Skip to content
Active incident? Certified responders answer 24/7, no retainer required.  Experienced a breach? →
from provisioning to performance

The Confidence Standard · Visibility Pillar

Find the devices your

network inventory

doesn't know about.

Discovery and risk assessment for IoT and operational technology.

Building automation, HVAC controllers, badge readers, cameras, industrial sensors: most of what runs
on a modern network was never provisioned by IT, rarely gets patched, and often can't run standard
endpoint security at all. This assessment discovers every IoT and OT device on your network, scores
the risk each one carries, and shows where segmentation would actually reduce exposure.
 
 

Professional Service, expert-led, project-based work. Deep expertise, delivered with structure.

Where this sits

Part of the IT Infrastructure portfolio, Visibility Pillar

This service serves the IT Director KPI: Unmanaged Device Risk.

Pillar 01

VISIBILITY

IoT/OT Assessment finds what the standard network inventory misses.

Pillar 02

OPTIMIZATION

Findings scope segmentation and network redesign work.

Pillar 03

CONTINUITY

Managed Networking keeps segmented zones enforced going forward.

what it covers

What passive discovery finds.

Full device discovery

Every IoT and OT device on the network identified by traffic pattern, not by asking IT what it thinks is connected.

Risk scoring per device

Ranked by what the device can reach on the network, since a low-value sensor can still be the path to something critical.

Segmentation recommendations

Where isolating device classes onto their own network segment would meaningfully reduce exposure.

Vendor and firmware inventory

What is running unpatched, and which devices are past the vendor's own support window.

honest qualification

When this is the right move, and when it's not.

Start here if...

  • You suspect more is connected to your network than IT has ever formally inventoried.
  • You operate building automation, industrial control systems, or a large fleet of connected devices.
  • You need to show an auditor or insurer that unmanaged devices are accounted for.
  • You are planning network segmentation and need a real device inventory to design around.

 

Something else first if...

  • You already have a full device inventory and just need the network redesigned. Managed Networking is the faster path.
  • Your concern is standard IT endpoints, not IoT or OT devices specifically. Network Assessment covers that ground.
  • You are in an active incident right now. Emergency response, 24/7 is the right next step.

where this connects

This service rarely stands alone.

OFTEN PAIR WITH

Network Assessment

The two together give a complete picture of everything on the network.

See Network Assessment →

IMPLEMENTS THE PLAN

Managed Networking

Turns the segmentation plan into enforced, monitored network zones.

See Managed Networking →

IF DEVICES ARE COMPROMISED

Compromise Assessment

A forensic sweep if this assessment surfaces signs of active compromise.

See Compromise Assessment →

Questions we get asked

Straight answers before the call.

Will this disrupt operational technology or industrial control systems?

No. Discovery is passive, built from traffic analysis rather than active scanning, specifically because OT and ICS systems can be sensitive to active probing. Nothing is queried in a way that risks disrupting a live control system.

What counts as an IoT or OT device here?

Anything connected to the network that isn't a standard managed endpoint: building automation controllers, HVAC systems, badge readers, cameras, industrial sensors, smart displays and similar. If it has an IP address and IT didn't provision it, it's in scope.

 

Do you recommend specific replacement hardware?

This assessment identifies devices and risk, and recommends segmentation. Hardware replacement, where warranted, is scoped separately based on these findings.

 

How is this priced?

Fixed price by site and estimated device count, established on the discovery call, so the number doesn't move if the environment is larger than expected.

Find out what's actually on your network.

Get in touch to scope passive discovery across your sites.