Forum Discussion
Research Release Highlight – "Fully Scan Operational Technology" Default Setting Change
Summary
The "Fully Scan Operational Technology" (OT) preference controls whether Nessus actively scans OT/ICS devices during a scan. This setting is intended to be disabled by default to avoid unintended disruption to sensitive operational technology environments.
A long-standing setting in the Do not scan operational technology devices plugin caused this preference to default to enabled in a Basic Network Scan when the discovery type is not set to Custom.
Change
The default value for "Fully Scan Operational Technology" preference has been corrected from yes to no.
Impact
This fix will affect existing Basic Network scans automatically upon the next feed update — no scan recreation is required. Customers using Basic Network Scan policies with a non-custom discovery scan type will see the following behavioral change:
- Before change: "Fully Scan Operational Technology" was silently enabled, meaning OT devices may have been actively scanned.
- After change: "Fully Scan Operational Technology" will correctly default to disabled.
Customers who intentionally want to scan OT devices should explicitly enable the "Fully Scan Operational Technology" preference by switching their scan policy's discovery type to Custom, which will expose the preference in the UI and allow it to be toggled on.
Affected products: Tenable Security Center (SC), Tenable Vulnerability Management (TVM), and Nessus
Target Release Date
July 13, 2026