Ask most operations leaders what is connected to their control networks and you will get an estimate. Ask for a list with model numbers, firmware versions, locations and owners and you will often get silence. Yet every serious security activity, from patching to incident response to compliance, depends on knowing what you have.
The challenge in industrial environments is that the usual IT shortcut, running an automated scanner across the network, can be risky. Some older controllers and devices do not handle unexpected traffic well, and an aggressive scan has been known to cause equipment to fault or restart. So the inventory needs to be built carefully, favoring methods that do not disturb running processes.
What an OT asset inventory contains
At minimum, for each asset, record:
- A name or tag and a short description of what it does.
- Manufacturer, model and serial number.
- Firmware or software version, if known.
- Physical location and the process or area it supports.
- Network details: IP or other addresses, connection type, and the network segment.
- Who owns it operationally and who supports it, including vendor contacts.
- Remote access methods, including vendor modems.
- Criticality: what happens if it fails or is manipulated.
- Date last verified.
You do not need a perfect database on day one. A spreadsheet is a legitimate starting point.
Safe ways to gather the information
Start with paper and people
Collect what already exists: P&IDs, one-line diagrams, network drawings, purchase records, maintenance management system entries, vendor service contracts and commissioning documents. Then interview the technicians and operators who work with the equipment every day. They often know about the extra switch in the cabinet that nobody documented.
Walk the site
A physical walkdown remains one of the most reliable methods. Photograph cabinets and panels, note labels and model numbers, and trace cables to see what connects to what. Look for cellular modems, unmanaged switches, wireless access points and anything plugged in for a vendor and never removed.
Use passive network monitoring
Passive tools listen to network traffic by connecting to a mirror port on a switch, without sending anything to devices. They can identify devices, protocols and communication patterns without disturbing them. Many products designed for industrial networks work this way. Passive collection is often the best way to find what the paperwork missed.
Use active scanning only with great care
If active methods are needed, limit them to specific, tested targets, use gentle settings, and coordinate with operations during a maintenance window. Consult the vendor first for sensitive controllers. Never run a general-purpose vulnerability scan across a live control network without planning.
Organize the inventory around what matters
Not every asset deserves equal attention. Group them by process or area and rank by consequence. A controller that governs a safety or environmental function deserves more rigor than a monitoring display. This ranking will guide where you invest in segmentation, monitoring and patching.
Include the connections
Assets matter, but so do the paths between them. Draw a simple network diagram showing:
- Where the control network meets the business network.
- Remote access entry points.
- Wireless links.
- Connections to cloud services and vendor systems.
A basic diagram, even hand drawn, can reveal risks immediately.
Keep it current
An inventory that is out of date is nearly as bad as none. Build updates into existing processes.
- When equipment is installed or replaced, add or update the entry as part of commissioning.
- When a vendor visits, record any changes they made.
- Review high-criticality assets quarterly and the rest annually.
- Assign a named owner for the inventory.
Common mistakes
- Treating the inventory as a one-time IT project instead of an operational record.
- Scanning aggressively and causing the very outage you wanted to prevent.
- Ignoring "temporary" equipment that has been there for years.
- Failing to include vendor-managed devices.
Where to go from there
Once you have the inventory, many other steps become possible: segmenting networks, prioritizing patches, planning incident response and answering customer or regulatory questions with evidence rather than guesses.
Ironfield Cyber helps energy and industrial clients build inventories using safe, non-disruptive methods and turns the results into practical priorities. If you want a starting point, we can begin with a walkdown of one facility.