Accurate OT asset register: passive discovery, manual verification, live updates.
OT Asset Inventory delivers a complete listing of controllers, PLCs, HMIs, sensors and other ICS devices in your network. We combine passive monitoring and active scanning, without disrupting production, to generate an accurate asset database.
A reliable inventory is the cornerstone of risk assessments, obsolescence planning and effective maintenance scheduling, ensuring operational continuity and security.
Accurate asset management and lifecycle tracking
Reduced maintenance windows and unexpected outages
Strengthened OT security, no unknown devices lurking
Transparent budgeting and CAPEX planning
Seamless regulatory and audit compliance
Optimized resource utilization and waste reduction
Set technical and organizational boundaries.
Standards-aligned, OT-specific evaluation.
Executive and technical documentation.
This service is particularly valuable in the sectors below, due to their specific regulations, asset base and threat models.
An asset inventory is the precondition for all other OT security work. We work passively: discovery happens without disturbing the network, because active scanning can knock over an older controller.
We place a SPAN port or network TAP on key switches. The device only listens and sends not a single packet onto the network.
From the traffic we identify vendor, model, firmware version and protocols spoken through protocol analysis. Typically 2-4 weeks of observation yields the full picture.
We record who talks to whom in normal operation, over which protocol and at what cadence. This becomes the baseline for later anomaly detection and the segmentation design.
Devices not visible passively are added through a site walkthrough and existing documentation, then the list is reviewed with the plant engineers.
At the start of an OT project these questions get asked, and without an asset inventory none of them has an answer.
| Question | What the inventory adds | What it enables next |
|---|---|---|
| How many devices are on the network? | Exact counts by type | Licence and project planning |
| Which are vulnerable? | Firmware version and CVE matching | Vulnerability management plan |
| What talks to what? | Communication matrix | Firewall rules, segmentation |
| Who reaches in from outside? | Remote access paths | Access management, MFA |
| What is out of vendor support? | Lifecycle status | Replacement plan, compensating controls |
| What is normal operation? | Traffic baseline | Anomaly detection |
No. We work exclusively passively: information is read from traffic mirroring (SPAN port or network TAP) and we send not a single packet onto the network. This matters because a standard active network scanner is capable of knocking over an older PLC purely by sending it unexpected packets. Installing the TAP is the only physical intervention, and it happens in the switch cabinet without touching the process.
The observation phase is typically 2-4 weeks: that is how long it takes for rarely communicating devices and weekly or monthly cycle processes to appear. Add setup (1-3 days) and analysis (1-2 weeks). For a mid-sized plant the full turnaround is 5-7 weeks. Shorter observation still gives a usable picture, but rare events will be missing from it.
In our experience there is always a gap between documentation and reality, and typically not a small one. The most common discoveries: devices left over from a project years ago that nobody operates, an undocumented supplier VPN connection, and a direct path between the office network and a controller. Passive discovery shows what actually runs, not what ought to.
Three things immediately. One: vulnerability matching reveals which devices need compensating controls. Two: the communication matrix lets you write firewall rules without blocking traffic blindly. Three: anomalies become measurable against the baseline, so it also underpins continuous monitoring. The inventory needs maintaining, so the handover includes the update regime.
The common industrial protocols: Modbus TCP, S7comm and S7comm-plus, EtherNet/IP and CIP, PROFINET, DNP3, IEC 61850, BACnet, OPC UA. Beyond these we also analyse general network traffic, because IT/OT crossings often show up there. If the environment contains a bespoke or rare protocol, we clarify that at the start of the assessment.