Building an OT Asset Inventory When You Have No Budget

You cannot protect industrial equipment you do not know you have. Here is a practical way to build an OT asset inventory using walkdowns and simple tools.

3 min readBy Ironfield Cyber Team

Ask a plant manager, a pipeline operations lead or a utility superintendent how many networked devices run their process, and you will often get a confident answer that turns out to be wrong. Controllers were installed by a contractor ten years ago, a vendor added a remote modem for support, and a few devices were swapped without anyone updating a list.

Every serious framework for industrial security starts in the same place: know what you have. NIST CSF 2.0 and ISA/IEC 62443 both put asset knowledge at the foundation, and CISA guidance for operational technology says the same. This post describes a way to build that inventory in a few weeks with modest resources.

Why the inventory comes first

Without an inventory you cannot answer basic questions during an incident. Which controllers talk to the corporate network? Which devices run unsupported software? Who has remote access to the compressor station? An inventory also lets you prioritize, because a spare pump controller and a safety system are not equal risks.

Step 1: Set the boundary

Decide what is in scope. Start with one site, one unit or one pipeline segment. A small, finished inventory beats an ambitious one that stalls. Involve operations from the beginning, since they know the equipment better than IT does.

Step 2: Do a physical walkdown

Walk the site with a camera, a notepad or a tablet and a person from operations. Record for each device:

  • Type and function, such as PLC, RTU, HMI, drive, gateway or camera
  • Manufacturer and model
  • Location and the process it supports
  • Firmware or software version if visible
  • How it connects, such as Ethernet, serial, cellular or radio
  • Who supports it, internal or vendor

Photos of labels and cabinet interiors help later. Do not touch or change anything during the walkdown.

Step 3: Review drawings and vendor records

Compare the walkdown to network diagrams, project documentation, vendor support contracts and purchase records. Gaps between paper and reality are the most valuable findings.

Step 4: Capture network information carefully

This step needs care. Active scanning of industrial networks can disrupt fragile devices. Prefer passive methods, such as reviewing switch configurations, address tables and traffic captured from a mirror port, and use specialized OT monitoring tools when you have them. Never run a general-purpose scanner against live controllers without the plant's agreement and a plan.

Step 5: Record connections to the outside

Pay special attention to every path that leads out of the process network:

  • Links to the corporate IT network
  • Vendor remote access, including modems and cloud portals
  • Cellular gateways and radios
  • Wireless access points
  • USB and laptop connections used by technicians

These paths are where many real-world incidents begin.

Step 6: Classify and prioritize

Add two columns to your spreadsheet: how important the asset is to safe, continuous operation, and how exposed it is. A critical device that is reachable from the corporate network deserves attention before an isolated, low-value one. This simple ranking drives your first round of improvements.

Step 7: Assign owners and keep it current

Each asset needs a named owner and a review date. Add inventory updates to your change management process so that new equipment gets recorded at installation, and schedule a walkdown at least once a year.

What to do with the results

Use the inventory to take quick, safe actions:

  1. Remove or disable unused remote access paths.
  2. Change default passwords where the vendor permits.
  3. Segment obvious high-risk connections.
  4. Make a list of unsupported devices and plan their replacement.
  5. Confirm backups of controller programs and configurations exist and are stored safely.

A note on safety culture

Operations teams rightly worry that IT interference could affect safety and uptime. Frame the project as supporting reliability. Agree up front that no change happens without operator approval.

How Ironfield Cyber helps

Ironfield Cyber offers OT security awareness and assessment support for energy services firms, contractors with industrial equipment and small utilities. We can help plan a low-risk inventory with your operations staff and turn the findings into a prioritized improvement list.