Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Article

Why you cannot scan an OT network

The single most common way an IT security programme causes an industrial incident, and what to do instead.

Updated August 2026 · 6 minute read

The thing IT security gets wrong here

Vulnerability scanning is so ordinary in enterprise security that it is barely a decision. You point the scanner at a range, it enumerates, you get a report.

Point the same scanner at a control network and you can stop production. This is not caution or folklore. Industrial controllers have limited network stacks, tight timing assumptions and no expectation of malformed or unexpected traffic, because they were built for a deterministic network that no untrusted party could reach.

What actually goes wrong

A scanner opens connections a controller was not built to handle and exhausts its session table. A probe sends a malformed packet and the device faults. An enumeration sweep introduces enough latency that a time-sensitive process misses its window.

None of these are exotic. They are ordinary scanner behaviour meeting equipment that has been running continuously since before the scanner existed.

Why "just do it in a maintenance window" fails

Maintenance windows on a process plant are measured in hours and negotiated months ahead against production commitments. On a vessel under way there is no window at all.

Even where a window exists, a scan tells you about the estate during the window. Change happens the rest of the time, and OT estates change more than people expect: vendors connect, engineers swap parts, temporary fixes become permanent.

Passive discovery, and why it is better anyway

Passive discovery listens rather than asks. From observed traffic you can identify what is on the network, what firmware it runs, what protocols it speaks and which processes it participates in, without sending anything at all.

It is often argued that this is a compromise, an inferior substitute accepted for safety reasons. In practice it produces a better inventory. A scan gives you a point-in-time list of what answered. Passive observation gives you a continuous picture, including the devices that would never have answered and the relationships between them, which is the part that actually matters when you are trying to understand consequence.

What you still cannot learn passively

Passive discovery will not confirm exploitability. It tells you a device is running a firmware version with a known vulnerability; it does not tell you whether an attacker could reach and use it given your segmentation.

That question is answered by validation, carried out deliberately and under approval, against targets you have agreed. The distinction worth holding onto is that discovery should be continuous and safe, while validation should be occasional and controlled. Collapsing the two into one activity is how the industry ended up pointing scanners at plant.

FAQ

Questions, answered

Is passive monitoring enough on its own?
For inventory and detection, yes. For understanding exploitability, no. The two jobs are different and should be done differently: continuous passive observation for the picture, deliberate and approval-gated validation for the question of what an attacker could actually reach.
Our vendor says their scanner is OT-safe. Is it?
Some are considerably gentler than others, and a few are genuinely built for industrial protocols. The question to ask is not whether it is safe in general but what it does to your specific equipment, and whether the vendor of that equipment supports it. If the answer involves anyone shrugging, the risk is yours.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.