IT Discovery for Manufacturing: Closing the OT Boundary Gap
When Nucor detected unauthorized access to its IT systems in May 2025, the largest steel producer in North America did not wait to learn what that access could reach. It shut down production at multiple locations first. That choice only makes sense if you cannot yet say, with confidence, exactly what is connected to what.
IT discovery for manufacturing is often pictured as a corporate office sweep or as reading plant-floor protocols. The devices that go missing sit in between. They are IT-class hardware installed where OT connects to the corporate network: jump servers, historians, engineering workstations, remote-access gateways, switches, and access points. This article is about why that zone is still nobody’s standard inventory, and how to close the gap without pretending to be an OT-protocol tool.
Where Manufacturing Visibility Usually Stops
Most plants already track something. A CMDB in manufacturing can model how enterprise and corporate configuration items relate. Operations teams watch whether those systems stay up. Dependency maps can show how ERP and supply-chain platforms connect. License and hardware records can show what the company owns once an asset is known.
IT discovery for manufacturing starts one step earlier. It means finding and identifying the IT-class assets that sit in the boundary zone where the corporate network meets the plant floor. That work does not inventory PLCs, sensors, or controllers. It also does not read OT protocols such as Modbus, DNP3, EtherNet/IP, or PROFINET. Plant-floor devices stay with OT tooling. Corporate discovery should still own the jump servers, historians, gateways, and network gear that make the boundary run.
The Devices That Belong to No One’s Inventory
In Purdue-model terms, the boundary often includes a DMZ or “Level 3.5” zone. Historian servers, jump hosts for remote OT access, engineering workstations, and vendor-installed remote-access gateways and switches live there by design. They run Windows or Linux. They have IP addresses corporate tools could reach. They are IT-class devices in every practical sense.
They rarely enter either team’s book of record the normal way. Systems integrators and OT vendors install them as part of a plant project. Corporate IT did not provision them through the standard request path. OT engineering does not track them as “their” assets because they are not controllers. The result is a population that neither corporate-scoped discovery nor protocol-level OT inventory claims by default.
What counts as an IT asset at the boundary between OT and the corporate network?
IT assets at the OT edge include jump servers, historian databases, engineering workstations, remote-access gateways, switches, and wireless access points in the DMZ or Level 3.5 zone. They are IP-addressable hosts and network gear that support plant connectivity, not PLCs, sensors, or industrial controllers themselves.
Why the Boundary Is Where Visibility Actually Breaks
Third-party install patterns explain a large share of the blind spot. Ponemon’s 2025 manufacturing third-party research, summarized by Kiteworks, found 43% of manufacturers lack a comprehensive inventory of third parties with network access to their environment. Fifty-four percent do not evaluate a third party’s security practices before granting that access. Manufacturing also showed the lowest rate among surveyed industries (29%) for applying a consistent privileged-access strategy to those parties. Those are the conditions under which boundary-zone gear appears without an owner in either inventory.
The SANS State of OT/ICS Cybersecurity 2025 findings, covered by Dragos, put the same path in visibility terms. Only 12.6% of organizations report full visibility across the entire ICS Cyber Kill Chain, from an IT-side compromise through to potential OT impact. Asset inventory and visibility ranked as a top technology investment priority for many respondents for 2025 and again for 2026-2027. That is a discovery gap before it is a monitoring gap. You cannot patch, govern, or assign blast radius for a device your inventory does not know exists.
Corporate discovery stops at the segments it is configured to reach. OT inventory claims devices that speak OT protocols. The IT-class middle is the residual.
What Happens When Nobody Can Say What’s Connected
Nucor’s May 2025 disclosure, reported by Cybersecurity Dive, described unauthorized third-party access to certain IT systems and a proactive decision to take potentially affected systems offline. Production halted at multiple locations while the company determined scope. Public reporting does not identify an unmanaged boundary device as the entry point. This article does not claim that. The operational lesson still holds: a broad, precautionary stop is what leaders choose when they cannot quickly answer what else a path can reach.
Masimo’s April 2025 disclosure of unauthorized on-premise network activity is a second, independent data point. Manufacturing capacity and order fulfillment came under pressure while the company worked the incident. Again, the public record does not pin a specific undiscovered host. The shared pattern is scope uncertainty under time pressure.
CISO and GRC leaders feel that uncertainty as audit and exposure risk at zone boundaries. Plant and controls leads feel it as unexplained stoppages. IT discovery and infrastructure leads feel it as the missing source record everyone else assumes already exists.
Trusted Runtime Truth at the IT/OT edge See how manufacturers build discovery-sourced truth for the IT assets living where the corporate network meets the plant floor, before an incident forces a plant-wide stop. |
Why This Is a Discovery Problem, Not Just a Policy Problem
Vendor-access policy and IT/OT governance frameworks matter after you know what exists. IT/OT asset management in manufacturing can govern lifecycle, ownership, and compliance once those assets are on record. Written policy, spreadsheets, and even CMDB rows go stale the moment a vendor adds or swaps boundary-zone equipment on a plant visit.
The fix has to run at the discovery layer first. A recurring, source-verified sweep of IT-class assets in the boundary zone feeds the CMDB that change, asset, and dependency work depend on. Service mapping across manufacturing systems can only show blast radius for services and paths that discovery has already made visible. Governance without discovery leaves empty rows under polished policy language.
Why do standard IT discovery sweeps miss devices installed by OT vendors and integrators?
Corporate discovery is scoped to subnets IT owns and provisions. Integrator-installed jump servers, historians, and gateways often sit on boundary segments outside that scope and outside OT protocol inventories. Without a deliberate boundary discovery job and an owner field, those hosts never enter the CMDB.
Extending Discovery to the Boundary, Safely
Apply the same methods IT already trusts on the corporate side, on purpose, to the boundary’s IT-class assets:
- Agentless discovery (SNMP, WMI, SSH, and related protocols) for network gear and reachable hosts
- Agent-based discovery for Windows, macOS, and Linux hosts that can run an agent
- API-based discovery for virtualization and cloud layers that host boundary workloads
Coordinate with OT and plant engineering on which segments and time windows are safe to scan. Do not assume either team’s existing sweep already reaches the zone.
Where a segment is sensitive, start passive-first and schedule active checks in off-hours or maintenance windows. That caution matches general OT-adjacent practice and Virima’s published guidance on active versus passive discovery. It is operational judgment, not a claim that Virima ships a dedicated OT-certified or passive-only plant-floor mode.
Virima IT Discovery covers agentless, agent-based, and API-based discovery of IT-class assets. Discovered configuration items flow into the CMDB with source tags, last-verified timestamps, and authority-rule conflict resolution on high-frequency discovery cycles. Virima does not read OT protocols, monitor PLCs or SCADA, or replace dedicated OT/ICS security tooling. Pair discovery with OT security platforms where plant-floor telemetry is required. Feed ITSM platforms through Virima’s integrations (ServiceNow, Jira Service Management, Ivanti, HaloITSM, Xurrent, Hornbill, and TeamDynamix) so tickets sit on the same inventory picture.
How should manufacturing IT safely extend discovery into boundary-zone network segments?
Treat each interconnect segment as its own discovery scope. Agree methods and windows with OT and plant engineering first. Prefer passive collection where sensitivity is unclear, then add agentless or agent-based checks for IT-class hosts during approved windows. Record owner, vendor, and last-verified fields on every new CI.
Where to Start: Scoping Discovery at the Boundary
Use a short scope checklist rather than an open estate project:
- Name the interconnects. Map every segment where a corporate-IT subnet and an OT or plant subnet meet: DMZ, jump-server VLAN, wireless bridge. Treat each as its own discovery scope.
- List vendors with access. Inventory which integrators and OEMs currently have network access into that zone. Cross-check that list against what discovery actually finds.
- Agree methods with OT. Confirm scan windows and methods with plant engineering before any active discovery on boundary-adjacent segments. Passive first where sensitivity is unclear.
- Flag ownerless CIs. Any discovered device with no clear owner, install record, or vendor attached is the signature of an asset nobody’s inventory claims.
- Feed downstream work. Push verified CIs into the CMDB so operations monitoring, change impact, and license or hardware tracking all run from the same source record. That shared inventory is what keeps enterprise-layer manufacturing operations from relying on a parallel spreadsheet.
Start with the interconnect that supports production scheduling or remote vendor access. Expand outward once that segment has owners and last-verified dates.
Close the Blind Spot at the Edge
The riskiest gap in manufacturing IT/OT convergence often is not on the plant floor. It is the IT-class hardware sitting exactly where OT connects to the corporate network, installed by a vendor, claimed by no one’s standard inventory, and invisible until an incident forces the question. Closing that gap is a discovery problem before it is a governance or monitoring one.
See how Virima’s discovery finds the IT assets living where your corporate network meets your plant floor: Request a demo.
Frequently Asked Questions
What counts as an “IT asset” at the boundary between OT and the corporate network?
Jump servers, historian hosts, engineering workstations, remote-access gateways, switches, and access points in the DMZ or Level 3.5 zone. They are IP-reachable IT-class systems that support plant connectivity. They are not PLCs, sensors, or industrial controllers.
Why do standard IT discovery sweeps miss devices installed by OT vendors and integrators?
Those devices are often installed on boundary segments outside corporate discovery scope and outside OT protocol inventories. Without a dedicated boundary job, owner field, and last-verified timestamp, they never enter the CMDB that IT operations and audit teams use.
What’s the difference between OT asset discovery and IT discovery at the network edge?
OT asset discovery focuses on industrial control devices and protocols on the plant floor. IT discovery at the edge focuses on servers, workstations, gateways, and network gear in the interconnect zone. Both matter. They answer different inventory questions and usually need different tools.
How much visibility do manufacturers actually have across the IT/OT boundary?
SANS/Dragos 2025 reporting found only 12.6% of organizations claim full visibility across the ICS Cyber Kill Chain from IT-side compromise to potential OT impact. Ponemon’s manufacturing third-party research found large gaps in vendor inventory and privileged-access consistency. Exact rates vary by plant, but incomplete boundary inventory is common.
How does Virima support IT discovery for manufacturing without claiming OT monitoring?
Virima discovers IT-class assets with agentless, agent-based, and API-based methods and feeds the CMDB with source tags and last-verified data. It is built for that corporate and boundary IT layer and ITSM integration. It does not replace OT security platforms that monitor industrial control systems on the plant floor.






