Why cyber-physical assets are silently breaking enterprise risk management

Security teams get a clear, fast answer when a critical vulnerability alert targets a laptop, a server, or a traditional application. The same alert landing on a hospital scanner, a factory floor controller, or a building HVAC network triggers a different experience entirely, because the connected devices that run physical operations rarely identify themselves reliably on the network. New research on 17 million cyber-physical assets shows that 88 percent of those devices fail to transmit an exact product code and 76 percent send a code that does not match the vendor’s own record, leaving risk decisions built on inference instead of confirmed data.
How bad is the visibility problem on cyber-physical systems?
The problem is not concentrated in a few unlucky sectors. Across a dataset of 17 million cyber-physical assets, the research found that 88 percent of devices failed to transmit an exact product code, and 76 percent sent a code that did not match the vendor’s own catalogue entry. The gap shows up at the operating system layer too: 41 percent of devices had no OS version on file and 24 percent had no OS name at all.
The cause is rooted in how these systems were originally engineered and how they were later integrated into enterprise networks. Programmable logic controllers, medical imaging systems, and industrial sensors were designed for decades of physical reliability rather than tidy digital labeling. Network identification was rarely part of the original design brief, so the same device can present itself differently depending on which protocol or integration asks the question. When a CVE advisory arrives, the first question, does this alert actually apply to a specific device in our environment, becomes a multi-day investigation or a guess. CVE records themselves are compiled from the same patchy vendor information, so an official advisory can be just as incomplete as the network it is meant to protect.
What does this blind spot look like at the board level?
The pain surfaces as a vague, rising sense that risk cannot be quantified, rather than as a clearly labeled data problem. In a global survey of 1,100 security leaders, 44 percent named understanding their organization’s risk exposure as one of their biggest operational concerns, ahead of compliance pressure or budget constraints. A further 45 percent said they were struggling to reduce cyber risk to their most important assets and processes.
The connection between that struggle and an unreliable asset inventory is often missed entirely. Security teams reach for technical framing: missing product codes, inconsistent naming conventions, protocol mismatches. Business leaders hear none of that, and what they do hear is that risk cannot be quantified with confidence. Until the two conversations are joined, every risk register a CISO presents upward carries an asterisk that nobody in the room can see. Leadership reads the symptom: an impression of unmanageable risk. The cause sits underneath, in asset data that cannot answer the questions being asked of it.
How can teams turn guesswork into a confirmed answer?
Resolving the issue starts with a shift in what visibility means in an OT-adjacent environment. Knowing that a device exists on the network is only half the job. Knowing what it does, what physical process depends on it, and what happens if it is compromised is what makes a risk register useful under pressure.
Doing this at the scale of modern industrial and clinical estates requires specialized tooling to handle the proprietary and eclectic nature of these assets, along with automation that can cope with millions of endpoints. In one example from the research, applying AI-driven mapping techniques to a single vendor’s device catalogue lifted product code identification from 4 percent to 83 percent. The follow-through was just as significant: 56 percent of devices received a new or updated firmware recommendation as a result, and vulnerability identification accuracy improved by 25 percent.
Numbers like these change the question a security team can credibly answer. Instead of asking what is connected, teams can ask which systems would cause the greatest disruption if compromised, and act on the answer with confirmed data rather than inference. That is the practical difference between an asset inventory that exists on paper and one that holds up under an active CVE.
What should change in how organizations treat this problem?
Adding another tool to the stack will not fix the foundation. The shift that pays off is treating asset data quality as a board-level risk issue, alongside budgets, compliance, and third-party access. When the foundation is in order, a new CVE alert triggers the kind of confirmed, prioritized response security teams expect from any mature vulnerability management program, and the alert landing on a hospital scanner or a factory floor controller becomes no harder to act on than the one landing on a laptop.
The measure of progress is no longer whether alerts are arriving faster. It is whether the organization can name, with confidence, the assets a vulnerability actually affects, what those assets support, and what an attacker would gain by reaching them.
FAQ
What is a cyber-physical system and why does it matter for security?
A cyber-physical system is a connected device that runs a physical operation rather than just processing data, including medical imaging equipment, factory floor controllers, and building HVAC networks. Because these devices sit at the intersection of IT and operational technology, a successful compromise can affect physical safety and continuity, not only data.
Why can’t security teams match vulnerabilities to these devices quickly?
Most of these assets were built for physical reliability rather than clean network identification, and they often report different product codes depending on the protocol asking. Across 17 million assets studied, 88 percent failed to transmit an exact product code, and 41 percent had no operating system version on file, so confirming whether a CVE applies becomes a manual search.
How can organizations improve visibility on cyber-physical assets?
The research points to specialized tooling designed for the proprietary nature of these assets, combined with automated mapping of vendor catalogues. In one example, AI-driven mapping lifted product code identification on a single vendor’s catalogue from 4 percent to 83 percent and improved vulnerability identification accuracy by 25 percent.
This article summarizes reporting from techradar.com.