Why poor asset data is undermining cyber-physical risk management

New research across 17 million cyber-physical assets shows most fail to report an exact product code, leaving security teams guessing when vulnerabilities hit.

New research across 17 million cyber-physical assets shows that most devices fail to report an exact product code to the network, which turns routine vulnerability alerts into multi-day guessing games and leaves leaders uncertain about their actual exposure.

The data gap hiding inside critical infrastructure

When a critical vulnerability alert lands in a traditional IT environment, it is rarely a cause for panic regarding the operational continuity of the business. The affected laptops, servers, and applications can be identified quickly, and a good team can catalogue and patch them within hours. The same alert landing across a hospital’s imaging equipment, a factory floor’s control systems, or a building’s HVAC network tells a different story. These cyber-physical systems sit at the sharp end of IT and OT convergence. Confirming whether an alert even applies to a specific device can take days, and often ends in a guess rather than an answer.

The root cause is product code quality. Across a dataset of 17 million cyber-physical assets, research from Claroty found that 88% failed to transmit an exact product code, and 76% sent a code that did not match the vendor’s own record. Programmable logic controllers, medical scanners, and industrial sensors were engineered for decades of physical reliability, not for tidy digital labeling. Network identification was rarely part of the original design brief, so the same device can report itself differently depending on which protocol or integration is asking.

The operating system picture is just as patchy. In the same dataset, 41% of devices had no OS version available and 24% had no OS name at all. Without those details, matching a device to a known vulnerability stops being a quick database lookup and becomes a manual search.

Why the alert itself cannot be trusted

CVE advisories, the industry’s standard mechanism for tracking vulnerabilities, are compiled from this same patchy vendor data. An official advisory can be just as incomplete as the network it is meant to protect. That mismatch is what makes a single incoming alert so hard to act on, even when the alert looks well-formed on paper.

Applying AI-driven mapping techniques to an original equipment manufacturer’s device catalogue lifted product code identification from 4% to 83%, turning a near-blind spot into a near-complete picture. As a follow-through, 56% of devices received a new or updated firmware recommendation as a result, and vulnerability identification accuracy improved by 25%.

How the gap shows up at the boardroom level

The visibility problem flows straight into leadership conversations. Among 1,100 security leaders surveyed globally, 44% named understanding their organization’s risk exposure as one of their biggest operational concerns, more than compliance pressure or budget constraints. A further 45% said they were struggling to reduce cyber risk to their most important assets and processes, yet the connection between that struggle and an unreliable asset inventory is often missed entirely.

Leadership sees the symptom, a rising sense that risk is unmanageable, without ever seeing the cause sitting underneath it. Security teams that start describing the problem in terms of missing product codes and inconsistent naming conventions will not get far. Business leaders hear none of that; they hear only that risk cannot be quantified with confidence. Until those two conversations are connected, every risk register that a CISO presents upward carries an asterisk that nobody in the room can see.

What works: treating asset data as a board-level risk

Resolving this issue starts with a shift in what visibility means. Knowing a device exists on the network is only half of the job. Knowing what it does, what process depends on it, and what happens if it is compromised is what actually makes a risk register useful. Achieving this shift at scale requires specialized tools to manage the often eclectic and proprietary nature of cyber-physical assets, and an automated approach to cope with the scale.

Numbers like these change the question security teams can answer. Instead of asking what is connected to the network, teams can ask which systems would cause the greatest disruption if compromised, and act on the answer with confidence rather than inference. That is the difference between an asset inventory that exists on paper and a resilient one that holds up under pressure.

None of this gets solved by adding another tool to the stack. Asset data quality has to be treated as a board-level risk issue rather than background IT housekeeping, with the same scrutiny applied as to budgets, compliance, and third-party access. A new CVE alert should then trigger a confirmed, prioritized response rather than a scramble to work out which critical devices might be affected.

FAQ

What is the main visibility problem with cyber-physical systems?

Research across 17 million cyber-physical assets found that 88% failed to transmit an exact product code and 76% sent a code that did not match the vendor’s own record, making it hard to confirm whether a vulnerability alert applies to a specific device.

Why are cyber-physical assets so hard to identify on a network?

Cyber-physical devices such as PLCs, medical scanners, and industrial sensors were engineered for long physical service life rather than for clean digital labeling, so the same device can identify itself differently depending on the protocol or integration that asks.

How can organizations improve cyber-physical asset visibility?

Treat asset data quality as a board-level risk issue, use specialized tools with an automated approach for proprietary cyber-physical assets, and reframe visibility around what each device does and what depends on it rather than only that it is connected.


This article summarizes reporting from techradar.com. See our editorial disclaimer for how our articles are produced.

🤖
Is your business visible to AI assistants?

Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.

Check Your Score →