INTEGRATION

Cyolo

Identity-Based Access for Every Guardian-Discovered Asset — Zero Trust Without Network Change

About
Cyolo

ConnectCyolo PRO with Nozomi Networks Guardian to turn OT asset visibility intoenforced, identity-based access. Cyolo PRO polls the Guardian asset inventoryand automatically populates its own asset database with discovered devices —name, IP, MAC, vendor, type, and operating system — so administrators buildaccess policies on real, current inventory instead of manual lists.Configurable polling intervals, matching keys, and attribute-override ruleskeep records accurate and deduplicated over time. Every asset Guardiandiscovers can be brought under zero-trust privileged access control, with MFA,supervised sessions, recording, and full audit — without network redesign.

Features

  • Automated OT Asset Inventory Sync

    Cyolo PRO polls Nozomi Networks Guardian on a configurable interval and imports discovered assets directly into its inventory, eliminating manual asset entry and keeping access policy aligned with the live state of the OT network.

  • Accurate Matching and Deduplication

    Cyolo administrators define matching keys and attribute-override rules, so assets already known to Cyolo are enriched rather than duplicated, and the authoritative source is respected field by field.

  • From Discovery to Enforced Access

    Assets surfaced by Guardian become targets for least-privilege connections with MFA, supervision, session recording, and audit — closing the gap between knowing an asset exists and controlling who reaches it.

Importer Data Types

Vantage imports the following from
Cyolo PRO (Privileged Remote Operations)
:

Joint Use Cases

  • Onboarding a newly commissioned site

    WhenGuardian discovers devices at a newly instrumented plant, Cyolo PRO ingeststhem automatically and administrators can scope access for OEMs, contractors,and internal engineers on day one, without waiting for a manual inventoryexercise or a CMDB update.

  • Governing third-party vendor access proportionally to risk

    Securityteams use Guardian asset context — device type, vendor, criticality — to decidewhich assets warrant supervised, recorded, time-bound access in Cyolo PRO, sovendor connections to PLCs, HMIs, and engineering workstations are controlledaccording to their operational impact.

  • Compliance evidence spanning visibility and access

    Auditorspreparing IEC 62443 or NERC CIP evidence can trace an asset from Guardiandiscovery through to the Cyolo PRO policy, session recording, and audit loggoverning it, demonstrating both that assets are known and that access to themis controlled and reviewable.

Integration Prerequesites

  • Cyolo PRO v7.2 or later
  • Nozomi Networks Guardian appliancereachable over HTTPS from the Cyolo component performing the poll
  • Guardian API access enabled, with adedicated read-scoped API key (key name and token) for the asset inventory
  • Cyolo PRO administrator withpermission to configure asset connectors
  • Consistent identifiers (IP, MAC, orhostname) between Guardian-observed and Cyolo-known assets, to support accuratematching and deduplication

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory and management.