Thursday, 3 September 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Why your business can't trust the data behind its own security decisions

TechRadar ·
Why your business can't trust the data behind its own security decisions

When a critical vulnerability alert lands in a traditional IT environment, it’s rarely a cause for panic regarding the operational continuity of the business .

The affected laptops, servers, and applications can be identified quickly, and a good team can catalogue and patch them within hours if it’s urgent.

The priorities are clear, and there’s very little guesswork involved.

Now picture the same alert landing across a hospital's imaging equipment, a factory floor's control systems, or a building's HVAC network.

These cyber-physical systems (CPS), the connected devices that run physical operations rather than just processing data, sit at the sharp end of IT and OT (operational technology) convergence.

But unlike traditional IT assets, confirming whether that alert even applies to a specific device can take days, and often ends in a guess rather than an answer.

While this kind of uncertainty would be considered a failure of basic hygiene, for cyber-physical systems, it’s unfortunately much more often the norm.

So why is this such a widespread problem for CPS, and how can security teams get these vital assets back in line with their IT network? Bad visibility into cyber-physical systems is worryingly widespread The inability to manage incoming vulnerabilities for CPS isn’t an outlier or worst-case scenario, which is especially concerning when these assets are at the heart of critical infrastructure like energy and healthcare.

The issue comes down to the product codes that help networks identify what CPS is in the environment, which is an essential part of identifying and applying security patches.

Across a dataset of 17 million cyber-physical assets, our research found that 88% failed to transmit an exact product code, and 76% sent a code that didn't match the vendor's own record.

It’s a side effect of the way these systems were initially designed and later integrated into modern IT environments.

Programmable logic controllers (PLCs), medical scanners, and industrial sensors were engineered for decades of physical reliability, not for tidy digital labeling.

Network identification was rarely part of the design brief, so the same device can report itself differently depending on which protocol or integration is asking.

We found a similar state of affairs when it comes to the operating systems behind the physical hardware .

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

This story in other outlets

More from TechRadar

See all ›

More in Technology

See all ›