Binary-derived component inventory and reachability analysis can sharpen firmware review, but an asset owner still has to prove device identity, deployed version, exposure, process consequence, and change authority.
OTbase documents a contextualized OT asset inventory with device, firmware, topology, lifecycle, and vulnerability context. A firmware value becomes actionable only when it is tied to the correct physical device, acquisition method, observation time, engineering baseline, process role, exposure, approved change, and recovery evidence.
runZero presents active and passive discovery, asset correlation, topology, criticality context, and exposure intelligence across heterogeneous environments. Discovery can create a stronger candidate inventory, but accountable operations and engineering owners still have to resolve identity, function, criticality, lifecycle state, and authority for each OT asset.
The provider's annual report supplies threat, vulnerability, ransomware, assessment, and incident-response observations—but its populations and methods must remain attached to every reported number.
The release spans multiple Siemens and Schneider Electric product families and demonstrates why asset identity, version, vendor guidance, exposure, process consequence, and maintenance feasibility must stay connected.
The May 2025 fact sheet emphasizes internet exposure, credentials, remote access, segmentation, inventory, monitoring, and recovery without turning public guidance into a site-specific response plan.