ServingNew York, New Jersey, and Connecticut
24/7 incident response1-800-868-8189Contact GDF

Field note / operational technology

Passive-first discovery is a coverage discipline

The sensor sees traffic at its collection point. It does not automatically see dormant assets, isolated cells, serial links, or the process consequence behind a controller.

OT and SCADA security architecture showing enterprise, operations, control, process, and safety boundaries
Passive coverage is reconciled against engineering records, operator knowledge, and known blind spots.

Passive observation is a sound starting point in OT because active probing can create unnecessary risk for fragile or poorly documented systems. It still requires engineering. Life safety, environmental protection, and stable operation govern the collection plan. Sensor placement, operating state, protocol visibility, and reconciliation determine whether the resulting inventory can support security decisions. Any active follow-up requires operator-designated authority, reviewed process conditions, stop points, and recovery steps.

Document what each sensor can and cannot see

A capture at the IT/OT boundary may show historian and remote-access traffic while missing controller-to-HMI communication inside a cell. A trunk sensor may miss isolated switches, maintenance connections, serial gateways, cellular paths, and assets that communicate only during a batch or failover. Record collection points, span configuration, start and stop time, packet loss, encrypted sessions, and operating modes observed.

Reconcile network observations with engineering truth

Compare observed addresses and fingerprints with controller projects, HMI configurations, switch tables, firewall objects, network drawings, asset registers, maintenance platforms, backup repositories, purchase records, and operator knowledge. Conflicts are work items, not rows to overwrite. Preserve both values and the basis for resolution.

  • Vendor, model, firmware, protocol, address, and zone
  • Process function, safety relevance, and operational owner
  • Expected peers, remote path, and maintenance method
  • Backup, restore, replacement, and vendor-support status
  • Observation source, confidence, and last validation date

Make the inventory support a decision

A useful inventory can identify unsupported systems, unexpected communication, unmanaged vendor access, weak recovery points, and high-consequence assets. Feed those findings into architecture, segmentation, monitoring, vulnerability, and capital planning. Establish a change and reconciliation cycle so the baseline does not become another stale spreadsheet.

Primary and public sources

Assess OT inventory coverage

Describe the work, the deadline, and the people authorized to act. Do not send evidence through the public form.

Contact GDF