lean ot/ics asset management

Identify, inventory and manage your PLCs, RTUs, and network gear with a software-only solution. No hardware appliances & SPAN ports needed. On-premise or SaaS.

Experience the OT-BASE difference

Let’s face it: You want an OT/ICS asset inventory. You need an OT/ICS inventory. You’re past the stage of improvised, outdated Excel spreadsheets and Visio diagrams. You need automation and scalability. What you don’t want is a solution that expects you to install a hardware appliance in every subnet, configure SPAN ports, and consume man-months of consulting services by the vendor’s solution architects.

OT-BASE is an asset management platform for large organizations which want to inventory and manage their digital OT infrastructure but play it lean. The value of OT-BASE is not just alleged risk reduction of imagined cyber attacks. It’s measurable efficiency gains for engineering and maintenance.

OT-BASE shows more asset details than any “ICS detection” product, and even more than IT asset management systems: Installed hardware products (vendor, model, version), hardware configuration (such as installed I/O modules), installed firmware, OS, patches, and software along with version and installation date, known security vulnerabilities, product web page URL, product lifecycle stage, published product description, network topology, and much more.

Without OT-BASE:
Tool-centric workflow

Excel, Visio & wiring diagrams… because you didn’t have anything better

Without OT Base
Configuration details of control networks, PLCs, software versions etc. are scattered across dispersed files. Stored in different folders, on different servers, and locked in silos. Data acquisition is manual, resulting in incomplete and outdated information. Workflow automation is completely missing. It’s like being stuck in the Nineties.

User-centric Workflow

Designed for the way control engineers & admins want to work

Automatic discovery of the identity and configuration of your digital OT assets and networks. Consolidation of OT configuration details in a central platform, accessible by web browser and REST API. System details are no longer known to individual engineers only, but are instantly available to every team member, turning everyone into an expert.

OT-BASE isn’t about hackers. It’s about YOU.

Unlike “ICS detection” solutions which put all the emphasis on hypothetical cyber attacks and the potential threat actors behind them, OT-BASE focuses on you. Its prime focus is the people responsible for keeping OT infrastructures reliable, safe, and secure.

OT-BASE helps engineers, maintenance specialists, system administrators, and auditors to get more stuff done quicker. It covers the most basic (yet important and time consuming) activities such as IP address management as well as the most complex tasks, such as mapping multi-site network architectures.

It will make you more efficient, and make your work more fun, too — because nobody likes to work with inappropriate tools. OT-BASE also opens up a whole new level of teamwork because you can share OT insights and configuration details with coworkers, contractors, and vendors.

Hardware Inventory

Get a listing of all OT devices, both bare metal and virtualized, that can be filtered by location, device category, IP address and more. Get a listing of all devices of a specific make and model.

Software Inventory

Get a listing of operating systems, software applications, and firmware along with exact version numbers. Get a listing of all software installations for a specific product and version, along with license keys. Identify all devices where a specific software, firmware, OS version is installed within seconds.

Vulnerability Management

See vulnerabilities published in NIST’s National Vulnerability Database that affect your installed base, associated with the software & hardware products you are using, and with individual devices.

Configuration Management

Plan and monitor configuration change with a straightforward workflow. Check configuration change, no matter if planned or unauthorized, by using a change history that is automatically maintained for every device. Use baselines to define and audit reference configurations.

Network Topology

Get accurate and complete interactive network diagrams which allow you to drill down into device configurations and subnets. Focus on layer 2 or layer 3 information by selectively enabling or disabling certain types of metadata.

Data Flow Mapping

Get a realistic picture of the de-facto data flow in your mission-critical networks. Validate protocols and endpoints for actually intended vs. unauthorized traffic. Get alerts on unauthorized data flow. Automatically visualize data flow in interactive UML diagrams.

Location Mapping

Get context information about the location where OT components are installed, be it photos, Google Maps depiction, street address, or Webcam feeds.

Access Control

Allow access to the asset management platform for various user roles and third parties such as contractors, vendors, and consultants with user-definable roles and scopes. Assure that users can only see those parts of your OT infrastructure that they are entitled to.

Multi-language user interface

Does your company operate internationally? Then you will appreciate that the user interface of OT-BASE supports multiple languages. Switch between English, German, Swedish, Mandarin and others with a click of the mouse.

Your OT configuration is more than a bunch of hardware boxes, software, and cables.

OT-BASE turns it into data that you can visualize, analyze, search, and share 

Unlock the configuration data already stored in your devices
Unlike the first generation of ICS asset discovery tools that use passive scanning, OT-BASE Asset Discovery selectively probes endpoints and network gear using legitimate and safe protocols which were intended just for this purpose. This way, OT-BASE can tell you the full story: About your network topology, software products and versions, security patches not installed, firmware versions, device metadata drawn from GSDML files, and much more.

No appliances needed

OT-BASE Asset Discovery is a software-only product that discovers your network topology, device identity, hardware and software configuration, and data flow.

Selective Probing

Unlike network anomaly detection products, OT-BASE uses legitimate standard interfaces such as SNMP, WMI, Ethernet/IP. It provides configuration details that passive scanning can’t.

routing supported

OT-BASE Asset Discovery can discover devices in routed networks — both by IP routing and CIP Route Browsing. Deployment and maintenance cost is thereby vastly reduced.

periodic monitoring

OT-BASE automatically maintains a configuration history for every device. Review all configuration changes instantly.

Integrate OT asset data into your existing software environment

Chances are that there is more than one enterprise solution in your organization which also stores OT asset data — or would like to do so! Examples are IT asset management systems such as BMC ARS and IBM Maximo. Or service management platforms such as ServiceNow. And you may also want to analyze OT configurations and events using Splunk or QRadar. What you don’t want is to maintain asset information in multiple places.

OT-BASE was designed to integrate with your existing IT infrastructure and with custom applications.

Need to inventory IT devices and software as well? OT-BASE can do that for you, too
If you don’t maintain an asset inventory for your IT systems already, there’s no need to purchase an additional, IT-centric solution. OT-BASE can inventory your IT systems just as well. Added benefit: You get the full picture in one solution, and you can integrate overlapping functions such as vulnerability management, thereby boosting efficiency.

Inventory, analyze and audit operating system versions, application software and network topology using one platform for both OT and IT.

backed by policy

Technology alone doesn’t make your OT infrastructure more secure if not backed by a set of sound policies. OT-BASE is fully integrated with a comprehensive OT security program that takes the guesswork out of implementing IEC 62443, ISO 27k, NIST CSF or other standards, and shows you exactly how to complement a powerful OT asset management system with policies, procedures, and metrics. It’s called the Simple Cyber Governance Program (SCGP) and it’s used for years in multiple critical infrastructure sectors, including nuclear.

The Simple Cyber Governance Program shows you in detail, step by step, how to arrive at sustainable OT security, and how to leverage OT-BASE for maintaining a solid cyber security posture.

Priced around Customer value,

on-premise and saas

OT-BASE is licensed based on volume. You pay for your number of digital devices, regardless of the number of users, number of networks, number of sites. Devices are: Computers (bare metal or virtualized), network switches, PLCs, RTUs etc. Devices are not: Interface cards, I/O modules, keyboards etc.

License fee per device degrades with the number of devices. The more devices you manage with OT-BASE, the lower the cost per device. Best of all, if you manage multiple sites with OT-BASE, license fees are calculated based on the cummulative number of devices, not based on the number of devices per site.

You have the choice between on-premise and SaaS. The OT-BASE cloud version is also an attractive platform for consultants who do asset inventories as a service. Inquire for more information!

Go to a full scale, automated OT asset inventory in these three steps:

Step 1

OT-BASE Asset discovery evaluation (do this now)

Download the free OT-BASE Asset Discovery evaluation software. Check it out in your testbed, in your office network, and in selected process networks. You will see results within the first hour. Discuss results with your fellow engineers.

Step 2

OT-BASE Asset center proof-of-concept

As a proof-of-concept, see what your asset discovery results look like in OT-BASE Asset Center. Get a limited, inexpensive subscription for OT-BASE Cloud, where you can import and process discovery results. In the unlikely case that you shouldn’t like OT-BASE Asset Center good enough, you can still export all discovery results to Excel and JSON and be much better off compared to your previous outdated Excel spreadsheets for asset data and IP lists.

If you don’t have an even minimalistic budget, send us your discovery files and we will give you and your team (and your boss) an impression of Asset Center workflows with your data in a web conference. Usually this results in budget for a proof-of-concept being made available.

Step 3

go to production

For going to production, you can simply keep your OT-BASE Cloud subscription, or purchase a perpetual license for an on-premise version of OT-BASE Asset Center. The on-prem version is functionally identical to the cloud version. Whatever path you choose, we will assist you in getting top results out of your OT-BASE installation.
Why we invented the world’s first full-fledged OT asset management platform
For twenty years we did little else but help asset owners in multiple industries to protect their plants against sophisticated cyber-physical attacks. The fundamental problem we encountered over and over again was a blatant lack of appropriate digital system documentation. As a result, assessment projects took much longer than needed, and always turned up serious vulnerabilities in system design that could have been avoided if appropriate documentation had been available.

We spent several years working on the concepts of an asset management platform purpose-built for digital operations technology which would fix all these issues. Based on a system model that is built from metadata rather than from content. Then, we turned concepts into reality, making sure that control system engineers and IT experts alike would actually love the resulting product:

The OT-BASE asset management platform.

Identify, Inventory, Manage.
OT-BASE™ by Langner