Operational technology environments present a visibility problem that traditional endpoint management tools were never designed to solve. On the industrial shop floor, programmable logic controllers, HMIs, and other OT devices can't run a Tanium client—or any client. Yet these devices control critical production processes, carry firmware vulnerabilities, and often go untracked in spreadsheets that haven't been updated in years. For organizations running global manufacturing operations, the gap between what IT knows and what's actually running on the plant floor is a serious security and compliance risk.
Aaron walks through how Tanium's new OT capabilities close that gap by extending an existing Tanium client into an OT satellite: a configuration that uses native industrial protocols, specifically Ethernet IP and Profinet, to discover OT devices and pull back make, model, firmware, and serial number data. That data flows directly into the Tanium platform, where it surfaces in Tanium Comply for vulnerability assessment, in inventory reports for asset management, and in integrations with ServiceNow and CMDB for remediation workflows.
If your organization manages manufacturing environments, operates across segmented OT networks, or has ever tried to answer the question "What devices do I actually have on the shop floor?", this episode is essential viewing. Aaron's live demo shows the full workflow, from enabling an OT satellite to seeing Rockwell and Siemens devices appear in Tanium in real time, and the results from early adopters in private preview are striking. Watch the full video below.
Key takeaways
- OT devices can't run agents: Programmable logic controllers, HMIs, and other OT devices on the industrial shop floor can't run a Tanium client or any client, yet customers still need to understand what they have in their environment so they can understand and protect what they have.
- Asset inventory is the starting point: The data Tanium retrieves from OT devices includes make, model, firmware, and serial number—the foundation customers need to build out an asset inventory and understand what they have in their environment.
“The data we're trying to get back from these devices is we're trying to understand that make, model, firmware and serial number that helps these customers understand and build out that asset inventory.”Tanium Product Manager Aaron Sipe
- OT satellite uses native protocols: An existing Tanium client can be promoted to an OT satellite—the same workflow used for Tanium Discover—and configured to speak Ethernet IP, Profinet, or both, targeting Rockwell, Allen Bradley, and Siemens, as well as many other vendors within the manufacturing space.
- Discovery respects device sensitivity: Rather than scanning ports or attempting every possible connection method, the OT satellite uses vendor native protocols in the way those devices expect, so it is designed to reduce the likelihood of unexpected behaviors that could disrupt fast-moving or otherwise sensitive equipment.
“We're not going through and trying to interrogate them repeatedly and try every different way to get visibility because we know that these devices can be sensitive to that. So we want to introduce the behavior that they expect so that we can get the data that we need.”Tanium Product Manager Aaron Sipe
- Vulnerability data flows into Comply: OT device data maps directly into Tanium Comply, where customers can see critical findings for OT devices alongside their other endpoints, enabling a holistic view of the threat landscape across both IT and OT.
- Remediation uses existing workflows: Tanium doesn't take direct action against OT devices, but it allows customers to send data to ServiceNow or a CMDB, and to remote into devices using the Tanium client to use vendor software for firmware upgrades and vulnerability mitigation.
- Segmented networks are supported: Just as the Tanium client can operate within segmented networks today, OT devices in isolated network segments don't need a route out to the Tanium platform—the Tanium client handles getting that data out.
- Private preview revealed unknown devices: Early adopters in private preview found more OT devices than they expected, confirming that understanding what assets exist in these environments is a complicated question to answer.
“There's been situations where there was a number of devices we expected to find and there was a number that was greater than that that we found, which really shows that the visibility here and understanding what assets do I have can be a really complicated question to answer.”Tanium Product Manager Aaron Sipe
Additional resources
- Tanium OT visibility and endpoint management for industrial environments: Learn how Tanium extends endpoint management to OT devices in manufacturing and industrial environments, including asset inventory, vulnerability assessment, and integration with existing IT workflows.
- Tanium Asset Discovery & Inventory: Learn how Tanium provides complete, real‑time visibility into managed and unmanaged endpoints to reduce risk, optimize costs, and support operations, security, and risk teams with high‑fidelity data.
- How to monitor OT devices and surface vulnerability data in Tanium: Technical documentation covering how to view and assess OT device data within Tanium, including how findings for industrial devices appear alongside traditional endpoint data.
