Security teams can often identify and patch vulnerable laptops, servers and applications within hours. Cyber-physical systems (CPS), however, can be much harder to assess when a vulnerability alert arrives.
CPS includes connected equipment such as hospital imaging devices, factory control systems and building HVAC networks. These systems operate where IT meets operational technology (OT), but confirming whether an alert applies to a specific device can take days and may end in a guess.
Research covering 17 million cyber-physical assets found that 88% failed to transmit an exact product code, while 76% sent a code that did not match the vendor's record. Operating-system information was also incomplete: 41% of devices had no OS version available and 24% had no OS name.
That missing data makes vulnerability matching less suitable for quick database lookups or automation. CVE advisories can also be incomplete because they rely on the same vendor information.
Among 1,100 security leaders surveyed globally, 44% said understanding their organization's risk exposure was a major operational concern, and 45% said they struggled to reduce cyber risk to their most important assets and processes.
In one example, AI-driven mapping increased product-code identification from 4% to 83%. A further 56% of devices received a new or updated firmware recommendation, while vulnerability-identification accuracy improved by 25%.
Comments
0No comments yet. Be the first to comment.