The factory assets nobody knows are there
A building materials manufacturer believed one section of its plant contained around 3,000 connected assets. Within minutes of deploying automated asset discovery, the number had passed 15,000. The gap was not created by a sudden influx of new equipment. Those assets were already there. What changed was the manufacturer’s ability to see them.
For Andrea Carcano, co-founder and CEO of Nozomi Networks, an industrial cybersecurity company focused on OT and IoT environments, that discovery captures one of the most persistent problems in manufacturing security. Plants have become more connected, but security teams do not always have an equally complete picture of what those connections have created.
“Companies usually approach us because they have zero visibility or very limited visibility of what they have in the network,” he says. “Installing this kind of technology is like turning on the lights in a dark room. Suddenly you start to see things you did not expect. Once the light is on, you then have a journey to fix what you discover, and depending on the findings that journey can take years.”
That journey matters because asset discovery is not a one-off inventory exercise. A factory may know that a device exists without understanding whether its firmware is vulnerable, how it normally communicates or whether its behavior has changed. As manufacturers connect more operational technology to IT systems and introduce industrial AI, the security question is shifting from simply identifying devices to understanding what they are doing.
Seeing an asset is only the beginning
Knowing that an IP address exists is useful, but it says little about the level of risk attached to the equipment behind it. Carcano argues that useful visibility needs to become progressively richer, moving from basic network identity into the protocols being used and, where possible, information such as device model and firmware.
He compares the process with securing a house. “The first thing you want to know is how many windows and doors you have. That is the IP level. But it makes a big difference whether that door is a modern security door, or something built 50 years ago. When you understand what type of equipment you have and the firmware version, you can identify the vulnerabilities associated with it and decide where to invest to reduce risk.”
This becomes particularly important in factories because identifying a vulnerability does not mean it can simply be patched. Production equipment may have been running reliably for decades; replacement may be impractical and a firmware update can itself introduce operational risk. The security decision therefore becomes more nuanced than applying every available patch.
“If a device has old firmware that cannot be patched, knowing the vulnerability still gives you another control,” Carcano says. “If somebody starts doing exactly what is required to exploit that vulnerability, you can identify it and react. You may not be able to remove the vulnerability from the device, but you can monitor for the behavior that would indicate somebody is trying to use it.”
Asset intelligence takes that a stage further by asking not only what a device is, but what normal behavior should look like. Nozomi monitors large numbers of industrial devices across customer environments and uses that knowledge to establish expectations around how particular equipment normally communicates. An unexpected protocol or unusual traffic pattern can then be assessed against what is typical for that class of asset rather than waiting months to build a behavioral baseline at an individual site.
“The difference with asset intelligence is that we already know, at a high level, the standard behavior of many types of equipment,” Carcano explains. “You do not have to wait until something becomes an anomaly in that plant. From the beginning, you can recognize when a device is behaving in a way that is unusual for that type of equipment.”
For manufacturers with large installed bases, that changes the value of the asset inventory. It becomes less a static list of equipment and more a continuously updated picture of the production environment that can be used to prioritize security effort.
The OT network is no longer isolated
Factories are not becoming more connected accidentally. Businesses increasingly want production data available in real time, while investment in automation and AI depends on information moving beyond traditionally isolated control systems. The commercial value of that connectivity is now challenging security assumptions inherited from older OT architectures.
“I do not think it is safe anymore to say, ‘My OT network is segregated, so I only need to control the places where somebody can get in,’” Carcano says. “As you add more IT equipment and communication between different parts of the network, the assumption changes. The trajectory is towards treating OT much more like a zero-trust environment, where you apply limited trust and verify the communication and identity of the devices.”
Some of the resulting blind spots are mundane rather than exotic. A plant team may describe a network segment as purely operational while overlooking connected office equipment sitting inside the same physical environment. Carcano recalls challenging one manufacturer that regarded part of its network as free of IoT devices by asking whether employees had IP phones and printers connected inside the plant. Both were present.
The point is not how those devices are labelled. It is that defining a section of the factory as “OT” can create a false sense of certainty if security teams stop looking closely at everything communicating within it.
Passive monitoring has traditionally helped manufacturers build that understanding without interacting directly with sensitive control equipment. Carcano says growing knowledge of industrial assets is also making organizations more comfortable using active techniques selectively, provided they understand the characteristics of the equipment first.
“The unknown is what creates the fear,” he says. “When you understand the plant, you know where you can add more active monitoring and where you may have fragile equipment that you should leave alone because the CPU load is already high or the device is old. Visibility gives you the information you need to make that decision.”
AI changes what security must see
Industrial AI adds another dimension because security systems increasingly need to understand not just which asset initiated an action, but what was behind it. As manufacturers deploy AI agents, autonomous equipment and more software-driven automation, Carcano expects attribution to become a larger part of industrial monitoring.
“One of the new requirements we are starting to see from customers is the capability to distinguish when there is a human versus artificial intelligence behind an action,” he says. “You need to understand who or what is performing it. Is it malware, is it something automated, is it an AI agent or is it an agent working on physical automation? The landscape is changing, and the technology must change with it.”
AI is also becoming part of the defensive architecture. Nozomi has used machine learning in its technology for years, including for passive device fingerprinting and behavioral analysis. More recently, Carcano says AI has become useful for linking security events that might otherwise appear unrelated and helping overstretched teams decide what requires attention.
That is particularly relevant in OT, where an automatic response that is perfectly acceptable in enterprise IT could stop production. Carcano argues that security AI therefore needs to help people understand an incident and choose an appropriate response rather than simply blocking activity.
“When an attack generates different alerts in different parts of a plant, you may have somebody who understands cybersecurity or somebody who understands the plant, but rarely somebody who is an expert in both,” he says. “AI can help connect those two areas of knowledge. Once you detect an attack, the next question is what to do. In a plant you do not always want an automated security mechanism blocking something, because the customer does not want the security solution to stop production.”
The original principle behind OT visibility therefore still holds, but its meaning is expanding. Manufacturers need to know far more than whether a device exists. They need enough context to understand the risk it represents, recognize when its behavior changes and increasingly determine whether the activity behind that change came from a person, software or AI.
Turning on the lights remains the starting point. The harder task is understanding everything that becomes visible once the room is no longer dark.

