Key Takeaways
- The new agentless DXM module monitors device configurations against operational and security baselines and automatically remediates unauthorized changes.
- New integrations span cyber-physical systems (CPS) security, building management, physical security, and enterprise workflow ecosystems.
- DXM is scheduled for release in Q4 2026 as part of the broader action platform.
Viakoo introduced Device Configuration Manager (DXM) at Black Hat USA 2026, an agentless module designed to detect and remediate configuration drift across operational technology and Internet of Things environments. Scheduled for availability in Q4 2026, DXM will integrate directly into the company's broader action platform.
Configuration drift occurs when a device's settings move away from an approved security or operational baseline. This drift often stems from maintenance work, manual errors, inconsistent updates, unauthorized changes, or hardware restored with outdated settings. While one deviation may appear minor, unchecked baseline variations across thousands of cameras, sensors, controllers, and building systems create specific risks, including unauthorized network access and localized system failures.
DXM monitors OT and IoT devices against defined baselines and automatically remediates unauthorized changes. Its agentless design accommodates connected devices that cannot support conventional endpoint agents. Many of these endpoints feature limited processing capacity, run proprietary operating systems, or operate in environments where installing additional software could disrupt critical processes.
Asset discovery only addresses initial visibility. Knowing that a device exists does not indicate whether its configuration changed after maintenance, whether a disabled service was reactivated, or whether security settings still match established policies. Viakoo addresses this operational gap by shifting the focus from baseline visibility toward ongoing, automated correction.
The exposure footprint across connected environments is substantial. Forescout reported that its analysis of nearly 19 million devices found 33% of IoT hardware carried an active vulnerability. While vulnerability management and configuration management remain distinct disciplines, they are closely connected. An unpatched device with weak or inconsistent settings expands the attack surface, particularly when fleets span multiple manufacturers and business units.
Industry guidance supports the emphasis on persistent management. NIST SP 800-82 Rev. 3 explains that OT security differs from conventional IT security because safety, reliability, and availability constraints shape how controls can be deployed. CISA guidance for connected environments emphasizes asset visibility, secure configuration, and sustained device management. Furthermore, IEC 62443 provides standard requirements covering industrial automation systems, components, and secure development practices.
Automated remediation in OT environments requires distinct operational workflows. A configuration that appears anomalous from a security perspective may actually support a critical operational process. Organizations implementing configuration management tools require clear approval controls, audit trails, rollback options, and maintenance-window support. Baselines also demand shared ownership; while security teams define policy, operations and engineering personnel understand which settings directly affect safety or production.
The company also expanded its partner ecosystem, stating its integrations now include 5 of the 7 top performers in Gartner's 2026 CPS Protection Platform Magic Quadrant. Named integrations include Armis, Forescout, Nozomi Networks, and Claroty. This overlap reflects a broader market direction: CPS protection platforms identify devices and risks, while specialized remediation products automate the follow-through after an issue is discovered.
Additional partnerships with Johnson Controls, Axis Communications, and Honeywell extend the platform's reach into building controls, physical security, and industrial device environments. Availability through the ServiceNow Marketplace enables enterprises to connect device remediation with established incident, change, and workflow processes. This linkage addresses a common deployment barrier: cyber hygiene work often stalls not because a problem is invisible, but because ownership and execution remain fragmented across disparate teams.
At the board level, a former senior vice president of Americas sales at Palo Alto Networks recently joined the company's advisory board. This appointment points to broader commercial ambitions as OT and IoT security spending shifts beyond initial asset discovery toward continuous, measurable remediation.
For buyers, the practical test arrives upon the module's scheduled Q4 2026 release. The technology must demonstrate that automated configuration correction scales across heterogeneous device fleets without creating operational disruption. If successful, this approach provides a mechanism to close the gap between identifying device risk and completing the remediation lifecycle.
โฌ๏ธ