You cannot protect what you cannot see. OT asset inventories are stale spreadsheets, so vulnerable, unpatched or unknown devices sit exposed on plant networks.
"What is actually on our OT networks, and which of it is exposed?"
OT assets in view
Exposure mapping
Remediation