Gartner VP Analyst Katell Thielemann is largely credited with resurrecting the term cyber-physical system in 2022, arguing that it more accurately captures the convergence of IT, OT and IoT assets and networks, including wireless, that are now commonplace in production and mission-critical environments. Thielemann went on to coin the term “CPS protection platform,” a market that Gartner now defines as “products and services that use knowledge of industrial protocols, operational/production network packets or traffic metadata, and physical process asset behavior to discover, categorize, map and protect CPS in production or mission-critical environments outside of enterprise IT environments.”  

This distinction matters because cyber-physical system security is not the same as traditional IT security. They often include legacy assets, specialized industrial protocols, third-party connections and devices that cannot be easily patched, scanned or taken offline. Security teams also need to understand how assets behave in context, because a cyber event in a CPS environment can disrupt production, affect safety or impact the delivery of essential services.

The 2025 Magic Quadrant for CPS Protection Platforms elaborates on the need for more precise terminology to define a growing market:

Until recently, “OT security” was seen as a catch-all security market encompassing everything from intrusion detection/prevention services (IDS/IPS) vendors, point solution firewall vendors, data diodes vendors, USB kiosk vendors and professional services providers. Three years ago, Gartner established specific cyber-physical categories due to both rising end-user demand and rapid vendor innovations in response to a growing focus on CPS security.1

For organizations protecting industrial, commercial and critical infrastructure environments, this shift means CPS security is no longer just about adding another point solution. It requires a platform approach that can discover assets, understand operational context, prioritize risk and detect threats across increasingly connected cyber-physical environments.1

Protect Your Cyber-Physical Systems

Detect threats faster and respond with confidence across OT, IoT, and cyber-physical environments.

Explore Threat Detection & Response →

How Nozomi Networks Protects CPS Environments

The Nozomi Networks platform meets the definition of a CPS protection platform, as evidenced by our status as a Leader in consecutive Magic Quadrants. Purpose-built for complex industrial, commercial and critical infrastructure environments, our platform combines visibility from the endpoint to the air with continuous monitoring and AI-powered analysis to minimize cyber risk and maximize operational resilience.

When evaluating a CPS protection platform, organizations should look for capabilities that support both cybersecurity and operational needs. These include broad asset discovery across OT, IoT and IT-connected systems, protocol-aware monitoring, behavioral baselining, risk prioritization, threat detection, response workflows and compliance support across distributed environments.

Whether you call it OT security, industrial cybersecurity, or CPS protection, Nozomi Networks provides the asset inventory, risk scoring, threat detection and response capabilities industrial organizations need to meet regulatory requirements and secure complex operational environments.

Request a demo to see how the Nozomi platform can help defend your cyber-physical systems.

1 Gartner, Magic Quadrant for CPS Protection Platforms, Katell Thielemann, Wam Voster, Ruggero Contu, 12 February 2025  

Back to FAQs