
Most OT environments have zero security visibility. PLCs, SCADA systems, and HMIs were designed for reliability, not security — they run on flat networks with no logging, no intrusion detection, and no compliance monitoring. When IEC 62443 or NIST 800-82 auditors come knocking, the answer is usually a spreadsheet.
Wazuh fills this gap without a six-figure license. It's the most widely deployed open-source security platform (15K+ GitHub stars, 474 contributors, active since 2015), and it works across both IT endpoints and OT gateway systems. Plant engineers use it alongside dedicated OT-specific tools like Suricata for network IDS.
| Method | Use case | Min resources |
|---|---|---|
| Docker Compose | Quick evaluation, small deployments | 4 CPU, 8GB RAM |
| Kubernetes (Helm) | Production, multi-site scaling | Cluster with 3+ nodes |
| Single server | All-in-one for small sites | 4 CPU, 8GB RAM, 50GB disk |
| Wazuh Cloud (SaaS) | Managed service, no infrastructure | Starts at $500/mo |
| AWS Marketplace AMI | One-click AWS deployment | m5.xlarge or larger |
The platform itself is free (GPLv2). Real costs: