
Nexus: A Claroty Podcast · 2026-06-29 · 13 min
Key moments - from our scoring
Substance score
40 / 100
Five dimensions, 20 points each
Dan Ricci explores the critical difference between simple asset enumeration and a strategic asset inventory in operational technology environments. While asset lists capture basic device information like IP addresses and device types, true asset inventories incorporate contextual data including firmware versions, applicable vulnerability advisories, patch status, compensating controls, communication relationships, criticality ratings, owner accountability, vendor support status, and network presence history. Building this inventory leverages both automated tools - including passive packet capture via Wireshark, TShark, and Network Miner, plus vulnerability data from the ICS Advisory Project and CISA guidance - and manual validation. Ricci emphasizes that organizations must treat inventory management as a continuous, living process rather than a point-in-time exercise, involving clear role assignment, technology automation, scheduled physical validation, and integration with contractor operations. The ultimate value lies not in tool count but in measurable risk reduction over time, where baseline configuration knowledge enables rapid detection of asset manipulation and supports incident response and root cause analysis.
An asset list is basic enumeration of devices, IP addresses, physical locations, and device types. An asset inventory adds contextual data like firmware/software versions, applicable vulnerability advisories, patch status, compensating controls, data flow relationships, criticality ratings, owner accountability, vendor support status, and when the asset was last seen on the network.
Passive tools like Wireshark, TShark, and Network Miner can identify assets and build initial lists. Additional data comes from vendor websites, the ICS Advisory Project, passive packet capture, flow data analysis, router logs, and switch configuration analysis - all of which can be done passively using existing network infrastructure.
Baseline configuration knowledge allows rapid detection of unauthorized changes such as altered setpoints, unexpected device communications, public IP connections, or connections to devices never previously contacted, enabling quicker identification of compromise and root cause analysis.
Organizations need clear role assignment for responsibility, automated technology to reduce manual effort, scheduled physical validation (such as annual audits), contractor integration for outsourced operations, and a commitment to treating inventory as a living document that tracks asset lifecycle through end-of-life.
Success is measured not by tool count or number of discovered assets, but by whether risk actually decreases over time and whether every alert and scan feeds into a continuous cycle of prioritization, action, and validation that moves the organization from relying on hope to achieving resilience.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers a reasonably thorough definitional breakdown of asset list vs. asset inventory and mentions legitimate tools, but the ideas are foundational OT security education rather than novel insights. In 13 minutes there is no surprising claim a practitioner in this space wouldn't already know.
Are there uh specific um advisories, vendor uh vulnerability advisories assess attached to that that are applicable to that asset? Are they been patched or not, right?
a connection or a configuration to uh um devices that it normally does not communicate with, now is communicating with it, or it's making connections out to uh a uh a public IP when it should only be communicating on private IP addresses
The content tracks closely to standard CISA guidance and well-worn OT security frameworks; there is no contrarian argument, first-principles reasoning, or counterintuitive position. The closing framing of 'hope to resilience' is a recycled industry phrase.
I will say that SISA does a very good job providing the step-by-step guidance
it kind of moves the organization from a posture of like hope to uh one of uh resilience
Dan Ricci is a legitimate domain practitioner as founder of the ICS Advisory Project, a credible OT vulnerability resource, but the episode presents him primarily as an author/educator rather than someone sharing hard-won operational experience at scale. He openly admits limited visibility into what asset owners actually do.
I wouldn't be able to speak directly on how um how many like asset owners are actually uh going in that direction
ICS Advisory Project supports it. You can use SysA directly, you can go to the vendor's uh website
The episode names specific open-source tools (Wireshark, T-Shark, Network Miner) and concrete asset attributes (firmware version, end-of-life status, set-point changes), which is above average for the genre, but there are zero real-world case studies, metrics, dollar figures, or named deployments to anchor the claims.
passive tools out there that can help with do this asset identification, uh, such as like Wireshark, T Shark. You can use uh Network Miner.
a set point was changed, uh a um uh a um a connection or a configuration to uh um devices that it normally does not communicate with
The host's questions are broad and soft ('give me some examples,' 'how continuous is this'), there is no follow-up pressure or pushback on any claim, and the interview opens with overt promotion of the guest's article. The conversation functions as a friendly recap rather than a probing interview.
Really great stuff. It's going to be linked here uh in the video. Uh, and I urge everybody to read it, share it internally. There's a lot of valuable information in here.
So just kind of as a last thought, I mean, how do you how continuous is this
Computed from the transcript - who did the talking, and the words that came up most.
ICS Advisory Project founder Dan Ricci joins the Nexus Podcat to discuss how to turn operational technology (OT) and cyber-physical systems (CPS) visibility into actual risk reduction. Dan describes the need to distinguish between asset lists and actual asset inventories, what those differences are, and how to make the most of the information made available. Device data such as firmware versions, protocol identification, and more are vital to other aspects of the OT and CPS protection program, including exposure management and segmentation initiatives. Dan wrote more on this topic in this article: “ From Inventory to Insight: Turning OT Visibility into Concrete Risk Reduction .” This interview was pulled from Episode 4 of Nexus Digest . Subscribe and listen to the Nexus Podcast here .
Transcribed and scored by The B2B Podcast Index.
1 - > SPEAKER_00: All right, welcome to episode four of Nexus Digest. 2 - > Dan Ritchie, the founder of the ICS Advisory Project, and uh day 3 - > one, Nexus Contributor joins us today. 4 - > Uh Dan and I are going to discuss an article he wrote 5 - > recently that was titled From Inventory to Insight. 6 - > And basically the article talks about how to leverage OT 7 - > visibility to achieve concrete risk reduction.
8 - > So it's great to see you, Dan. 9 - > How are you doing? 10 - > SPEAKER_01: Doing well. 11 - > Thank you, Michael.
12 - > Great to be here. 13 - > SPEAKER_00: Yeah, thanks for uh giving me a few minutes. 14 - > I'm glad the audience is going to get to hear from you on this. 15 - > Um, so let's talk about your most recent contribution.
16 - > Really great stuff. 17 - > It's going to be linked here uh in the video. 18 - > Uh, and I urge everybody to read it, share it internally. 19 - > There's a lot of valuable information in here.
20 - > So basically, you start off talking about how a lot of 21 - > organizations, you know, get these asset lists from their 22 - > tools, whatever they might be. 23 - > And they kind of think of that as an asset inventory, and you 24 - > distinguish between the two. 25 - > So tell me a, you know, I I think it's a it's a good table 26 - > setter kind of question. 27 - > How do you view the two in terms of differences?
28 - > SPEAKER_01: Well, uh asset list is your basic enumeration of the 29 - > your devices, the IP addresses assigned to those devices, if 30 - > they're assigned with static IP addresses, the physical 31 - > location, device type, whether it's PLC, HMI, historian, uh, 32 - > vendor model. 33 - > But like getting into like when you start to get into the asset 34 - > inventory site, that starts to have like higher highly more 35 - > contextual data. 36 - > Now we're looking at you know the firmware and software 37 - > version is associated with it.
38 - > Are there uh specific um advisories, vendor uh 39 - > vulnerability advisories assess attached to that that are 40 - > applicable to that asset? 41 - > Are they been patched or not, right? 42 - > What the patched asset are, or they're not gonna patch it. 43 - > That's fine too.
44 - > What are the compensated controls that are in place to 45 - > protect it? 46 - > Uh, what is the communications relationship between that that 47 - > asset, you know, the data flow between that device and the and 48 - > the rest of the OT uh environment, uh whether it's 49 - > communicating with another PLC or it communicates only directly 50 - > with the with the uh SCADA server. 51 - > Um, then you gotta look at uh what's the what's the 52 - > criticality of that asset?
53 - > You know, what's the process impact rating of that? 54 - > Is it a crown jewel? 55 - > You know, it's essential to that uh to the uh business industrial 56 - > operations or not. 57 - > Uh what's the owner, who's the owner of that asset and the 58 - > responsible party who maintains the operation and maintenance 59 - > side, uh process uh control engineer, uh instrumentation 60 - > control engineer that might be responsible for that device.
61 - > Uh what vendor support status? 62 - > You know, we talked about whether this it's uh whether 63 - > it's an end-of-life product. 64 - > So if it's end-of-life, there's no longer patch support for end 65 - > of service, or that uh specific um control system uh asset is no 66 - > longer supported by the system integrator or or the company 67 - > went out of business, that's very possible as well. 68 - > And then, you know, when was the last time that asset was seen on 69 - > the network?
70 - > So there's a lot more to just having, you know, uh asset 71 - > device list. 72 - > So hopefully that's uh um a help helpful distinction between uh 73 - > the two two pieces here. 74 - > SPEAKER_00: Yeah. 75 - > And how good are existing tools in providing all that context?
76 - > I mean, uh how much of that is automated versus manual, I guess 77 - > is what I'm asking. 78 - > SPEAKER_01: A lot of it can be automated uh with a lot of the 79 - > products that are out there. 80 - > There's uh passive tools out there that can help with do this 81 - > asset identification, uh, such as like Wireshark, T Shark. 82 - > You can use uh Network Miner.
83 - > There's these are all like kind of open source products that you 84 - > can help to start to build the the um the asset list and you 85 - > know the rest of the asset inventory data you'd want to 86 - > bring into it, uh, then you have tools uh that can help you start 87 - > to identify the the um vendor uh vulnerability data. 88 - > Uh ICS Advisory Project supports it. 89 - > You can use SysA directly, you can go to the vendor's uh 90 - > website for the asset if they're still they still exist.
91 - > Uh, then you can also look at um uh using the vendor to also help 92 - > identify the you know what the most current firmware version 93 - > that should be running on that software. 94 - > Right. 95 - > Identifying it um within the environment, within your 96 - > environment, you might be able to identify it through passive 97 - > packet capture, full content, um doing identifying the data flow 98 - > between those networks. 99 - > You can look at your flow data between uh and that can be done 100 - > all passively using uh your um your existing um uh network 101 - > infrastructure.
102 - > Um uh you can use um uh your logs from your your your router, 103 - > your from your router. 104 - > You can also look at uh your switch configurations. 105 - > I mean there's configuration analysis is very powerful and 106 - > and trying to fill these gaps and trying to provide that asset 107 - > inventory picture. 108 - > So um, I mean we could I could go on probably a lot longer 109 - > about this.
110 - > SPEAKER_00: You in the article too, you referenced um Sys's OT 111 - > inventory guidance, and you mentioned that inventories 112 - > should be organized, regularly updated, physically validated. 113 - > How difficult is that? 114 - > Are those steps and and how often are organizations actually 115 - > going that extra mile if it's an extra mile? 116 - > SPEAKER_01: I wouldn't be able to speak directly on how um how 117 - > many like asset owners are actually uh going in that 118 - > direction, but I will say that SISA does a very good job 119 - > providing the step-by-step guidance, although it might be 120 - > high level, gives you the the a great starting point for uh 121 - > building your asset inventory.
122 - > I I want to say it very much aligns with you know giving 123 - > asset owners the foundational information to to uh to scope, 124 - > you know, understand the objectives. 125 - > Uh a point that I really didn't touch on in the last last piece 126 - > was like, you know, how do you identify the uh your crown 127 - > jewels? 128 - > And that's a lot of that comes down to understanding what the 129 - > risk of uh to that specific asset is to uh you know your 130 - > organizations or business operations.
131 - > SPEAKER_00: So that really becomes like a business impact 132 - > discussion at that point. 133 - > SPEAKER_01: Yeah, yeah. 134 - > I mean it's classified by you know function and uh 135 - > criticality. 136 - > Um the SISA um OT uh asset inventory guidance hits on it as 137 - > hard as like creating a taxonomy, right?
138 - > Of classifying by function and criticality. 139 - > And then, you know, another piece is you know asset 140 - > inventories are and asset management in general is is is a 141 - > living document, it's not a static document. 142 - > So you're looking at you know managing that data, uh, and 143 - > implementing an asset lifecycle management, you know, tracking 144 - > it to end of life, you know. 145 - > SPEAKER_00: So once you have that inventory, give me some 146 - > examples of what it can be used to enable in terms of the rest 147 - > of the security program.
148 - > SPEAKER_01: Obviously, it's very foundational, and you probably 149 - > can't start anything else without a decent inventory and 150 - > visibility into what you have, but well, I mean key point is of 151 - > having an asset inventory or is understanding what your 152 - > organizational risk and then how to defend it and how you can 153 - > actively defend it, because now you have the ability to 154 - > understand what the baseline configuration of those assets 155 - > are, uh, which is is so if there is something that does occur in 156 - > your environment, if uh your that asset is a is um is 157 - > manipulated in a way that is off its known baseline, you can 158 - > identify that rather quickly.
159 - > It helps tremendously in incident uh response. 160 - > Uh, because that way you're you're able to really know for 161 - > sure, you know, there there was there was definitely a change 162 - > made, but who made the change, what was you could you could 163 - > start to do the root cause analysis of understanding what 164 - > happened, uh, because you know uh you know, based off of like 165 - > the known configuration, that uh something happened on the device 166 - > that uh tampered with uh the current configurations, like a 167 - > set point was changed, uh a um uh a um a connection or a 168 - > configuration to uh um devices that it normally does not 169 - > communicate with, now is communicating with it, or it's 170 - > making connections out to uh a uh a public IP when it should 171 - > only be communicating on private IP addresses within the 172 - > environment, or it's communicating with a device that 173 - > it's never communicated with before.
174 - > So having uh that asset inventory allows you to detect 175 - > uh possible indications of compromise. 176 - > SPEAKER_00: And so just kind of as a last thought, I mean, how 177 - > do you how continuous is this in in terms of as a as a process, 178 - > as an exercise? 179 - > How do you keep it from being just kind of a point in time 180 - > thing that really isn't useful? 181 - > How just give me some advice in that in that direction.
182 - > SPEAKER_01: I think that's more than more than uh a technical, 183 - > more than just a technical challenge, it's a it's a a 184 - > people and process challenge, right? 185 - > And having a a uh identifying those roles of responsibility 186 - > that can enable and sustain um the management of uh of uh solid 187 - > acid inventory, uh leveraging uh technology to automate and 188 - > reduce uh the amount of time it would be to uh gather and 189 - > maintain, but also develop a schedule that would address uh 190 - > what can't be covered by uh passive uh monitoring, like a 191 - > physical uh inventory that's maybe done annually to kind of 192 - > help uh keep this alive over over time.
193 - > Also, I mean uh some organizations um are contract 194 - > out a lot of their um uh ICS uh OT uh uh asset uh operations and 195 - > maintenance. 196 - > So uh looking at their contract and seeing how that might help 197 - > them uh maintain and track uh their their asset inventory and 198 - > hit on uh maintaining uh uh baseline configuration uh 199 - > information and ensuring that's documented and maybe out of that 200 - > uh they produce a uh a uh a file that can be integrated with the 201 - > current asset inventory for uh for management.
202 - > It's the only way I think organizations could really stand 203 - > uh top and uh manage risk because you know visibility only 204 - > matters when it drives uh real and continuous uh risk 205 - > reduction, right? 206 - > unknown: Right. 207 - > SPEAKER_01: For small and medium OT environments, uh security 208 - > success isn't measured on you know how many tools they have 209 - > deployed and how many assets are discovered. 210 - > It's measured by whether risk is actually going down over time, 211 - > right?
212 - > Uh, and also uh whether you know every alert, every scan on every 213 - > uh asset should uh feed into like their cycle of 214 - > prioritization and action and validation. 215 - > Uh it kind of moves the organization from a posture of 216 - > like hope to uh one of uh resilience. 217 - > SPEAKER_00: And that's the goal, right? 218 - > Resilience.
219 - > SPEAKER_01: Yeah, it's it's it's not um something that uh is uh 220 - > is hope's not a plan. 221 - > Yeah. 222 - > But having having a plan having a plan is is uh is key to uh 223 - > being successful in uh in recovery in a lot of these 224 - > situations. 225 - > SPEAKER_00: All right, Dan.
226 - > I think that's a good place to leave it. 227 - > I want to thank you so much for coming on and uh I appreciate 228 - > the great work on Next as always. 229 - > SPEAKER_01: Likewise, thank you for that. 230 - > SPEAKER_00: All right, Dan, take care.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.