Skip to content

Cybersecurity

How to Achieve Complete OT/ICS Asset Visibility

A hands-on guide to building a complete OT/ICS asset inventory: sensors, passive and active discovery, DPI and behavioral baselines without stopping production.

2 min read
Industrial network diagram with sensors mapping PLCs, HMIs and OT devices across the levels of the Purdue model

Knowing that asset visibility is the foundation of OT security is one thing. Actually achieving it, in a plant with thousands of devices from dozens of different vendors, is another. This article does not discuss the why: it focuses on the how, with an operational path for building and maintaining a reliable inventory without putting production continuity at risk.

Start with the right sensors, at the right levels

A single collection point is not enough. The industrial network extends from PLCs and field devices up to the IT levels, and each segment requires a different approach:

  • Network sensors for passive traffic observation on the main segments.
  • Wireless sensors to intercept Wi-Fi, Bluetooth, Zigbee and LoRaWAN, often the most overlooked blind spot.
  • Lightweight endpoint sensors on workstations and process servers.
  • Embedded sensors close to PLCs and low-level devices, where East-West traffic would otherwise stay invisible.

The rule of thumb: the further you go down toward the field, the more you need a dedicated probe, because the lower Purdue levels do not produce traffic that climbs spontaneously all the way up to central monitoring.

Combine three discovery modes

Relying on a single method always leaves gaps. The three approaches should be used together:

  1. Passive discovery. Listens to traffic without interacting with devices. It is safe by definition, but it does not see silent or standby assets.
  2. Active discovery (smart polling). Targets the devices that the passive mode cannot profile with focused queries. It must be calibrated carefully: slow, targeted queries compatible with industrial protocols, so as not to overload equipment designed for deterministic cycles.
  3. Integrations with existing systems. Active Directory, EDR, CMDB and ticketing enrich the inventory with data that the network alone does not expose.

Passive discovery on its own is the first typical mistake: dormant devices, maintenance assets and equipment powered on only during certain phases of the cycle stay out of the inventory until someone queries them.

Deep Packet Inspection and protocol coverage

Identifying an IP address is not identifying an asset. You need Deep Packet Inspection of industrial protocols (Modbus, Profibus, DNP3, EtherNet/IP and many others) to understand what each device is, which firmware it runs and who it communicates with. The depth of protocol coverage is what separates a list of addresses from a real map of device-to-device relationships.

From the map to the behavioral baseline

Once the assets and their communications are known, the next step is to establish what is "normal". A learning phase builds the profile of legitimate communications; from there, monitoring flags deviations: a new flow to a PLC, an unexpected write command, a device that appears where it should not.

This is where the MON5 angle becomes concrete. The platform does not merely list assets: it correlates vulnerabilities with the real context of the plant, so a CVE carries weight for its actual exposure and not in the abstract. Anomaly monitoring is passive by principle, designed not to interfere with production cycles and to prioritize what really matters.

Keeping the inventory alive

An inventory is only useful if it stays current. That is why it pays to:

  • Automate discovery and classification instead of relying on manual spreadsheets, which age from the day they are compiled.
  • Enrich the data with external intelligence to improve the accuracy of model and firmware classification.
  • Periodically review sensor coverage, because every new line, supplier or maintenance activity introduces assets that were not there before.

In summary

Complete visibility comes from combining multi-level sensors, passive and active discovery, DPI of OT protocols and behavioral baselines, all automated and maintained over time. Done well, the inventory stops being a compliance exercise and becomes the foundation on which segmentation, vulnerability management and incident response rest.

Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.

OTICSasset visibilitydeep packet inspectionanomaly detection

Related articles

Comparison of OT monitoring platforms on an ICS network with evaluation criteria side by side

Cybersecurity

What Is the Best OT Cybersecurity Platform for ICS Networks? Selection Criteria

There is no single best OT cybersecurity platform — there is the right one for your ICS network, your protocols, and your maturity level. Concrete criteria for choosing without being guided by marketing.

4 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna