Automation Glossary • OT Asset Inventory

What Is an OT Asset Inventory?

Merobix Engineering • • 7 min read

An OT asset inventory is a complete, maintained record of every device on an operational technology network - what it is, where it is, how it connects, and what software it runs. It is the least glamorous and most foundational of security controls, because every other protection depends on it: you cannot secure, patch, segment, or monitor a device you do not know exists. This guide explains what an OT asset inventory contains, why the principle that you cannot protect what you cannot see makes it the starting point for OT security, and how it differs from a one-time audit.

Back to Blog

OT Asset Inventory in one line: An OT asset inventory is an accurate, continuously maintained list of all hardware and software assets on an industrial control network, including controllers, HMIs, network devices, instruments, their firmware and software versions, and how they communicate. It is considered the foundational security control because every subsequent control - vulnerability management, segmentation, patching, monitoring - depends on knowing what exists. The guiding principle is simple: you cannot protect, or even assess the risk of, an asset you are unaware of.

Why You Cannot Protect What You Cannot See

Every security activity implicitly assumes you know what you are securing. You cannot patch a device whose existence you have forgotten, apply a firewall policy to a system you did not know was on the network, or investigate anomalous behavior from an asset you cannot identify. An unknown device is a blind spot in every one of those controls at once - it is unpatched by default, ungoverned by policy, and invisible to monitoring. This is why the asset inventory is placed first among security controls: it is the precondition for all the others being complete.

OT networks are especially prone to unknown assets. They accumulate equipment over decades, from many vendors, installed by different integrators and contractors, often with poor documentation. Devices get added during a project and never recorded, temporary connections become permanent, and spare or legacy equipment lingers on the network. The result is that many operations genuinely do not have a full picture of what is connected, and the gaps are exactly where risk hides - an unmanaged, unpatched device nobody remembers is a favorite foothold for an attacker.

The inventory also underpins risk assessment itself. To judge how exposed an operation is, you have to know how many devices run vulnerable firmware, how many use unsupported operating systems, and how the network is actually connected - and all of that comes from the inventory. Without it, a risk assessment is guesswork over an unknown population. With it, the same assessment becomes a concrete accounting of specific devices and specific weaknesses, which is the difference between a defensible security posture and a hopeful one.

What a Good Inventory Actually Contains

A useful OT asset inventory goes well beyond a list of device names. For each asset it captures identity and type - what the device is and what it does - along with its make and model, its firmware or software versions, its network identifiers and how it connects, and its physical location. The software and version detail is what makes the inventory actionable for security: knowing a controller runs a particular firmware version is what lets you match it against known vulnerabilities and decide whether it needs attention.

The relationships between assets matter as much as the assets themselves. Knowing which devices communicate with which others, and across which network boundaries, turns a flat list into a picture of the network that supports segmentation and anomaly detection. An inventory that records these communication relationships lets you see whether the real traffic matches the intended design, and it gives monitoring a baseline of normal to compare against - traffic to or from a device that should not be talking to anything is only recognizable as unusual if you knew what usual looked like.

Building an inventory in OT requires care because the devices are sensitive. Aggressive active scanning that works fine on an IT network can disrupt fragile control-system equipment, so OT asset discovery often leans on passive methods that observe network traffic to identify devices without probing them, supplemented by careful active queries and by configuration records where scanning is too risky. The goal is completeness without disturbing the process, which is a genuine constraint that shapes how the inventory is gathered.

Asset Inventory in SCADA and Cloud Monitoring

For SCADA operations spread across many remote sites, the asset inventory is what makes the whole estate governable rather than a collection of half-remembered installations. A distributed oil and gas operation may have RTUs, gateways, flow computers, and instruments across dozens or hundreds of locations, and the inventory is the single source of truth for what is deployed where. It is what lets an operator answer basic but critical questions - which sites run a device with a newly disclosed vulnerability, which firmware versions are in the field, which assets are approaching end of support.

A cloud SCADA platform such as Merobix contributes to this visibility as a natural byproduct of connecting the field. Because sites report in to a central system, the platform inherently knows which gateways and devices are online, which have gone quiet, and how they are configured, which feeds and cross-checks the formal asset inventory. Connectivity and inventory reinforce each other: the monitoring system reveals what is actually communicating, and the inventory records what is supposed to be there, and comparing the two surfaces both rogue devices and assets that have silently dropped off.

The distinction from a one-time audit is the crucial one for keeping an inventory useful. A self-audit checklist or a point-in-time survey captures a snapshot that starts going stale the moment a new device is added or an old one is swapped, and a stale inventory quietly regains all the blind spots it was meant to remove. A genuine asset inventory is a living record, updated as assets change, so that the picture of the network stays true over time. That ongoing accuracy is what separates an inventory as a security control from an inventory as a document that once existed.

Frequently Asked Questions

Why is an asset inventory called the foundational security control?

Because every other control depends on it. You cannot patch, segment, apply a firewall policy to, or monitor a device you do not know exists, so an unknown asset is a blind spot in all of those controls at once. Knowing exactly what is on the network is the precondition for every subsequent protection being complete, which is why the inventory is placed first and captured in the principle that you cannot protect what you cannot see.

How is an OT asset inventory different from a security audit or checklist?

A self-audit or checklist captures a point-in-time snapshot that starts going stale as soon as a device is added, swapped, or removed, and a stale record quietly regains the blind spots it was meant to eliminate. An asset inventory is a living record that is updated as assets change, so the picture of the network stays accurate over time. That ongoing accuracy is what makes it a working security control rather than a document that was true once.

How is an OT asset inventory built without disrupting the process?

Aggressive active scanning that is routine on IT networks can crash fragile control-system devices, so OT asset discovery often relies on passive methods that identify devices by observing network traffic without probing them. These are supplemented by careful, limited active queries and by existing configuration records where scanning would be too risky. The aim is a complete inventory gathered without disturbing the equipment that runs the process.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Passive vs Active Discovery  •  Jump Host / Bastion Host  •  Unidirectional Gateway  •  Patch Management in OT  •  Virtual Patching  •  Configuration Baseline / Hardening  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →