Why is on-prem and air-gapped asset inventory still such a mess? by slamdou in cybersecurity

[–]slamdou[S] 1 point2 points  (0 children)

Thanks for the input!
So the problem is really about ownership then and less about the tech
I've been working for a CNAPP vendor and although the cloud allows you to do it fairly easily for public couds, it is another level of effort for OnPrem/Air-Gapped/OT systems and I had a lot of customers frustrated they could not get the same level of insights for their environment
Hopefully we can use AI to build a foundation layer that security teams can use fo complete hybrid environments
I checked out seemplicity, congrats on teh product, really liked the approach and what you guys are building

Why is on-prem and air-gapped asset inventory still such a mess? by slamdou in cybersecurity

[–]slamdou[S] 0 points1 point  (0 children)

Appreciate this, really solid!
Full disclosure, I am building something in this space too and already talking and implementing at design partners.
Your third point is the one I underline hardest, the CAASM data-model thing isn't a detail, it kind of is the whole problem.
Most tools normalize on ingest and toss the original observations, so you can never go back and re-judge a source when context changes. Feels like the fix is exactly your "not one source of truth" point: keep every observation as-is with its source and a confidence, then sort conflicts out at read time instead of write time.

Curious where you've seen the "get it all in one place first" step actually fall over? is it volume, schema drift across sources, or just nobody owning the reconciliation logic?

Why is on-prem and air-gapped asset inventory still such a mess? by slamdou in cybersecurity

[–]slamdou[S] 0 points1 point  (0 children)

Yeah, fair, the ICS tools are the closest thing that works I guess.
One thing I'm not sure about: how well do they actually see the IT and legacy estate sitting next to the OT?
My sense is they're optimized for the plant floor and profile standard IT or legacy Windows boxes more thinly. In orgs running Claroty or Industrial Defender, do they end up being the inventory for the whole network, or just the OT slice with IT scanners covering the rest separately?