OT Asset Discovery & Vulnerability Management by Kai London
Almost every industrial security programme stalls at the same place: nobody can say with confidence what is actually on the network. This field guide gets you to a defensible inventory — safely, without tripping a process — and then turns that inventory into a vulnerability programme that fits plant constraints.
Available on Amazon.
What is inside
Safe discovery methods
Passive monitoring, configuration extraction and controlled active techniques — and when each is appropriate near live process.
What an OT asset record must hold
Make, model, firmware, protocol, owner, criticality and the process it serves — not just an IP address.
Finding the hidden estate
Engineering laptops, legacy serial devices, vendor-installed equipment and everything the drawings never captured.
Vulnerability intelligence for ICS
Mapping CVEs and advisories to real device populations, and filtering out what does not apply.
Prioritisation under plant constraints
Risk ranking by consequence and exposure when patching means a shutdown window you may not get.
Compensating controls and evidence
What to do when the fix is not available, and how to evidence the decision to an auditor.
Who it is for: OT security teams standing up an asset programme, control system and maintenance engineers, plant managers, and CISOs inheriting an industrial estate.
You cannot defend what you cannot see, and you cannot prioritise what you have never counted.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.