Many organizations face a critical blind spot in cybersecurity due to inaccurate or incomplete data on their own connected physical assets, making it difficult to identify vulnerabilities and secure vital operational technology.

  • 88% of cyber-physical assets fail to provide exact product codes.
  • 41% of devices lack any operating system version information.
  • 44% of global security leaders cite poor risk visibility as a top concern.

What happened

Recent research analyzing 17 million cyber-physical assets revealed that the majority do not reliably communicate accurate product identification codes. This makes it extremely difficult for security teams to determine which devices are affected by specific vulnerability alerts. Nearly nine out of ten devices failed to transmit an exact product code, and over three-quarters sent codes that did not match vendor data.

The problem extends beyond product codes to the devices' underlying operating systems. Around 41% of these devices do not report any OS version, and 24% provide no OS name, further complicating vulnerability identification. Unlike traditional IT systems, many CPS were designed decades ago prioritizing physical reliability over digital asset inventory accuracy and network identification.

Why it matters

This lack of reliable asset data has profound implications for cybersecurity strategy, particularly in critical sectors such as healthcare, energy, and manufacturing, where cyber-physical systems play a key operational role. Vulnerability alerts for these assets often require days of manual verification or guesswork to assess impact, drastically slowing patching efforts and increasing the risk of successful attacks.

Moreover, industry-standard vulnerability tracking mechanisms like CVE advisories rely on vendor-supplied data that is often incomplete or inconsistent. This amplifies the challenge of aligning known vulnerabilities with actual deployed devices, eroding confidence in risk quantification and visibility. A survey of over 1,100 security leaders underscored this concern: 44% identified insufficient understanding of organizational risk exposure as a top operational worry, highlighting the widespread impact of poor asset data quality.

What to watch next

Organizations need to prioritize improvements in cyber-physical asset inventory accuracy to strengthen overall security posture. This may involve investing in advanced asset discovery tools that can better interpret diverse device protocols and correlate inconsistent data points. Security teams also need to foster closer collaboration with operational technology stakeholders to address the longstanding disconnect between IT and OT asset management.

At the industry level, enhancing vendor transparency and standardizing device metadata reporting can help improve the completeness and reliability of vulnerability data feeds. Until these gaps are addressed, business and security leadership must recognize the limits of their risk visibility and adjust decision-making frameworks to account for inherent uncertainties in CPS asset data.

Source assisted: This briefing began from a discovered source item from TechRadar. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings