SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
Flux result c7112620 ee78 433f 9a4b 3ca2ccf1b56c

Tenable launches OT asset discovery engine for security

Wed, 15th Apr 2026

Tenable has launched an OT asset discovery engine for its security products. The tool is designed to identify cyber-physical assets without requiring additional hardware or software agents.

The feature is now available to customers using Tenable One, Tenable Vulnerability Management and Tenable Security Centre. It is intended to help security teams bring operational technology, internet-connected devices and unmanaged assets into a single view alongside IT, cloud and identity exposures.

Asset visibility in operational technology environments remains a challenge for many organisations. Security teams often need specialist sensors, separate deployments or additional software to discover devices on factory floors, in buildings and across other physical environments connected to digital networks.

Tenable has built the new OT discovery engine directly into its core vulnerability management offerings, removing the need for separate infrastructure and giving customers a faster way to begin identifying cyber-physical assets.

The launch reflects a broader shift in security responsibilities. Many Chief Information Security Officers now oversee operational technology as well as traditional IT systems, while the boundary between the two environments has become less distinct.

That convergence has widened the range of assets exposed to cyber threats. Tenable says cyber-physical systems now extend beyond industrial sites into settings such as hospitality venues, education estates, offices and data centres, including assets such as HVAC equipment, printers and badge readers.

The company also cited industry research suggesting cyber and cyber-physical attacks are set to rise sharply in the coming years. It pointed to data indicating that a large share of modern OT compromises begin in IT environments, underscoring how weaknesses in one part of a network can affect physical operations.

Early Findings

In early access deployments, customers found substantial numbers of previously unknown OT and IoT assets after first using the tool. According to Tenable, most uncovered between 100 and more than 1,000 unique assets, and some of those assets had critical vulnerabilities.

Early users came from sectors including hospitality, financial services, education, food and beverage, and government. The findings suggest that many organisations still lack a complete inventory of connected devices outside conventional IT asset registers.

Incomplete asset inventories have become a persistent problem for cyber defence teams. Without knowing which devices are present, organisations may struggle to patch weaknesses, monitor risky behaviour or meet audit and regulatory requirements tied to operational resilience and critical systems.

The new engine is intended to reduce that gap by giving users immediate visibility into asset details such as vendor, model, firmware and operating state. It is also designed to support compliance work by avoiding lengthy procurement and deployment cycles for dedicated OT tools.

Platform Push

The update also fits into Tenable's broader effort to position exposure management as a single discipline across technology domains. By placing OT discovery inside existing products, the company is aiming to tie cyber-physical risk more closely to the same workflows used to track vulnerabilities in IT, cloud and identity systems.

That approach may appeal to customers trying to reduce the number of separate security consoles and specialist tools they use. It also gives Tenable a simpler way to expand its reach in OT security by starting with discovery rather than requiring customers to deploy a full standalone platform from the outset.

Tenable already sells a separate product, Tenable OT Security, for organisations with more advanced operational technology requirements. The new discovery engine provides a lighter entry point for customers that need basic visibility first or want to identify hidden devices before deciding on broader OT security controls.

"Cyber-physical risk can't remain a blind spot in exposure management. We're giving organizations an immediate, low-friction way to bring OT into scope, so they can gain visibility, meet compliance requirements and start reducing risk from day one, without adding new infrastructure," said Eric Doerr, Chief Product Officer, Tenable.

"For existing customers with more complex use cases, we offer Tenable OT Security, a comprehensive OT solution that delivers visibility, security and control for proactive risk reduction across today's rapidly converging OT/IT environment," Doerr added.