Minas Tirith - Charcoal

Minas Tirith - Charcoal

TL;DR

Context & Stakes

Most manufacturing environments still run on tribal knowledge.
Ask for the list of PLCs, HMIs, firmware versions, or who has admin rights, and you’ll often get the same answer: “Peter knows that.”

This is not an edge case, it’s the norm. Here is what many plants lack:

At the same time, regulatory pressure is rising fast:

And then there’s the operational reality:

Without visibility, you can’t secure or sustain production. And without sustained production, nothing else matters.

What Good Looks Like

An effective OT discovery program produces:

When plants reach this state, uptime, safety, and troubleshooting will all improve immediately.

Practical Path

Based on your maturity model you should utilize Crawl - Walk - Run approach.

Crawl: Build Visibility

Goal: “What do we actually have?”

Walk: Turn Findings Into Security

Goal: “What matters most and how do we protect it?”

Run: Operationalize & Mature

Goal: “How do we stay secure without slowing down production?”

Trade‑Offs & Gotchas

Manual discovery becomes obsolete in weeks

Plants tend to change, new vendor panels, replaced PLCs, reconfigured lines. Excel dies on day one.

Active scanning can break devices

Legacy equipment can’t handle port scans, SMB probes, or anything intrusive. This is why passive tools dominate OT.

Tools without process = zero value

Asset discovery is not a silver bullet.
It must integrate with:

KPIs: What to Measure

These KPIs reinforce both cyber and operational value.

Conclusion

Asset discovery is no longer a “nice to have”, it is the first domino in modern OT security and regulatory compliance.
You can’t segment, you can’t respond, you can’t protect, and you certainly can’t comply with NIS2 or CRA unless you know:

Visibility is uptime. Visibility is safety. Visibility is compliance.