Why it comes first
- Risk assessment needs to know what could be compromised and what it controls.
- Segmentation needs to know what talks to what, on which protocol.
- Monitoring needs a baseline of normal to detect a change from.
- Incident response needs to know what a suspect device is and what happens if it is isolated.
- Regulators now ask for it by name: Australia's CIRMP rules expect material risks to be identified, which is impossible without an inventory, and India's CEA power sector regulations require a cyber asset register with ownership, hardware, firmware, software and patch state for every asset, reviewed every financial year.
How to discover assets without disturbing the process
Passive discovery listens. A network tap or a switch mirror port copies traffic to a collector that identifies devices from what they say: a controller answering Modbus, an HMI polling over DNP3, a relay speaking IEC 61850, an engineering workstation pushing a project. It touches nothing and it sees everything that communicates, but it is blind to devices that stay silent.
Active discovery asks. A controlled query to a device returns its model, firmware and configuration. Done carelessly on a control network it can knock a controller over. Done properly, with vendor-safe queries, one device at a time, in a maintenance window and with operations in the room, it fills the gaps passive discovery leaves.
The third source is people. Walk the plant with the engineers. The serial-connected device behind the panel, the vendor 4G router and the laptop that lives in the switchroom do not show up on the wire.
What a useful record holds
- Identity: make, model, serial, and the role it plays in the process.
- Software: firmware and application versions, and the patch state against the vendor's advisories.
- Location: site, area, cabinet, and the zone it belongs to.
- Ownership: who is responsible for it, and which vendor supports it.
- Communications: what it talks to, on which protocols and ports, in which direction.
- Consequence: what happens to safety, production and the environment if it fails or is misused.
Keeping it alive
An inventory that is right on the day it is delivered and wrong a month later is a snapshot, not a control. It stays alive when new assets are added at commissioning as a matter of procedure, when passive monitoring flags anything new on the wire, and when someone owns it. Our asset discovery and management service does the first pass and then keeps the register current with baselines and monitoring, so the next assessment starts from truth rather than from scratch.
- IEC 62443-2-1
- CEA (Cyber Security in Power Sector) Regulations, 2026, Reg 5(25)
- NIST SP 800-82 Rev 3





