StrategyCore
Back to Resources
03/cybersecurity 7 min read

IoT and OT Security in Japan: A Foreign Vendor's Field Guide

Why agentless device intelligence is a category leader's opportunity in Japan, and why most global vendors miss it

Japanese manufacturing runs on a hybrid of modern IoT sensors and decades old OT infrastructure, creating an enormous attack surface that traditional IT security tools cannot see. The same gap runs through hospitals, utilities, and every operator of critical infrastructure: the typical enterprise tracks only a fraction of the connected devices actually on its networks. For global IoT/OT security vendors, this is one of the clearest product market fit opportunities in APJ. It is also where delivery stumbles: Japanese operators will not tolerate active scanning in production, agent installation is impossible on most OT and medical devices, and Japanese language deployment is nonnegotiable. Written for the vendor executive weighing Japan as a growth market.

OT zones · agentless visibility

SC-LY-01 · REV A · 2026.07

Enterprise IT

L4 · L5

T1

DMZ

L3.5 · idmz

T2

Supervisory

L2 · L3 · scada

T3

Control

L1 · plc

T4

Field devices

L0 · sensors

T5

No agents, no probes below the DMZ · identify by vendor · model · firmware

Layer diagram of Purdue-style zones from enterprise IT at the top through the DMZ, supervisory SCADA, and control layers down to field devices, where agents cannot be installed and active scanning is unsafe.
01

The visibility problem

Traditional endpoint security tools (EDR, antivirus, vulnerability scanners) rely on installing software agents on the devices they protect. This works for laptops, servers, and modern workstations. It does not work for IoT sensors, OT controllers, SCADA systems, building automation, industrial robots, or legacy manufacturing equipment. These devices cannot run agents, either because they lack the compute resources, because the vendor does not allow modifications, or because agent installation would void warranty or safety certifications. The result is a massive blind spot on the factory floor.

02

Why scanning is not the answer

The obvious workaround, running active network scans against these devices, creates its own problem. Industrial control systems were not designed to handle the traffic patterns of security scanners. Unsolicited probes can cause PLCs (programmable logic controllers) to hang, reboot, or behave unpredictably. In an environment where device failure can halt a production line or create physical safety risks, active scanning is not an option. Japanese manufacturers, with their emphasis on uptime and process stability, are especially cautious here.

03

The agentless alternative

The alternative does not touch the device at all. Agentless device intelligence identifies a device from three facts alone: vendor, model, and firmware version. Those come straight from an existing inventory or CMDB, or from a lightweight discovery scanner that reads them off the network, actively or passively, with no appliance to install and nothing running on the device. From those three facts the platform returns the device's known vulnerabilities, its lifecycle status, and an actionable risk score. No agent, and not a single probe sent to a production controller. For an operator with 10,000 devices across 20 sites, this surfaces the devices the security team did not know it had. Industry research bears this out: organisations underestimate their connected device count by 25 to 40 percent, and a 2025 Forescout study of over 10 million devices found that 65 percent of connected assets now sit outside traditional IT visibility.

04

Vendor sourced versus crowdsourced vulnerability data

One detail matters more than it sounds: the quality of the underlying vulnerability data. Most tools aggregate CVE data from public databases such as the NVD, which are incomplete and often delayed. The NVD's February 2024 enrichment breakdown left more than 4,000 CVEs without full analysis, and anyone relying on it alone went blind for months. Platforms that instead collect data directly from device manufacturers, 874 vendor sources in DeviceTotal's case, surface materially more issues: in a Japanese electricity provider deployment, 66 percent more vulnerabilities than JVN and JPCERT. They also get earlier notice, more accurate remediation guidance, and visibility into vendor specific issues that never reach public feeds. In OT environments where some devices have not been patched in a decade, that difference is knowing what to fix versus guessing.

05

Reconciliation, not just discovery

Finding devices is only half the job. The same device shows up differently in a scanner, a CMDB, and an EDR console, often with a mismatched model or a blank firmware field, and a vendor name on its own maps to no CVE. Reconciliation is the step that correlates all of those records into one validated device identity, confirms the model and firmware, then scores it. Gartner already recognises reconciliation as a category in finance and master data management. Applied to device security, it sits as an intelligence layer above the tools an operator already runs, from Claroty and Nozomi to ServiceNow, rather than replacing them. The output is one trusted inventory and a defensible, ranked remediation queue in place of thousands of raw alerts.

// Key Takeaways

What to remember

  • Traditional agent based security tools cannot protect IoT/OT devices
  • Active scanning is dangerous in industrial control environments
  • Organisations underestimate connected device counts by 25 to 40 percent, and most connected assets sit outside traditional IT visibility
  • Vendor direct vulnerability data from 874 sources surfaces materially more issues than NVD or JVN and JPCERT
  • Reconciliation turns fragmented scanner, CMDB, and EDR records into one validated device identity and a ranked fix list

// FAQ

Frequently asked questions

Q1

What is agentless device security?

Agentless device security identifies and assesses connected devices without installing anything on them. A device is identified from three facts, vendor, model, and firmware version, taken from your existing inventory or read off the network by a lightweight discovery scanner, actively or passively. Each device is then matched against a vulnerability database. This is the only workable approach for IoT, OT, and legacy equipment that cannot run an agent.

Q2

Why is active network scanning risky for OT and industrial systems?

Industrial control systems were not built to handle scanner traffic. Unsolicited probes can make a PLC hang, reboot, or behave unpredictably, and in a plant or utility that can halt a line or create a safety risk. Passive, agentless observation reads the same devices without sending anything to them, so it carries none of that risk.

Q3

How many connected devices do organisations actually miss?

More than most teams expect. Industry research puts device-count underestimation at 25 to 40 percent, and a 2025 Forescout study of over 10 million devices found that 65 percent of connected assets sit outside traditional IT visibility. The gap is worst in OT, healthcare, building automation, and other environments full of vendor-locked or legacy hardware.

Q4

Why is vendor-sourced vulnerability data better than public CVE databases?

Public databases such as the NVD are incomplete and often delayed, and recent NVD backlogs have made that worse. A platform that collects security data directly from device manufacturers, in DeviceTotal's case 874 vendors, gets earlier notice, more accurate remediation guidance, and visibility into vendor-specific issues that never reach public feeds.

Q5

Can you secure IoT and OT devices that cannot be patched?

Yes. Many OT devices have not been patched in years and some never will be. Agentless intelligence still gives you an accurate risk score, the available mitigations and workarounds, end-of-life status, and CISA KEV flags for each device, so you can compensate with network controls and prioritise the assets that matter most.

Last updated:

Scoping Japan entry in this category?

If your company is weighing Japan entry in the work above, StrategyCore is the operating layer that carries it from first assessment to live deployments, run locally and in Japanese.