OT, ICS & SCADA field guides

OT Asset Discovery & Vulnerability Management by Kai London

Almost every industrial security programme stalls at the same place: nobody can say with confidence what is actually on the network. This field guide gets you to a defensible inventory — safely, without tripping a process — and then turns that inventory into a vulnerability programme that fits plant constraints.

Available on Amazon.

What is inside

Safe discovery methods

Passive monitoring, configuration extraction and controlled active techniques — and when each is appropriate near live process.

What an OT asset record must hold

Make, model, firmware, protocol, owner, criticality and the process it serves — not just an IP address.

Finding the hidden estate

Engineering laptops, legacy serial devices, vendor-installed equipment and everything the drawings never captured.

Vulnerability intelligence for ICS

Mapping CVEs and advisories to real device populations, and filtering out what does not apply.

Prioritisation under plant constraints

Risk ranking by consequence and exposure when patching means a shutdown window you may not get.

Compensating controls and evidence

What to do when the fix is not available, and how to evidence the decision to an auditor.

Who it is for: OT security teams standing up an asset programme, control system and maintenance engineers, plant managers, and CISOs inheriting an industrial estate.

IEC 62443NIST SP 800-82NIS2NERC CIPPurdue model

You cannot defend what you cannot see, and you cannot prioritise what you have never counted.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.