
Sep 29, 2026 · 34 min
Asset context beats CVE counts in OT security
Soap Box: HD Moore talks OT security, frontier fearmongering and more
Industrial environments cannot manage exposure reliably without knowing which devices exist, how they connect, and what access they have.
- 1RunZero maps unmanaged IT and OT assets across gateways, layered networks, and non-IP protocols such as BACnet and KNX.
- 2Asset context, connectivity, vendors, and blast radius provide more useful remediation guidance than CVE counts alone.
- 3AI integrations and MCP require product-aware design, inspectable activity, and granular permissions rather than a simple API connection.
Don't miss
H. D. Moore explains why effective MCP and AI reporting depend on product context, summarization, and permissions—not merely exposing an API.
The brief
Patrick Gray talks with H. D. Moore about RunZero’s founding problem: organizations cannot secure assets they do not know exist, especially across sprawling IT and OT environments.
RunZero’s discovery approach reaches beyond ordinary IP inventories, finding devices behind gateways and systems using industrial protocols such as BACnet and KNX.
The conversation challenges CVE-centered security: asset identity, connectivity, vendor details, and blast radius often matter more than a raw vulnerability count.
Moore compares today’s fear of AI-enabled exploitation with the backlash against Metasploit, arguing that firewalls, monitoring, honeypots, and access controls remain foundational.
The standout product discussion covers RunZero’s built-in MCP, AI-generated integrations, reporting limits, and a move toward granular scopes and custom roles.