Why Cyber Asset Visibility Matters More Than Ever
The California wildfire crisis reshaped the utility industry's approach to risk. Investigations into major wildfire events underscored the need for strong infrastructure, asset maintenance, operational oversight, vegetation management, and timely risk identification. Litigation and regulatory actions led utilities to invest billions in grid modernization, advanced monitoring, asset management, inspection technologies, and operational resilience.
Suchismita Chatterjee, a cybersecurity product specialist who works on governance, risk, and compliance for a large U.S. electric utility, approached the problem from a different angle. "My work did not focus directly on wildfire prevention," she said. "It addressed an equally critical question."
Working within the U.S. utility sector, Chatterjee has supported cybersecurity initiatives for North American Electric Reliability Corporation (NERC) regulated environments, helping enhance identity governance, secure access management, and cybersecurity controls aligned with NERC Critical Infrastructure Protection (CIP) requirements. Her work bridges cybersecurity engineering and product strategy to improve security and enable operational efficiency.
Chatterjee led the initiative of enterprise asset visibility—one of the most fundamental challenges in operational technology (OT) cybersecurity. At one of the largest utility providers in the United States, serving over 16 million customers, that meant building a robust strategy and calculation to understand the asset counts and the visibility of assets connected to the network. That coverage had to extend to all ODN and UDN network assets, irrespective of their activity status. Establishing it gave the organization substantially more confidence in asset data scanning and vulnerability management.
By helping improve the visibility, governance, and accountability of cyber assets across complex utility environments, she has supported stronger vulnerability management, risk assessment, and security decision-making. Her work emphasizes that effective cybersecurity begins with knowing what assets exist, who owns them, and how they are protected.
Can an organization confidently identify, govern, and trust every digital asset that supports critical grid operations?
This question is increasingly important as today's electric grid relies on more than just physical infrastructure. Modern utilities depend on a complex digital ecosystem, including engineering workstations, operational technology, remote sensors, intelligent electronic devices, communication gateways, identity platforms, asset management systems, environmental monitoring technologies, and thousands of interconnected applications.
Every one of those systems is a cyber asset. Every one of those assets must be visible.
And every one of those assets must be governed. In her work, Chatterjee focused on strengthening enterprise cyber asset visibility by identifying why legitimate assets disappeared from organizational awareness. These assets were not compromised but often changed operational states, became intermittently connected, or fell outside traditional discovery processes.
Instead of repeatedly reconciling inventory reports, she focused on understanding the root causes of visibility gaps. This approach led to a more sustainable governance model.
Answering this question improved accountability for asset ownership, strengthened lifecycle governance, and increased confidence in enterprise cyber inventories across complex operational environments.
Supporting Grid Resilience
A monitoring platform is only reliable if its supporting infrastructure is well governed.
An engineering workstation cannot be relied on if ownership, configuration, or lifecycle status is unknown.
An operational system cannot be effectively secured if it is outside enterprise visibility.
This is where cyber asset governance becomes strategically important. Although asset visibility alone does not prevent wildfires, it strengthens the cybersecurity foundation that supports modern operational capabilities. Improved visibility enables stronger vulnerability management, clearer ownership, better configuration control, more reliable incident response, and greater confidence in the digital technologies supporting grid operations.
Ultimately, resilient infrastructure begins with trusted information.
Before organizations can detect threats, respond to incidents, modernize operations, or improve resilience, they must first know what technology they own, where it resides, who is responsible for it, and whether it remains governed throughout its lifecycle.
That philosophy guided her work.
It was not simply about improving an inventory; it was about strengthening the digital foundation that enables modern critical infrastructure to operate more securely, more reliably, and with greater operational confidence in an increasingly complex threat landscape.
For more than a century, the electric grid has been viewed primarily as a physical engineering achievement—an interconnected network of power plants, substations, transformers, transmission lines, and distribution systems designed to deliver electricity safely and reliably.
Today, however, the grid has evolved into one of the world's most complex cyber-physical systems. Behind every megawatt delivered to homes, hospitals, manufacturing plants, and emergency services exists an equally sophisticated digital ecosystem that monitors, controls, protects, and maintains crucial operations.
Modern power infrastructure depends on thousands of operational technology (OT) devices, industrial control systems (ICS), engineering workstations, intelligent electronic devices (IEDs), supervisory systems, communication gateways, remote sensors, field laptops, cloud platforms, identity management services, and cybersecurity monitoring tools. These technologies together form the digital nervous system of the modern grid.
As utilities continue deploying renewable energy, battery storage, advanced automation, predictive analytics, artificial intelligence, and distributed energy resources, cybersecurity has moved beyond a technology discipline. It has become an operational necessity that directly supports grid reliability, resilience, and public assurance.
Despite significant advances in cybersecurity, one of the industry's most critical challenges often remains unseen. Organizations cannot secure systems they cannot accurately identify. This principle has become a defining cybersecurity challenge for critical infrastructure worldwide.
Cybersecurity Begins with Visibility
Public discussions about critical infrastructure cybersecurity often focus on ransomware, nation-state threats, malware, and zero-day vulnerabilities. While these risks are real and growing, experienced professionals recognize that many security failures begin much earlier in the defense lifecycle. These failures often start with incomplete visibility.
Every cybersecurity control depends upon understanding what technology actually exists inside an environment. Vulnerability management requires accurate inventories. Identity governance requires known endpoints. Security monitoring depends upon trusted asset baselines. Incident response relies on knowing which systems are affected. When organizations lose visibility into parts of their infrastructure, all subsequent security processes become more challenging. Unknown assets are not necessarily unauthorized devices.
Many are entirely legitimate. Some operate only during scheduled maintenance windows. Some support engineering operations. Others remain powered down until emergency response activities require them. Still others exist within geographically remote operating environments where connectivity remains intentionally intermittent.
Although these systems serve legitimate operational purposes, they often fall outside standard enterprise discovery methods.
Traditional scanning techniques perform exceptionally well when systems remain continuously connected. They are much less effective when assets remain offline for extended periods.
Those intermittently connected devices eventually reconnect to production environments.
When they do, they immediately become part of the organization's cyber-attack surface.
Recognizing this operational reality formed the basis of Chatterjee's work in enterprise cyber asset governance.
Looking Beyond Asset Counts
While supporting cybersecurity governance initiatives within a large-scale critical infrastructure environment, Chatterjee encountered an enterprise-wide challenge: achieving visibility into cyber assets across an ecosystem of hundreds of thousands of technology assets spanning operational and enterprise environments.
Leadership initially focused on reconciling inventory discrepancies.
- How many assets were missing?
- Why were different governance systems reporting different totals?
- Could every device be accounted for?
These questions appeared straightforward. The answers were not.
Reconciling individual records in such a large environment would require significant effort and yield only temporary improvements. Instead of focusing on the numbers, Chatterjee recommended examining the processes that generate them. This shift changed the discussion. Rather than asking where assets disappeared, she focused on why enterprise governance systems lost visibility of them.
The investigation revealed that many discrepancies were not technology errors. Instead, they were governance challenges resulting from differences in operational lifecycles, ownership accountability, synchronization timing, and asset behavior across environments. Identifying these root causes proved more valuable than repeatedly correcting inventory reports.
Understanding ODN and UDN
Large utility environments typically include multiple operational network domains designed to support different business and operational functions. Although naming conventions vary between organizations, Operational Data Networks (ODNs) generally support operational technology environments associated with power generation, field operations, engineering systems, industrial control platforms, and other operational processes that require high reliability and disciplined change management.
Utility Data Networks (UDNs), by contrast, regularly support broader enterprise services, business applications, administrative functions, collaboration platforms, analytics, and organizational workflows that enable day-to-day utility operations.
Both environments are essential. Neither operates in complete isolation. Engineering data, operational planning, maintenance scheduling, cybersecurity monitoring, identity governance, compliance reporting, and asset management frequently depend upon secure interactions spanning multiple technology domains.
Because these environments serve separate operational purposes, they also exhibit different technology lifecycles, ownership models, connectivity schemes, maintenance schedules, and cybersecurity requirements. Maintaining accurate visibility across both environments is a governance challenge, not just an inventory task.
A cyber asset that disappears from visibility within either domain does not necessarily disappear from operational reality. Instead, it may become significantly more difficult to monitor, assess, govern, and secure. Recognizing this distinction became central to Chatterjee's approach. Rather than viewing asset discrepancies as isolated reporting errors, she saw them as opportunities to strengthen enterprise governance.
This perspective led to a methodology focused not only on counting assets, but on understanding why visibility gaps occur and how organizations can systematically reduce them to improve cybersecurity maturity.
Looking Past the Numbers: Finding the Story Hidden Inside 800,000+ Cyber Assets
What follows is Chatterjee's account of the project in her own words.
The deeper I went into the project, the more I realized that the problem wasn't about missing assets—it was about missing context. At first, everyone naturally wanted the same answer.
"How many assets are we missing?"
It made sense. If different systems reported different inventory numbers, the obvious response was to reconcile the counts until they matched. However, I sensed there was a deeper issue.
If I spent weeks or months reconciling numbers, the discrepancies would likely reappear the following month. This would address the symptom, not the underlying cause. I kept asking myself a different question.
Why are perfectly legitimate cyber assets disappearing from enterprise visibility in the first place?
This question became the turning point. Instead of investigating spreadsheets, I started investigating the processes that produced those spreadsheets. The findings were unexpected.
The majority of discrepancies weren't caused by broken technology. They weren't necessarily software defects. They weren't cyberattacks. More often than not, they were governance gaps.
When "Offline" Doesn't Mean "Gone"
One misconception about cybersecurity is that every important asset is online all the time.
That isn't true in large operational environments. Many devices only connect during maintenance activities. Some engineering systems remain powered down until scheduled work begins. Certain field devices may remain in storage for weeks or months before returning to service. Portable maintenance laptops travel between locations. Replacement equipment waits on shelves. Backup systems remain dormant until they're needed. None of these assets are malicious. But from a cybersecurity perspective, they create an interesting challenge.
Traditional asset discovery tools are exceptionally good at finding systems that are currently communicating. They're much less effective at explaining why legitimate devices temporarily disappear from view. When those devices reconnect, they instantly become part of the organization's attack surface.
If no one knows they're coming back online—who owns them, whether they've been patched, or whether they're still configured correctly—it creates unnecessary operational uncertainty. This realization prompted a change in my approach.
Muted Assets: The Blind Spots Nobody Intends to Create
As I analyzed the data, I noticed that many assets followed a similar pattern.
They weren't permanently disconnected. They were simply quiet. They would disappear for long periods before reappearing during operational activities. Internally, I began referring to these as muted assets. The name wasn't meant to describe a technology. It described behavior.
A muted asset still exists. It still belongs to the organization. It may still perform an important operational function. It's simply not visible enough for traditional discovery mechanisms to maintain continuous awareness. The opposite category consisted of assets that remained sufficiently active to participate in routine monitoring, vulnerability scanning, compliance reporting, and operational governance. Those became non-muted assets. The distinction sounds simple.
In practice, this perspective fundamentally changed my view of enterprise cybersecurity. Instead of treating every inventory discrepancy as identical, I could begin understanding why different assets behaved differently throughout their lifecycle. This outlook shifted the focus from counting devices to understanding operational behavior.
Why ODN and UDN Matter
One of the most fascinating aspects of utility cybersecurity is recognizing that not every network serves the same purpose. Operational and enterprise environments address different challenges.
Although every organization uses its own terminology, Operational Data Networks (ODNs) generally support technologies directly involved in operational activities—engineering systems, industrial control environments, maintenance platforms, and infrastructure that demands extremely disciplined change management because reliability is of utmost importance.
Utility Data Networks (UDNs), meanwhile, commonly enable broader enterprise operations, including collaboration platforms, identity services, business applications, analytics, compliance functions, and the administrative workflows that keep large organizations running efficiently.
On the surface, they may appear to be just two different networks. From a cybersecurity perspective, they are two ecosystems with distinct operating characteristics. Assets move differently. Maintenance cycles differ. Ownership models vary. Network patterns aren't always the same.
Cybersecurity controls may also differ depending on business requirements. This means visibility is much more than an inventory exercise. If an engineering workstation temporarily disappears from governance processes, it hasn't disappeared from reality. If a maintenance device reconnects after months of inactivity, it still requires governance. If ownership information becomes outdated, cybersecurity teams lose confidence in their ability to manage risk efficiently. The challenge isn't simply identifying assets. It is about sustaining confidence in those assets throughout their entire lifecycle.
Following the Story Instead of the Spreadsheet
One lesson from this project has remained with me.
Data always tells a story. You simply need to know where to look. Instead of comparing inventory reports line by line, I traced the lifecycle of assets across multiple governance processes.
- Where did they originate?
- When were they created?
- When did they become inactive?
- Who owned them?
- What happened when ownership changed?
- Why did one governance system continue tracking an asset while another no longer did?
These questions revealed relationships that raw asset counts could not. Patterns began to emerge.
Many discrepancies appeared during operational transitions. Others occurred because ownership records weren't synchronized across several processes. Some reflected perfectly legitimate operational behavior that existing governance logic simply didn't account for. Once these relationships were visible, resolving the problem became much easier.
Rather than repeatedly correcting reports, we could improve the governance processes that generate them. This is a much more sustainable solution.
Correlation Instead of Reconciliation
The project gradually evolved from an inventory exercise into something much larger.
Instead of manually reconciling hundreds of thousands of individual records, I prioritized building correlation logic to explain why assets appeared—or failed to appear—across different governance workflows. That distinction matters. Reconciliation tells you what happened.
Correlation helps explain why it happened—understanding the "why" allows organizations to improve processes rather than repeatedly correcting outcomes.
For leadership, this shifted the conversation dramatically. Instead of asking why one report showed a different number than another, discussions increasingly focused on strengthening the enterprise governance model itself. This ultimately provides far greater long-term value.
Why This Matters Beyond Cybersecurity
One thing I appreciate about infrastructure cybersecurity is that its impact often extends far beyond cybersecurity teams.
- Better asset governance benefits engineering.
- It benefits compliance.
- It benefits operations.
- It benefits maintenance planning.
- It benefits incident response.
- It benefits executive decision-making.
Most importantly, it enhances organizational confidence.
When organizations trust their cyber asset inventories, they can make operational decisions with greater certainty.
- They know who owns systems.
- They know which devices require attention.
- They know where vulnerabilities exist.
- They know which assets are active, inactive, or transitioning through different operational states.
This level of visibility reduces uncertainty throughout the organization.
The Connection to Power Grid Resilience
People often ask how asset visibility relates to power grid resilience.
The connection isn't always obvious until you step back. Modern electric grids depend on thousands of digital technologies working together, including engineering workstations, remote sensors, monitoring platforms, identity systems, communication gateways, industrial controllers, maintenance equipment, environmental assessment technologies, and fault detection systems.
Every one of these technologies depends upon cybersecurity governance. If organizations lose confidence in the digital systems that support operations, maintaining reliable infrastructure becomes significantly more difficult. Strong asset governance doesn't generate electricity. It doesn't extinguish wildfires. It doesn't repair transmission lines. It provides the trusted digital foundation that enables these operational capabilities to function securely and reliably.
During periods of elevated wildfire risk, utilities increasingly rely on digital technologies for weather awareness, remote monitoring, inspections, communications, equipment status, and operational coordination. These capabilities depend on secure, well-governed cyber assets.
Maintaining visibility into these assets ensures that supporting technology remains trustworthy, available, and well-managed throughout its lifecycle. That realization reinforced something I now believe strongly.
Cybersecurity isn't only about defending against attacks. It's about creating confidence that systems are known, that ownership is clearly defined, and that the technology supporting critical operations remains visible, governed, and ready when it is needed most. In critical infrastructure, confidence is one of the most valuable security controls an organization can have.
Swati Khandelwal https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQQyjwPYjJP0wddSEB8Dlpr3dlnQUs52-WmlrZfqJoBPeOvv2Zoqlq-FhEAz_Xeprj_mtrI1MGCW1JS840JUjVEK6VoNe6zCNNTw_7YmyvNmf3E5pprZ3zqP8lszq74Wt97SvbJo5yeuyep0U6-nGs0vdarg4_WUrc5r6L0ML0xE-BsPipJd2-1PMHTvO1/s76-e365/thn.jpg


