
OT Network Mapping: the first step to securing your industrial environments
You cannot protect what you do not know. That is the starting point for any serious OT security initiative. Before protecting or monitoring, you need to know exactly what is running on the industrial network: which assets, which flows, which vulnerabilities. This first step (OT network mapping and inventory) is also the one most organizations struggle with most. Here is why it matters, and how to approach it in practice.
Key takeaways
-
- Securing an OT environment follows a precise sequence that begins with asset and network flow inventory.
- In industrial environments, two identical assets like PLCs can have radically different criticality levels. Assessment cannot be based solely on asset type, it must incorporate operational context.
- Network flows observed passively are the most reliable basis for understanding who communicates with whom. Declarative documentation alone is not enough.
- The mapping must speak to both IT and OT teams: the same underlying data, presented from different angles depending on the audience.
- Protection configurations can be generated directly from the observed flow matrix, with no intermediate manual step.
A reminder: a five-step security methodology
Faced with the rising threat to OT environments, regulations and field experience converge on the same sequence:
- inventory assets and network flows,
- reduce the attack surface by removing what is unnecessary,
- identify critical systems and physically isolate them,
- put the infrastructure under continuous monitoring,
- secure backups with physical isolation.
Everything starts with the first step. Without a reliable inventory, the four that follow are built on nothing.
Why OT mapping is more complex than it looks
In IT, network mapping is a well-understood exercise. The tools exist, the teams know how to do it. In OT, it is a different story. Industrial environments have evolved in layers, often without up-to-date documentation. Agentless legacy devices, proprietary protocols, complex network topologies inherited from architectures designed for availability above all else: inventory work cannot be improvised.
The first challenge is reconstructing the complete pedigree of every asset. A single device may have multiple IP addresses, nested network configurations, and software or firmware versions that no longer match any existing documentation. Without that level of precision, any criticality or vulnerability assessment remains approximate.
The second challenge is assessing the criticality of each device. In IT, this is often intuitive: an Active Directory is critical, full stop. In OT, two PLCs of the same vendor and model may belong to entirely different operational scopes. One controls a process that is vital to production; the other handles a peripheral function with no immediate impact. This assessment cannot be generalized, it must be done device by device, in collaboration with operational teams.
The challenge of multiple perspectives
In IT, conversations typically happen between specialists: network, cybersecurity, systems administration. In OT, the stakeholders are different: production managers, process technicians, field operators. Effective mapping must produce representations that are usable by both worlds, drawn from the same underlying data.– IT teams need a precise network view: subnets, flows, protocols, vulnerabilities.
– OT teams need an operational view: by production line, by function, by potential process impact.
– Both must be able to work together from a shared representation.
The third challenge is source reliability. An inventory built on declarative documentation reflects what teams believe they know, not what is actually on the network. Undocumented flows, forgotten connections, devices added without formal procedure: none of them appear in any spreadsheet, but they are very much present on the network. Only passive analysis of real traffic can surface them.
How Seclab Xplore addresses these challenges
Seclab Xplore is the visibility layer of the Xcore platform. It relies on passive probes deployed on the industrial network to observe flows without ever disrupting them. No agent to install on devices, no impact on process availability: this is a non-negotiable constraint in OT environments. From these observed flows, Xplore reconstructs a complete, multi-level map of the infrastructure.
The data collected allows the full pedigree of each asset to be reconstructed: name, software and firmware versions, network configuration, zone assignment, communication peers, applications in use,… This includes devices with multiple IP addresses or complex configurations.
Multiple views are available from the same underlying data, tailored to different roles and use cases:
- Logical view (zones and conduits): Displays the different network zones with their assets and the flows between those zones (or between individual devices). Xplore can discover the network autonomously, or import existing configurations (firewalls, switches) as a reference baseline. The solution then distinguishes between what was assumed and what is actually observed, immediately surfacing outdated inventories.
- Purdue view: A layered representation following the IEC 62443 model, from OT cyber-physical systems at the bottom to the cloud at the top. It immediately highlights anomalous situations: remote access paths between the internet and an industrial administration zone — sometimes contractually established with maintenance providers — that may bypass firewalls via 4G routers or other uncontrolled access points.
- Operational view (functional groups): The same assets are grouped by operational function (compression, pumping, energy, etc.). This allows functional zones tied to business processes to be created, rather than technical zones tied to network equipment. This enables IT and OT teams to work from a shared representation.
- Network view: A hybrid between the Purdue view and a conventional network architecture diagram, generated automatically through router and firewall detection. It identifies dual-homed machines (one interface in the administrative domain, one in the industrial domain), prime targets for an attacker looking to pivot.
- Geographic view: Physical location of devices on-site, to identify where critical or vulnerable assets are located and streamline remediation interventions in the field.
All maps are exportable in Draw.io format for sharing with internal and external teams, or for use in migration and digitalization projects.
Flow matrix
The flow matrix is a central element of the analysis. It shows which device communicates with which, via which network interface, down to the application layer. It allows the direction of each communication between an asset and all its network peers to be validated. It is based on flows that are actually observed, not on declarative documentation.
This matrix can be analyzed at subnet level to obtain intra- and inter-VLAN views, following the same logic as a firewall: flow control and application-layer exchange governance across zones.
Its value extends beyond mapping. It is directly from this matrix that configurations for the Seclab Xchange appliance can be generated: filtering rules are not entered manually but built from the flows actually observed on the industrial network. This is the direct link between the discovery phase and the isolation phase.
Inventory and vulnerability management
The Xplore inventory goes beyond simple asset enumeration. It incorporates a criticality assessment for each discovered device, configured on a case-by-case basis in collaboration with operational teams. This criticality is reflected visually across all mapping views: asset color indicates criticality level or vulnerability status.
Specific views can be configured to surface at-risk situations: for example, displaying in red any vulnerable devices with active RDP connections. A common scenario in industrial environments, and one that helps prioritize remediation actions.
The list of detected vulnerabilities is integrated into the solution and can be shared with other tools: SOC, VOC, patch management platforms. The value of contextualizing them within Xplore is the ability to prioritize each vulnerability based on its actual criticality in the OT environment in question, rather than a generic CVSS score disconnected from operational reality.
Finally, the solution enables cross-referencing of software installed on workstations against known vulnerability databases, moving from passive collection to semi-active collection (by deploying scripts or executables provided by Seclab, signed and auditable, with no installation required). USB drives used in industrial environments are also tracked, as a threat introduction vector that is frequently underestimated.
To discover Seclab Xplore, watch this excerpt from our June 2026 webinar replay
What now?
Mapping is not an end in itself. It is the foundation that makes every subsequent step possible. Without a reliable inventory, attack surface reduction remains partial, identification of critical assets is approximate, and isolation only protects what someone thought to protect.
Seclab Xplore is the first building block of the Seclab Xcore platform. It establishes the visibility foundation on which detection and protection capabilities rely. In the next article in this series, we will cover the following step: physical isolation of critical assets with Seclab Xchange.
