Back to Resources

From Best Practice to Obligation: Why OT Asset Discovery Just Got More Urgent

Key Takeaways

  • Asset visibility is moving from OT security best practice to a practical input for critical infrastructure compliance.
  • Claroty’s research found 88% of CPS assets do not transmit an exact product code, and 55% of OT environments carry four or more remote access tools, both compounding the visibility problem.
  • Proposed SOCI Act reforms would require governing bodies to approve Critical Infrastructure Risk Management Programs and obtain periodic independent assurance over them, neither of which is credible without an accurate asset register.
  • The proposed “relevant operator” concept would extend obligations to managed service providers, OEMs and platform administrators, widening the group of parties who need an accurate view of the environment.
  • Discovery works best as a scoped, time-boxed exercise, not an open-ended project.

Asset visibility has long been treated as OT security good practice: the kind of thing every maturity framework recommends and few organisations get around to finishing. That framing is changing. Reforms currently before the Australian Government would make an accurate, current asset register a practical precondition for meeting obligations under the Security of Critical Infrastructure Act 2018 (SOCI Act), not simply a technical nicety underneath them.

What the data shows

The scale of the underlying visibility gap is well documented. Claroty Team82’s research into cyber-physical systems asset identification found that 88 percent of CPS assets do not transmit an exact product code, and 76 percent transmit product names that differ from the vendor’s official record. This is not primarily a monitoring gap. It is an identification gap: even where a discovery tool is deployed and collecting data, accurately identifying what a given asset actually is remains genuinely difficult. That difficulty compounds elsewhere in the environment. Claroty’s research into remote access sprawl found that 55 percent of OT environments now contain four or more remote access tools, adding complexity that most OT teams do not have centralised visibility over. Separately, Claroty’s global survey of security professionals found that 45 percent are not confident in their ability to reduce risk to key CPS assets, nor in their overall understanding of their own risk posture. Organisations cannot govern what they cannot first, accurately, name.

Evidence Snapshot

  • 88% of CPS assets do not transmit an exact product code, and 76% transmit product names that differ from the vendor’s official record (Claroty Team82, Resolving the CPS Identity Crisis)
  • 55% of OT environments contain four or more remote access tools, expanding the attack surface and adding operational complexity (Claroty Team82, The Problem with Remote Access Sprawl)
  • 45% of security professionals are not confident in their ability to reduce risk to key CPS assets or in their overall understanding of their risk posture (Claroty, The Global State of CPS Security 2025)

Two reform mechanisms that turn visibility into an obligation

Two specific mechanisms in the current SOCI Act reform process connect asset visibility directly to compliance, rather than leaving it as an implied prerequisite. The first sits inside proposed changes to Critical Infrastructure Risk Management Program (CIRMP) governance. The Department of Home Affairs released its second-tranche consultation paper on 3 July 2026, responding to the Independent Review of the SOCI Act delivered by Dr Jill Slay AM in January 2026. Among the proposed changes, a responsible entity’s governing body or a senior manager would be required to approve the establishment, review and variation of the CIRMP, and responsible entities would be required to obtain periodic independent assurance that their CIRMP is appropriately designed and implemented. Neither obligation is credible against an incomplete or outdated asset register. A governing body cannot meaningfully approve a risk management program, and an independent assessor cannot meaningfully assure one, if the organisation does not have a current picture of what is actually connected to its OT environment. The second mechanism is the proposed introduction of a “relevant operator” concept, which would extend elements of SOCI obligations beyond the responsible entity itself to third parties with practical control over a critical infrastructure asset, including managed service providers, OEMs and platform administrators. This widens the group of parties for whom “knowing the environment” is a live compliance question, not just the asset owner.

Security of Critical Infrastructure Act 2018 (SOCI Act) – CIRMP Reforms

Governing body: Department of Home Affairs, via the Security of Critical Infrastructure Act 2018 (Cth) and its associated rules.

What it requires: under the current tranche two consultation, a responsible entity’s governing body or senior management would need to approve the establishment, review and variation of its Critical Infrastructure Risk Management Program, with CIRMPs reviewed at least every 24 months (and sooner following significant events), and periodic independent assurance obtained that the CIRMP is appropriately designed and implemented.

Who it applies to: responsible entities for critical infrastructure assets under the SOCI Act, with the proposed “relevant operator” concept extending elements of the obligation to managed service providers, OEMs and platform administrators with practical control over an asset. Sector and asset-class applicability is specific to each organisation; assess your own classification rather than assuming it based on industry alone.

Consequence of non-compliance: the reforms propose increased civil penalties and strengthened enforcement powers alongside the governance changes. Submissions on the consultation paper closed 31 July 2026; the final shape of penalties and commencement timing will depend on the legislation ultimately introduced.

Where the blind spots typically sit

The visibility gap is rarely evenly distributed. It concentrates in specific, predictable places. Legacy equipment bridged onto modern networks is one of the most common: machinery installed years or decades before network connectivity was ever a design consideration, now reachable from corporate IT because a historian, a vendor support link or a convenience integration was added somewhere along the way. Engineering workstations are another recurring blind spot, given the level of access they typically hold over controller logic and physical processes. None of this is exotic. It is the accumulated result of environments that have grown incrementally, often across multiple owners, integrators and site teams, without a single, current record of what is actually there.

Treating discovery as a scoped exercise

Comprehensive OT asset discovery does not need to be an open-ended project, and treating it as one is often why it stalls. A discrete, time-boxed discovery engagement, scoped to a specific site, business unit or asset class, tends to produce a usable, defensible asset register faster than an attempt to boil the entire environment at once. Passive network monitoring is the appropriate starting point for most OT environments, given the sensitivity of actively probing production control systems. Claroty and Nozomi Networks, both Orro technology partners, are platforms Orro deploys for this kind of passive OT visibility work, alongside the broader discovery methodology.

Orro’s view

If your organisation falls within scope of the SOCI Act, or could reasonably fall within an expanded scope under the current reform proposals, an accurate OT asset register is no longer purely a technical exercise sitting underneath compliance. It is increasingly the evidentiary foundation the incoming governance requirements assume already exists. That applies directly to the OT/IT convergence conversation explored in SOCI Act reforms: what the tranche two consultation means for your organisation elsewhere in this edition. Submissions on the current consultation paper closed 31 July 2026, and the shape of the final reforms is expected to become clearer over the coming months as the Government works through the feedback received. That makes it worth assessing your organisation’s exposure now, while the legislation is still being finalised, rather than waiting until obligations take effect. This mirrors a pattern we’ve seen play out in a different framework: compliance activity that outpaces the underlying maturity work it’s meant to reflect. See Beyond the Checkbox: Why Essential Eight Compliance Without Maturity Is a False Sense of Security for a closer look at that gap. Orro works with critical infrastructure operators across mining, manufacturing, utilities, transport and logistics, and healthcare to scope and run OT asset discovery engagements, connecting the resulting asset register to broader SOCI compliance and CIRMP work. Learn more about Orro’s Critical Infrastructure services.


Sources and Further Reading

  • Claroty Team82 (2025) – Resolving the CPS Identity Crisis
  • Claroty Team82 (2024) – The Problem with Remote Access Sprawl
  • Claroty (2025) – The Global State of CPS Security 2025: Navigating Risk in an Uncertain Economic Landscape
  • Department of Home Affairs (2026) – Streamlining and Modernising the Security of Critical Infrastructure Act 2018 Consultation Paper
  • Independent Review of the Security of Critical Infrastructure Act 2018, Dr Jill Slay AM (January 2026)