SIGA OT Solutions

Cybersecurity Dual-Use Technology Priority Signal Founded 2014

Last updated: Jul 31, 2026

SIGA OT Solutions is an Israeli OT cybersecurity company whose SigaGuard platform monitors raw electrical signals at Purdue Model Level 0, while SigaGuardX and SigaPAS extend detection, incident-response decision support, and controlled process-attack simulation across Levels 1-4. The company targets operators of critical infrastructure and industrial processes that need an independent view of physical process integrity when network, PLC, or HMI telemetry may be compromised.

Visit Website

Company Overview

SIGA's core technical proposition is process-level visibility rather than another packet-inspection layer. SigaGuard is a field-deployed hardware sensor that passively duplicates selected analog and digital I/O signals from sensors and actuators, creating an out-of-band reference for what the machinery is actually doing. SigaGuardX can analyze Levels 1-4 data on its own and, when paired with SigaGuard, compare PLC, HMI, OPC, historian, and other software reports with Level 0 physical signals. The company describes model-free, multivariate and correlation-based machine learning, anomaly scoring, and detection of false-data-injection patterns; these are vendor claims that should be validated against independent test results and customer telemetry.

The current suite also includes SigaPAS, a software process-attack simulator and training tool. SIGA positions it for scenario design, controlled process manipulation, detection validation, incident-response rehearsal, and collaboration between operations and cybersecurity teams. The commercial problem is credible: utilities, oil and gas, water, data centers, mining, manufacturing, and other process industries may be forced to shut down when digital telemetry is no longer trusted. An independent physical reference could help operators distinguish a real process hazard from a compromised display or an ordinary operational fault, although the value depends on sensor coverage, installation engineering, baseline quality, and integration with existing safety and control procedures.

SIGA is competing in a crowded OT security market that includes Claroty, Nozomi Networks, Dragos, Radiflow, Microsoft and major security-platform vendors. Most substitutes emphasize asset discovery, network detection, endpoint or vulnerability management, or broader XDR workflows; SIGA's differentiation is the Level-0 physical reference and the claim that it remains useful when higher-layer systems are manipulated. The company reports global activity across power, water, oil and gas, data centers, and other sectors. Public evidence includes a New York Power Authority substation test described on SIGA's product page, prior public references to water and utility deployments, an Azure Marketplace availability announcement, and a 2021 Series B funding report. These signals establish commercialization effort, not repeatable scale: current ARR, renewal rates, gross margin, deployment count, sales-cycle length, and customer concentration are not publicly established.

The national-security relevance is substantive but should be stated precisely. The same physical-process integrity problem appears in civilian critical infrastructure, defense-support utilities, shipboard or industrial facilities, and other mission-critical environments. Detection of manipulation at the process layer can support continuity and safer containment, but SIGA is a defensive monitoring and decision-support product; public sources do not establish classified deployments or government contracts. Its Israeli engineering base, U.S. corporate presence, industrial partner history, and reported work across several countries may support strategic reach, while also creating export-control, procurement, localization, and cybersecurity-assurance questions. SIGA remains an early-stage independent company in database terms: Series B and initial-revenue evidence indicate progress beyond a prototype, but not the maturity of a scaled public-company platform.

Dual-Use Assessment

Military & Commercial Applications

SIGA's core capability has direct commercial and defense applicability because electrical-signal monitoring and process-integrity verification can protect power, water, industrial, data-center, maritime, and defense-support OT. The technology is defensive rather than an offensive system, and public evidence supports relevance to critical infrastructure and defense-adjacent operations but does not prove classified or military deployments. Dual-use strength is therefore high, with deployment, export-control, assurance, and accreditation diligence still required.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

SIGA has a credible strategic fit with dual-use infrastructure resilience: a specific physical-layer monitoring thesis, named products, a reported Series B, a public industrial partner and marketplace route, and evidence of deployments or tests in critical-infrastructure settings. The opportunity is not de-risked. Diligence should establish recurring revenue and renewal quality, number and size of active installations, sensor installation and support economics, false-positive and false-negative performance, patent and software ownership, security certification status, channel dependence, and the extent to which SigaGuard complements rather than displaces incumbent OT tools. The company is a priority-signal startup for strategic review, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

SIGA could add a differentiated process-integrity layer to a critical-infrastructure security stack by supplying evidence that is independent of potentially compromised network and control-system telemetry. That can improve continuity, incident triage, recovery confidence, and protection of industrial assets supporting civilian and defense missions. Strategic value is strongest where a short outage is costly, false data injection is a realistic concern, and operators can instrument enough Level-0 signals to make the reference useful. Relevant ecosystem partners or acquirers could include industrial automation vendors, OT security platforms, utilities technology suppliers, and defense or maritime integrators, but no transaction or government-program outcome should be assumed.

Key Technologies

  • Level-0 analog and digital I/O signal capture
  • Out-of-band physical-process reference monitoring
  • Unsupervised and multivariate anomaly detection
  • Cross-layer correlation across Purdue Levels 0-4
  • False-data-injection and process-manipulation detection
  • OT incident-response decision support
  • Controlled process-attack simulation and training

Use Cases & Applications

  • Detecting manipulation of utility, water, and industrial processes
  • Independently validating PLC, HMI, OPC, and SCADA telemetry during incidents
  • Protecting substations, generation assets, and other power infrastructure
  • Monitoring oil-and-gas, mining, manufacturing, and data-center process systems
  • Rehearsing OT incident-response playbooks with safe process simulations
  • Supporting forensic reconstruction and safer containment decisions
  • Hardening defense-support and other mission-critical industrial facilities

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 10 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

SIGA OT Solutions may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies SIGA OT Solutions's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.