Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Claroty xDome for Healthcare: Platform Demo

Claroty
09/21/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Many devices in a healthcare network have long life cycles. They often can't support security agents, and sometimes they can't even be patched. Because of this, the entire connected care infrastructure of a hospital is often a black box to the very teams put in charge of managing it. But this is why Xdome was created. To provide visibility and governance where agents can't go. Xdome is a purpose-built CPS or cyber-physical systems protection platform. At its core, Xdome takes raw data from network traffic, integrations, and even files, and transforms it into actionable information. Think of it like a virtual factory. The platform takes in the raw inputs of the network and produces the outputs that biomed, security, and other healthcare teams need to protect patient safety. All the devices connected to the network are broken into one of four buckets. IOMT, or Internet of Medical Things, these are clinical assets like imaging systems and infusion pumps. But beyond medical devices, we give visibility into OT. This is the building's physical brain. Things like HVAC, power, and elevators. And IoT, auxiliary devices like smart clocks and cameras. And finally, IT, managed workstations and servers. Before we go any further, let's take a look at how customizable Xdome is. Users can use the Create Your Dashboard AI widget to do just that, or add or subtract widgets from a dashboard using the Manage Widgets button. Either way, dashboards can be saved. Users also have access to Clarity Recommended dashboards, and even our Persona dashboards. I'm going to click into the CISO dashboard. Where most teams struggle is knowing where to start. This is why Xdome provides a total risk score of the environment. This risk score is based on likelihood and impact. This information gives teams a laser focus on which devices, in this case, 84, need the most attention first. Let's take a look at a medical device to see where this information comes from. I'm going to search for a Toshiba Aquilion CT scanner. The major differentiator here for Clarity is our data fidelity. Because if the user gets identification wrong, the vulnerabilities are just a wild guess, and everything becomes a false positive. Many of our competitors take a probabilistic approach, meaning basically they just guess based on the equivalent of a shadow. They might assign a type, for example, based on the manufacturer, but they could be wrong because they're missing additional important information. This is why Clarity takes a deterministic approach. We use DPI, or Deep Packet Inspection, to go beyond the media access control address. We parse actual communication to see the device's true digital identity. This includes things like serial number, device ID, operating system, even VLAN. This depth of information is what gives us an identification confidence score of 100. Now let's take a look at risk and exposure management. This device has a risk score of 62, which is high. We calculate the risk by looking at how an asset is built and how it behaves. We correlate CVEs, or Common Vulnerabilities and Exposures, with real-world threat intel using the formula of likelihood. This is where we prioritize KEVs, or Known Exploited Vulnerabilities. These aren't just common vulnerabilities. These are the things that hackers are actually using right now. Then we add it to impact. We assign clinical context. If this scanner is in the trauma unit, for example, the impact is maximum. Then we subtract compensating controls. This is essentially giving security teams credit for existing security, like network segmentation. But the risk simulator is where teams can prove ROI. They can toggle specific variables to see how they impact the risk score. For example, what happens to my risk if my firmware is no longer outdated? What happens if I apply an ACL or access control list to segment it? If teams don't know where to start, they can click the Clarity Recommended button. This allows teams to see the score drop in real time based on what Clarity recommends, allowing them to build a safety bubble around the device before they even ever touch the physical equipment. Now let's look at network protection. Since patching medical devices isn't always feasible, network segmentation is the best defense. Looking at this ACL policies table, we can see the Clarity Recommended policies. Teams can also simulate these against observed traffic to ensure they're not impacting patient safety before the policy is enforced. But to understand why these policies matter, we need to see where our traffic is going. The global communication map shows us every external connection our hospital is making. On this map, we can even filter by malicious IPs. If you see a medical device in your facility communicating with a malicious IP in another country, it is no longer a theoretical risk. It's an active event. So you can slice and dice this by site or device type to ensure your clinical assets aren't talking to the wrong parts of the world. Beyond the map, we have world-class threat detection. We even map alerts to the MITRE ATT&CK framework, giving security teams a playbook of the tactics, techniques, and procedures an attacker is using, like lateral movement or data exfiltration. And when a new advisory breaks, like the Stryker incident, one click on the relevant filter maps threats to the specific inventory instantly. This lets teams know if they're at risk in seconds, not weeks. Xdome though is more than a security platform. It's a business efficiency tool. By integrating with the customer's CMMS, or computerized maintenance management system, we can help teams work smarter. Clicking on the Utilization toggle gives information to teams like, do they need to buy 50 more infusion pumps, or is their current inventory enough? We can show actual usage data to drive smarter procurement. And location mapping? This is something that Biomed teams love. We can use the network infrastructure to show exactly where an asset is, so Biomed isn't hunting through five buildings during a recall. But it's important to note that Xdome doesn't sit in a silo. We integrate with entire tech stacks, feeding high-fidelity data into tools like the CMMS, SIEM, the Security Information and Event Management System, and more, all for threat response and to automate workflows. Managers can find out about what's happening in the Xdome platform and their environment with customized reports. You could schedule a high-risk report, for example, for the CISO, or a device count report for a site or location manager. This ensures the right data reaches the right person at the right time. One final note, you'll notice that up in this navigation bar, secure access isn't there. A more robust version for healthcare is being built by the product team. And this has been a high-level overview of Xdome for Healthcare. We identify and show all devices connected to the network, helping teams move from unquantified risk to actionable, clinical-first protection. This is how Clarity ensures that patient safety, clinical throughput, and revenue continuity remain uninterrupted.

TL;DR

  • Claroty xDome provides agentless visibility across all connected hospital assets — IoMT, OT, IoT, and IT — addressing the security blind spots common in healthcare networks with long device life cycles.
  • Deep Packet Inspection delivers a 100% device identification confidence score, which Claroty contrasts against competitors' probabilistic guessing approaches that can produce false positives.
  • A built-in risk simulator lets security teams model the effect of remediations like firmware updates or network segmentation on risk scores before any changes are made to live clinical systems.
  • Beyond security, xDome integrates with CMMS platforms to support smarter procurement decisions and physical location mapping, helping biomed teams respond to equipment recalls without searching across multiple buildings.

Visibility Across the Connected Care Environment

Claroty xDome is a purpose-built cyber-physical systems (CPS) protection platform designed for healthcare environments where traditional security agents cannot be deployed. The platform ingests raw data from network traffic, integrations, and files, then transforms it into actionable intelligence for biomed, security, and operations teams. All connected assets are automatically classified into four categories: IoMT (clinical devices such as imaging systems and infusion pumps), OT (building systems including HVAC, power, and elevators), IoT (auxiliary devices like smart clocks and cameras), and IT (managed workstations and servers). This unified inventory eliminates the blind spots that make hospital networks a black box to the teams responsible for securing them. Customizable dashboards — including AI-generated layouts and persona-specific views such as a CISO dashboard — surface a total risk score based on likelihood and impact, giving teams an immediate prioritization signal across the entire environment.

Deterministic Device Identification and Risk Simulation

A core differentiator Claroty emphasizes is data fidelity in device identification. Rather than a probabilistic approach that infers device identity from limited signals like manufacturer data, xDome uses Deep Packet Inspection (DPI) to parse actual network communications and extract precise attributes — serial number, device ID, operating system, and VLAN — yielding a 100% identification confidence score. This accuracy is positioned as foundational: incorrect identification renders vulnerability data meaningless. Risk scoring combines CVE correlation with Known Exploited Vulnerabilities (KEVs), clinical context (e.g., whether a scanner is in a trauma unit), and compensating controls such as existing network segmentation. The risk simulator allows teams to model the impact of specific remediations — firmware updates, ACL application — before touching live equipment, enabling them to build a virtual safety bubble around high-risk devices and demonstrate ROI to leadership.

Chapters

0:00 - Introduction and Problem Context
0:34 - Platform Overview and Asset Categories
1:39 - Dashboards and Risk Scoring
2:52 - Device Identification and Data Fidelity
3:58 - Risk Simulation and Remediation
5:37 - Network Protection and Threat Detection
7:24 - Operational Efficiency and Integrations
9:00 - Roadmap Note and Closing Summary

Key Quotes

3:07 "Many of our competitors take a probabilistic approach, meaning basically they just guess based on the equivalent of a shadow."
3:50 "This depth of information is what gives us an identification confidence score of 100."
4:29 "These aren't just common vulnerabilities. These are the things that hackers are actually using right now."
5:28 "This allows teams to see the score drop in real time based on what Clarity recommends, allowing them to build a safety bubble around the device before they even ever touch the physical equipment."
7:14 "This lets teams know if they're at risk in seconds, not weeks."
9:27 "This is how Clarity ensures that patient safety, clinical throughput, and revenue continuity remain uninterrupted."

FAQ

How does xDome handle medical devices that can't be patched or run security agents?

xDome is agentless by design, relying on network traffic analysis and Deep Packet Inspection rather than installed software. For unpatched devices, the platform recommends network segmentation as the primary compensating control and allows teams to simulate ACL policies against observed traffic before enforcement to ensure patient safety is not disrupted.

Can xDome integrate with existing hospital IT and operations tools?

Yes. xDome integrates with CMMS (computerized maintenance management systems), SIEM platforms, and broader tech stacks to feed high-fidelity device data into existing workflows. These integrations support both security threat response and operational functions like equipment utilization tracking and procurement planning.


Categories:
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • OT
  • IoT Security
  • Data Protection
  • Security Operations
  • Vulnerability Management
  • Demo
  • Technical Deep Dive
  • Healthcare cybersecurity
  • Medical device security
  • IoMT visibility
  • OT
  • IoT asset management
  • Network segmentation
  • Deep Packet Inspection
  • CMMS integration
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Claroty xDome for Healthcare: Platform Demo

              Industry Events (Sponsor Hosted)

              • Sep
                23

                Invisible Data: The Key to Effective Protection Strategies

                09/23/202601:00 PM ET
                • Sep
                  29

                  Embracing AI Adoption While Ensuring Robust Security Measures

                  09/29/202612:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/23/2026
                      01:00 PM
                      09/23/2026
                      Invisible Data: The Key to Effective Protection Strategies
                      https://www.truthinit.com/index.php/channel/2087/invisible-data-the-key-to-effective-protection-strategies/
                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhanced Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhanced-visibility-and-control-in-your-operations/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version