Site: anonymized process + packaging complex
Method: passive network listening + walkdown correlation (no active scans on live control VLANs)
Recorder: OT reliability / controls liaison
Purpose: build a defensible asset inventory before anyone promises “segmentation next quarter”
This is a discovery log, not a framework white paper. If you wanted NIS2 theater, stop here.
Day 0 — Charter (before packets)
We wrote three rules on the whiteboard:
- No active scans on Level 0–1 during production.
- Every “unknown” MAC stays unknown until a human sees the cabinet.
- Inventory is not a spreadsheet hero project—it is a living CMDB with owners.
Without those rules, Day 1 becomes a ping storm and a near-miss.
Day 1 — Listen first
Passive taps on the OT SPAN showed more talkers than the official list. Controllers we expected. Engineering laptops we feared. A serial-to-Ethernet brick nobody had claimed since 2019.
| Finding | Official list | Passive hear | Disposition | | --- | --- | --- | --- | | PLC family A | 14 | 14 | Match | | HMI panels | 9 | 11 | Two “temporary” still live | | Protocol converters | 2 | 5 | Three orphaned | | Unknown MACs | 0 | 17 | Walkdown queue |

If it talks, it exists—whether your CMDB agrees or not.
Day 2 — Cabinets do not lie (people do)
Walkdown against the unknown list. Two “decommissioned” VFDs still on the bus. One safety PLC clone in a spare rack powered for “backup firmware.” A vendor cellular modem zip-tied behind a panel with a faded SIM note from a turnaround.
Lesson logged: decommission without power removal is fiction.
Day 3 — Firmware is a field, not a rumor
We stopped accepting “about version 12.” Each controller earned a firmware string from the engineering workstation export or faceplate—never from memory. Three units were past OEM support and still on the critical path.
Obsolescence joined the inventory columns the same day: firmware, support_end, spare_board_qty.
Day 4 — Conduits, not vibes
We sketched who talks to whom—not for a pretty Purdue poster, but to mark conduits that would matter for future segmentation. Level 3 historian collectors speaking into two plants’ Level 2 was the uncomfortable drawing.

A conduit sketch beats a slide that says ‘zero trust’ and names nothing.
Day 5 — Remote access honesty
Jump hosts, vendor VPNs, and “temporary” TeamViewer-class paths (whatever the brand) were inventoried as assets with owners and expiry. Two paths had no expiry. One had an owner who left the company.
Rule added: remote path without expiry date = open finding.
Day 6 — Correlate to safety and quality
Not every MAC is equal. We tagged assets that touch SIS interfaces, batch release, or custody transfer. Inventory priority followed consequence, not alphabet.
Day 7 — Freeze v0.9 and name an owner
We published inventory v0.9 with:
- Asset ID, location, role, firmware, last seen, owner, criticality
- Unknowns listed as unknowns (not deleted to look clean)
- A weekly “new talker” review owned by one named person
Without that owner, Day 8 returns the plant to folklore.
What this log refuses
- Active scanning as default discovery on live loops
- Equating “we bought a detection box” with “we have inventory”
- Mixing IT laptop CMDB hygiene with Level 0 I/O truth
- Promising agentic AI on tags you cannot name
Adjacent fences
OT cybersecurity overviews own policy and zoning philosophy. Historian tag data quality owns bad points and naming sin inside historians. OT semantic catalogs own meaning for AI action. Alarm management owns rationalization. None of them own passive discovery cadence and cabinet-correlated asset truth. Do not buy a SOC playbook and expect to know which converter is still powered.
Close
You cannot segment, patch, or safely automate what you cannot name. Seven days of listening and walking will not finish the job—but they will end the fantasy that the official list was ever the plant.
