Manufacturing Sector
66 articles covering manufacturing OT/ICS security
Johnson Controls Simplex Incident Manager: ICSA-26-232-01 Discloses Cleartext Credential Storage Flaw
CISA published ICSA-26-232-01 on August 20, 2026, disclosing CVE-2026-27875, a cleartext-storage-in-memory vulnerability in Johnson Controls Simplex Incident Manager, an emergency and life-safety incident coordination platform used across critical manufacturing, commercial facilities, transportation, energy, and government sites worldwide. This advisory covers the vulnerability, exploitation requirements, and mitigations.
CVSS 10.0: Unauthenticated Root Command Injection in Haiwell IoT Cloud HMI Gateway (CVE-2026-19188)
A maximum-severity OS command injection flaw in Haiwell's IoT Cloud HMI Gateway lets unauthenticated remote attackers execute arbitrary commands as root through a Socket.io ping-test feature. CISA advisory ICSA-26-225-02 details the flaw, its exposure across energy, water, and manufacturing deployments, and patch guidance.
CISA Advisory AA26-231A: Active Threat Actors Use AI-Generated Exploitation Scripts Against Siemens S7 Series PLCs
NSA, CISA, FBI, DOE, and EPA jointly warned on 19 August 2026 that threat actors are scanning for and probing internet-exposed Siemens S7-200 through S7-1500 controllers using AI-generated exploitation scripts disguised as monitoring tools, communicating over the S7comm protocol on TCP/102.
ICSA-25-352-07: Rockwell Micro800 Series IPv6 and CIP Fuzzing Flaws Enable Remote Denial of Service
CISA advisory ICSA-25-352-07 details two Rockwell Automation vulnerabilities -- CVE-2025-13823 and CVE-2025-13824 -- in Micro820, Micro850, and Micro870 controllers. Malformed IPv6 and CIP packets can drive the PLCs into recoverable or hard fault, halting control logic on machines and skid-level equipment across manufacturing and utility sites.
Phoenix Contact PLCnext and mGuard Security: CISA Advisory Roundup and Hardening Guide
Phoenix Contact is among the top five ICS vendors by CISA ICS-CERT advisory volume in 2026. Vulnerabilities span the PLCnext runtime environment, mGuard security routers, and WP 6xxx web panel HMIs — covering authentication bypass, remote code execution, cross-site scripting, and weak cryptography. This guide consolidates the advisory landscape and provides OT-specific hardening steps for each product family.
Digital Twin Security: How Virtual Replicas Expand the OT Attack Surface
Industrial digital twins — virtual replicas of physical assets, processes, and systems — are expanding rapidly across energy, manufacturing, and transport. They introduce new network connectivity, data aggregation risks, and attack vectors into OT environments that have historically been air-gapped or tightly isolated.
CISA AA26-097A: Iranian-Affiliated Actors Escalate PLC Exploitation Across Water, Energy, and Municipal OT
A July 2026 update to CISA advisory AA26-097A expands the confirmed scope of Iranian-affiliated PLC exploitation to Schneider Electric Modicon M340 and Siemens S7-1200 controllers, adding to the initial Rockwell Allen-Bradley targeting disclosed in April. Active exploitation of internet-facing PLCs is now confirmed across water, energy, and government facility sectors.
Siemens SIMATIC IoT2050 Advanced: Maximum-Severity Unauthenticated RCE in Industrial IoT Gateways
Siemens published a maximum-severity advisory in August 2026 Patch Tuesday covering a missing authentication vulnerability in SIMATIC IoT2050 Advanced devices. An unauthenticated remote attacker can execute arbitrary code with elevated privileges on the underlying server — a critical risk for IT/OT bridging deployments where these gateways connect operational technology networks to enterprise IT and cloud systems.
CVE-2026-59310 in OT Environments: Protecting Virtualised SCADA and Historian Infrastructure
VMware vCenter CVE-2026-59310 (CVSS 9.8, actively exploited) presents an acute risk in OT environments where virtualisation hosts historian servers, HMIs, engineering workstations, and SCADA applications. This advisory covers which OT components are most exposed, how vCenter compromise translates to OT network impact, and the OT-specific mitigations that reduce risk while patching proceeds.
Johnson Controls C·CURE 9000 RCE Vulnerability: ICSA-26-204-01 Advisory and Mitigation
CISA published ICSA-26-204-01 on August 11, 2026, disclosing CVE-2026-21655, a remotely exploitable code execution vulnerability in Johnson Controls C·CURE 9000 physical access control systems. With a CVSS score of 9.8 and no authentication required, the flaw affects C·CURE 9000 versions prior to 3.0.3 deployed in enterprise and critical infrastructure physical security management. This advisory covers the vulnerability details, affected versions, exploitation risk in OT-adjacent environments, and recommended mitigations.
Modbus and DNP3 Under Attack: Protocol Security and Detection for OT Networks
Modbus and DNP3 are the dominant SCADA communication protocols in energy, water, and manufacturing — and both were designed with zero authentication. This guide covers the specific attack techniques these protocols enable, real-world exploitation patterns from incident reports, and how OT security teams can add detection without disrupting production.
CISA ICS Advisories: August 2026 Roundup — Siemens, Honeywell, GE Vernova
CISA published multiple ICS security advisories in the first week of August 2026, covering critical vulnerabilities in Siemens SINEC NMS, Honeywell Experion PKS, and GE Vernova grid management systems. This roundup covers the disclosed vulnerabilities, affected product versions, CVSS scores, and recommended mitigations for OT security teams.
Beckhoff TwinCAT and EtherCAT Security: Attack Surface Analysis and Hardening Guide
Beckhoff TwinCAT is one of the most widely deployed PC-based control platforms in European industrial environments. This guide covers the EtherCAT network protocol attack surface, TwinCAT ADS communication security, known vulnerabilities, and practical hardening steps for OT engineers and security teams.
OT Endpoint Security: Deploying EDR and XDR in Industrial Environments Without Disrupting Control Systems
Deploying endpoint detection and response tools on OT assets — PLCs, HMIs, engineering workstations, historians — requires a different approach than IT EDR rollouts. Aggressive scanning, real-time interception, and performance overhead that are acceptable on IT endpoints can destabilise industrial control systems. This guide covers agent versus agentless approaches, deployment sequencing, and what OT-specific EDR products actually monitor.
Private 5G and LTE in OT Environments: Attack Surface and Security Architecture for Industrial Cellular
Manufacturers, utilities, and logistics operators are deploying private 5G and LTE networks to enable wireless OT connectivity for AGVs, robotics, sensors, and field devices. This guide covers the security architecture differences from Wi-Fi, the attack surface specific to industrial cellular, and hardening guidance for private cellular deployments.
AVEVA System Platform SCADA Security: Attack Surface, Vulnerabilities, and Hardening Guide
AVEVA System Platform (formerly Wonderware) is one of the most widely deployed SCADA and HMI platforms in industrial environments. This guide covers its attack surface, known vulnerability classes, and hardening practices for security teams and OT engineers.
ICSA-26-202-07: Rockwell FactoryTalk JWT Algorithm Confusion Allows Forged Authentication Tokens
CISA advisory ICSA-26-202-07 documents a JWT signature bypass in Rockwell Automation's FactoryTalk Services Platform 6.60. The vulnerability lets an attacker set the JWT algorithm to 'none' during Okta Web Authentication, forge tokens without a valid signature, and impersonate authorised users to access industrial system configurations. Patch is available.
OT Patch Management in Practice: A Field Guide for Industrial Control System Operators
Patching industrial control systems is categorically different from IT patching. Production constraints, vendor dependency, and long asset lifecycles make standard patch cadences unworkable. This guide covers compensating controls, vendor coordination, and a realistic patching process for OT environments.
PROFIBUS Protocol Security: Attack Surface Analysis and Hardening
PROFIBUS is one of the most widely deployed industrial fieldbus protocols, with an installed base spanning decades of manufacturing, chemical, and power generation facilities. Designed before network security was an operational priority, PROFIBUS has no authentication, no encryption, and a physical access model that assumes trusted environments. This guide covers the attack surface and hardening path.
Yokogawa CENTUM VP DCS: Security Vulnerabilities, Attack Surface, and Hardening
Yokogawa's CENTUM VP is one of the most widely deployed distributed control systems in oil and gas, chemical, and power generation. Its VNET/IP communication protocol, Exaopc OPC server, and Windows-based HIS workstations each carry documented security gaps. This guide covers the attack surface and hardening path.
AI Workflow Tools in OT Environments: The Attack Surface Industrial Operators Are Building Without Noticing
n8n, Langflow, and Node-RED are being adopted in industrial environments for AI-driven process analytics, predictive maintenance, and historian integration. The NadMesh botnet now specifically targets these tools. This creates a new attack path from exposed AI workflow interfaces to OT data historians and, in poorly segmented environments, to SCADA systems.
July 2026 ICS Patch Tuesday: Siemens CVSS 10 Auth Bypass, ABB and Rockwell Advisories
July 2026's ICS Patch Tuesday brought nine Siemens advisories including a CVSS 10.0 authentication bypass in Opencenter X, three ABB advisories, and a Rockwell advisory. Here's what OT/ICS security teams need to prioritise and the operational context for each critical finding.
OT Threat Hunting with Passive Network Monitoring: An ICS Practitioner Guide
OT threat hunting is fundamentally different from IT threat hunting — you can't run endpoint agents on PLCs, and active scanning can destabilise control systems. This guide covers passive network monitoring with Zeek and Suricata ICS decoders, OT-specific hunting hypotheses, and the protocol anomalies that separate legitimate traffic from attacker activity in industrial environments.
Nation-State Router Targeting at the OT Perimeter: Technical Response to CISA AA26-194A
CISA Advisory AA26-194A documents Russian FSB Center 16 exfiltrating router configurations from critical infrastructure globally via SNMP and Cisco Smart Install. For OT environments, perimeter routers hold additional sensitivity: they contain VPN configurations, routing to SCADA networks, and credentials that can enable lateral movement from IT into OT. This guide covers the OT-specific implications and hardening steps.
ICS Patch Tuesday July 2026: Siemens TIA Portal RCE, Schneider IGSS Critical, Rockwell 12 Advisories
July 2026 ICS Patch Tuesday brings a significant advisory load: Siemens releases 18 advisories including a critical TIA Portal remote code execution flaw, Schneider Electric addresses a critical IGSS SCADA vulnerability, and Rockwell Automation publishes 12 advisories covering FactoryTalk and Logix controllers. Prioritisation guidance for OT security teams.
IEC 62443 in Practice: Security Levels, Zone-Conduit Model, and Implementation for OT Practitioners
IEC 62443 is the international standard series for industrial automation and control system security. This practitioner guide covers the security level framework, the zone-conduit network architecture model, and what implementation actually looks like for OT security teams — from SL-1 baseline controls to SL-3 nation-state-resistant configurations.
MQTT Security in IIoT: Authentication, TLS, and Broker Hardening
MQTT is the dominant messaging protocol for Industrial IoT — used in energy monitoring, manufacturing telemetry, building automation, and smart grid applications. Its minimal design and widespread default configurations leave most deployments exposed to unauthenticated access, data interception, and command injection. This guide covers the attack surface and hardening approach.
U-Boot Vulnerabilities in Industrial Control Systems: Embedded Firmware Security in 2026
U-Boot is the dominant open-source bootloader for embedded Linux devices — including industrial routers, RTUs, PLCs, and SCADA components. Vulnerabilities in U-Boot's FIT image parsing and boot verification logic have direct implications for OT device firmware integrity and secure boot trust chains.
GhostLock CVE-2026-43499: Advisory for OT Environments Running Linux-Based Historian and SCADA Systems
The GhostLock Linux kernel vulnerability (CVE-2026-43499) enables local privilege escalation to root in approximately five seconds with 97% reliability. OT environments running Linux-based historian servers, OPC-UA gateways, and SCADA platforms are directly affected. Patching and mitigation guidance for industrial operators.
Modbus Protocol Security: Attack Surface, Exploitation, and OT Network Hardening
Modbus is the most widely deployed industrial protocol in the world — and one of the least secure. This guide covers the Modbus attack surface, documented exploitation techniques used against OT environments, and practical hardening measures for energy, water, and manufacturing defenders.
ICSA-26-181-02: FUXA SCADA CVE-2026-13207 -- Path Traversal to Unauthenticated RCE
ICS-CERT advisory ICSA-26-181-02 covers a dot-segment path normalization bypass in FUXA open-source SCADA software that allows unauthenticated remote code execution. CVSS v4 score 8.6. Deployments in water, energy, and manufacturing are exposed.
Manufacturing Execution Systems Security: Protecting the Overlooked Bridge Between IT and OT
Manufacturing Execution Systems sit at the boundary between enterprise IT and production floor OT, connecting SAP/ERP business systems to SCADA and PLC networks. They are routinely overlooked in OT security programs despite being a primary lateral movement path between the two domains. This guide covers the MES attack surface and practical security controls.
OT Incident Response: The First 48 Hours
When a cyber incident hits an operational technology environment, the first 48 hours determine whether a brief outage becomes a prolonged shutdown. This playbook covers the critical decisions, sequencing, and OT-specific considerations that IR teams need to get right from the first alert.
Emerson DeltaV DCS: Authentication Gaps, CISA Advisories, and Zero Trust Remediation
Emerson DeltaV is one of the most widely deployed distributed control systems in oil and gas, pharmaceutical, and chemical manufacturing. Legacy DeltaV communication protocols lack authentication, and multiple CISA advisories document workstation-level vulnerabilities. Here's the current security posture and what operators should do.
Siemens S7comm Protocol: Attack Surface, Unauthenticated Access, and OT Network Detection
S7comm is Siemens' proprietary PLC communication protocol. Legacy S7comm lacks authentication and encryption, enabling unauthenticated read/write access to process data and PLC control commands. This guide covers the attack surface, documented exploit techniques, and detection approaches for OT defenders.
CISA June 2026 ICS Advisories: Siemens WinCC and Rockwell RSLinx RCE
CISA released a batch of 10 ICS advisories on June 23, 2026, including critical vulnerabilities in Siemens WinCC Certificate Manager and SIPROTEC 5. Separately, ICSA-26-167-02 documents an unauthenticated stack-based buffer overflow in Rockwell Automation RSLinx Classic enabling remote code execution.
EtherNet/IP and CIP Security: Attack Surface, Vulnerabilities, and Hardening
EtherNet/IP is the dominant industrial Ethernet protocol in North American manufacturing, used in Allen-Bradley PLCs, robotics, and drive systems. This analysis covers the CIP protocol attack surface, known exploitation patterns, CIP Security extension adoption, and network hardening guidance.
OT Security in Pharmaceutical Manufacturing: Protecting GMP-Regulated SCADA and DCS Systems
Pharmaceutical manufacturing operates process control systems under FDA 21 CFR Part 11 and EU GMP Annex 11 regulatory frameworks that constrain patching and change management. This sector briefing covers the pharma OT attack surface and how to implement compensating controls without triggering costly revalidation.
Securing OT Remote Access: VPN, ZTNA, and Jump Server Architecture for Industrial Networks
Remote access to operational technology environments expanded dramatically during 2020-2022 and was never fully locked down. This guide covers the specific risks of each remote access pattern — vendor VPNs, site VPNs, jump servers, and ZTNA — and the hardening steps that reduce the attack surface without breaking the maintenance workflows OT teams depend on.
PIPEDREAM and COSMICENERGY: The ICS Malware Frameworks Built for Grid Disruption
PIPEDREAM (disclosed April 2022) and COSMICENERGY (May 2023) are the two most sophisticated ICS-targeting malware frameworks to emerge since TRITON. Both target industrial protocols used in power and energy infrastructure. This analysis covers their architecture, capabilities, and what they mean for defenders.
PROFINET Security: Attack Surface Analysis and Hardening for Industrial Ethernet Networks
PROFINET is the dominant real-time industrial Ethernet protocol in European manufacturing and process automation, with over 70 million installed nodes worldwide. This guide covers PROFINET's attack surface, documented exploits, network segmentation requirements, and hardening controls for OT security practitioners.
CISA ICS Advisory Roundup: Inductive Automation Ignition, ICONICS GENESIS64, and Mitsubishi Electric Vulnerabilities June 2026
CISA released nine ICS advisories in June 2026 covering critical and high-severity vulnerabilities in Inductive Automation Ignition, ICONICS/Mitsubishi GENESIS64, and Axis network cameras used in OT environments. This roundup covers the operational risk and remediation priorities.
Ransomware in OT Environments: How Manufacturing and Energy Operators Are Being Hit in 2026
Ransomware groups are no longer stopping at IT systems. This sector briefing covers how operators in manufacturing, energy, and water treatment are being targeted in 2026 — the specific OT attack vectors, operational impact patterns, and the defensive controls that matter most.
ICS Patch Tuesday June 2026: Critical Vulnerabilities in Siemens, Honeywell, and Mitsubishi Electric Products
The June 2026 ICS Patch Tuesday cycle brings critical and high-severity advisories affecting Siemens industrial networks, Honeywell building and process control systems, and Mitsubishi Electric PLCs. OT security teams should prioritise triage and remediation planning for affected assets.
OPC UA Security: Attack Surface Analysis and Hardening Recommendations for Industrial Environments
OPC Unified Architecture has become the dominant interoperability standard for industrial communication — and a consistent target in ICS-focused threat campaigns. This analysis covers the OPC UA threat model, documented vulnerability classes from recent CVEs, known exploitation by nation-state actors, and the hardening steps that reduce exposure without breaking operational continuity.
Advantech WebAccess/SCADA: Multiple High-Severity Vulnerabilities Enable Remote Code Execution
Advisories covering Advantech WebAccess/SCADA document path traversal, unrestricted file upload, and SQL injection vulnerabilities rated up to CVSS 8.8. WebAccess/SCADA is deployed across manufacturing, energy, and water treatment facilities globally. This analysis covers the vulnerability classes, exploitation paths, and immediate mitigations for OT operators.
Rockwell Automation ControlLogix and CompactLogix: Vulnerability Landscape and Hardening Guidance
Rockwell Automation's Logix family of programmable automation controllers has accumulated significant vulnerability history. This analysis covers key CVEs affecting ControlLogix and CompactLogix platforms, exploitation implications for industrial operations, and vendor-specific hardening steps.
Record 508 ICS Advisories in 2025: What the Vulnerability Surge Means for OT Defenders
Forescout's analysis of 2025 ICS security advisories identifies a record 508 advisories covering 2,155 vulnerabilities — with 82% rated high or critical. Field controllers, PLCs, and SCADA systems are the primary targets, and the growing share of advisories with no available patch creates an unresolvable exposure category that demands compensating controls.
CISA's Zero Trust Roadmap for OT: What the April 2026 Joint Guidance Means for Industrial Operators
CISA's April 2026 joint guidance 'Adapting Zero Trust Principles to Operational Technology' lays out a practical roadmap for applying zero trust in environments where the standard IT playbook doesn't work — legacy protocols, uptime requirements, and safety constraints included.
Iranian APT Groups Escalate Attacks on Internet-Exposed PLCs: Water, Energy and Government Under Threat
Since March 2026, Iranian-affiliated APT actors have been conducting disruptive attacks on internet-exposed programmable logic controllers across US critical infrastructure — particularly water/wastewater, energy, and government services. A joint advisory from CISA, FBI, NSA and US Cyber Command details the campaign and recommended mitigations.
Siemens May 2026 ICS Patch Tuesday: Device Takeover in Sentron Energy Meters, Root RCE in Ruggedcom, and 300+ Third-Party Flaws in CN4100
Siemens published 18 security advisories in May 2026's ICS Patch Tuesday, with critical findings in the Sentron 7KT PAC1261 energy data manager, Ruggedcom Rox, Simatic CN4100, and Opcenter RDnL manufacturing platform. This roundup covers the highest-impact advisories with operational guidance for affected sectors.
CISA ICS Advisory Roundup: Kaleris Navis N4, Delta Electronics CNCSoft, and ABB EIBPORT (May 2026)
CISA released eight ICS advisories and one medical device advisory on May 28, 2026, covering critical vulnerabilities in transportation management, CNC motion control, and industrial building automation systems. This analysis covers the highest-impact advisories and operational guidance for affected organisations.
Schneider Electric EcoStruxure Vulnerability Roundup: Critical Advisories Affecting Energy, Manufacturing, and Data Centre Operations
Schneider Electric has issued multiple CISA-coordinated advisories in 2026 covering critical vulnerabilities across the EcoStruxure platform suite -- including a CVSS 9.8 deserialization flaw in the Foxboro DCS Advisor, hard-coded credentials in Data Center Expert, and local RCE in Power Monitoring Expert.
CISA CI Fortify: What the New OT Isolation Guidance Means for Operational Technology Operators
CISA's CI Fortify initiative moves beyond standard patching guidance to address a harder problem: how critical infrastructure OT environments maintain operational continuity when internet, cloud, and telecom connectivity is severed during a geopolitical cyber crisis.
IEC 62443: The OT Security Standard Your Procurement Team Needs to Understand
IEC 62443 is the international standard series for industrial cybersecurity. This explainer covers the structure of the standard, what Security Levels mean in practice, the zones and conduits model, and how to reference 62443 in vendor contracts to actually improve your security posture.
CVE-2026-8153: Critical Command Injection in Universal Robots PolyScope 5 Exposes Cobot Fleets
A CVSS 9.8 OS command injection flaw in Universal Robots' PolyScope 5 Dashboard Server lets unauthenticated attackers seize control of collaborative robot controllers across manufacturing, automotive, and logistics environments. Patch to 5.25.1 immediately.
OT Threat Landscape 2026: New Dragos Groups, Shrinking Exploit Windows, and the Visibility Crisis
Dragos's 2026 OT cybersecurity year-in-review identifies 26 threat groups specifically targeting operational technology -- including three newly tracked groups -- as exploit timelines compress to 24 days and fewer than one in ten OT networks have active monitoring. A practical analysis for OT security practitioners.
Default Credentials, Internet-Exposed PLCs, and the Unsophisticated Actor Problem
CISA's April 2026 joint advisory warns of Iranian-affiliated actors targeting internet-facing PLCs with basic techniques. The Poland energy attack demonstrated the real-world consequences. This analysis covers the threat, affected protocols, and what operators must do now.
CISA ICS Advisory Bundle: WAGO PFC, AVEVA Plant SCADA, and Beckhoff TwinCAT Vulnerabilities
CISA released seven ICS advisories on May 21, 2026, covering authentication and remote code execution vulnerabilities in WAGO PFC controllers, AVEVA Plant SCADA (formerly Citect), and Beckhoff TwinCAT runtime. Together these advisories affect PLC, SCADA, and automation runtime platforms deployed across manufacturing, energy, and building automation sectors globally.
Honeywell Experion PKS and C300 Controller Vulnerabilities: RCE Risk in Process DCS
Multiple vulnerabilities in Honeywell's Experion Process Knowledge System and C300 controller affect distributed control systems in oil and gas, petrochemical, and chemical processing facilities. Chained, the flaws provide an unauthenticated path from network access to code execution on the C300 controller's real-time OS, with potential to disrupt or manipulate industrial processes.
NIS2 OT Compliance: What the 2026 Enforcement Wave Means for Industrial Operators
EU member states are now issuing the first formal NIS2 enforcement actions against operators of essential services. Industrial operators — energy utilities, water authorities, manufacturing firms, and transport operators — face binding cybersecurity obligations, supply chain security requirements, and 24-hour incident reporting duties that the prior NIS1 regime did not meaningfully enforce. What actually changed and what OT teams need to do.
CISA Advisory: ABB AC500 PLC Remote Code Execution in Manufacturing and Process Control
CISA has issued an advisory covering a critical remote code execution vulnerability in ABB's AC500 PLC series, one of the most widely deployed programmable logic controller families in European manufacturing, paper and pulp, food processing, and water infrastructure. The flaw affects the Modbus TCP server component and requires no authentication to exploit.
CISA ICS Advisory: Siemens RUGGEDCOM and SCADABr Remote Code Execution
CISA has released a critical ICS advisory covering unauthenticated remote code execution vulnerabilities in Siemens RUGGEDCOM network devices and SCADABr SCADA software, both widely deployed in energy and manufacturing environments.
Claroty 2026 State of XIoT Security: OT Vulnerability Disclosures Hit New High
Claroty's annual State of XIoT Security report documents record-high vulnerability disclosures across operational technology, IoT, and connected medical devices. OT vulnerabilities now account for the majority of disclosed flaws, with critical infrastructure sectors facing compounded exposure from legacy device lifecycles and the accelerating advisory pace.
OT Network Segmentation: Purdue Model, DMZ Design, and Historian Isolation
A practical guide to network segmentation in OT environments, covering the Purdue Reference Model, industrial DMZ architecture, data historian isolation, and the tradeoffs between operational access and security posture.
The OT Asset Inventory Problem: Visibility Gaps, Passive Discovery, and Unmanaged Devices
Most industrial operators cannot accurately enumerate the devices on their OT networks. This visibility gap is the foundational barrier to OT security -- you cannot protect what you cannot see. A practical look at passive discovery tools, the limits of vendor inventories, and strategies for building actionable asset visibility.