Understanding your OT environment: the first step to stronger cyber security
If you can’t see your entire operational technology environment, you can’t defend it. New guidance from the NCSC will help you gain that visibility.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

If you work in operational technology (OT), you already know what’s at stake.
OT systems keep the lights on, the water pumping, the manufacturing lines moving and our critical national services running. When these systems are compromised or disrupted, the real-world impacts affect safety, operations, the economy, and even national resilience.
That’s why today the NCSC is launching new guidance to help OT organisations create and maintain a ‘definitive record’ of their environment, an accurate and up-to-date view of the system that will change over time to maintain its accuracy and authority.
Connectivity, complexity and change are part of today’s OT reality. Systems that were once air-gapped now interact with enterprise IT, cloud platforms, remote vendor management tools and external data services. Large, long-lived environments bring the extra challenge of undocumented changes, where temporary fixes become permanent, devices are swapped without records being updated, and network paths evolve over time. And without a complete, current understanding of your whole environment, effective cyber security controls can’t be designed, implemented or maintained.
The ‘definitive record’ the guidance describes isn’t just a technical asset list; it reflects how your OT supports your mission and your operations, and includes:
The more an adversary knows about your OT, the easier it is for them to plan and execute effective attacks. Every diagram, configuration and description is valuable intelligence to a skilled attacker. This means your definitive record is one of the most sensitive collections of information you will hold. It should only be accessible to those who need it, protected against tampering, and managed with secure change control. The guidance will help you protect this information appropriately while still enabling its operational and security value. Building your definitive record won’t happen overnight, and it’s not a ‘one and done’ task. Even a partial view to begin with is better than none, and it will mature as you work systematically through assets, networks and supplier relationships.
For many organisations, pieces of the puzzle already exist, in design documents, vendor manuals, maintenance logs or monitoring tools. The goal is to bring these together, validate them, and keep them up to date. By taking this approach, you can make informed, risk-based decisions on patching, architecture changes, third-party access, and contingency planning, ensuring your controls are proportionate and targeted where they matter most.
If you can’t see your whole OT environment, you can’t truly defend it. This guidance will help you gain that visibility, turning fragmented knowledge into a definitive, living record, and enabling you to protect the OT systems, services and supply chains that matter most.
This guidance has been produced by the NCSC in partnership with:
We thank all our partners who have contributed to this guidance.


