Access and accountability drift apart. Local accounts can remain valid after a worker leaves or changes role because the OT directory is not aligned to corporate joiner-mover-leaver events. That leaves teams unable to prove who still has access, and it weakens both audit evidence and operational trust in the access record.
Where the plant silo starts to fail
When OT identities are owned only inside local plant silos, the access model stops matching how people actually move. Accounts, roles, and exceptions get managed against local knowledge instead of a shared joiner-mover-leaver process, so identity truth drifts as soon as someone transfers, contractors rotate, or maintenance access outlives the job that justified it.
That is why the problem is not just administrative duplication. In a siloed model, the plant may still have a valid login record even after the person has changed role elsewhere in the company, and no one has a reliable way to reconcile that access against corporate records or identity convergence practices.
The practical break is accountability. If the OT team cannot tie each local account back to a current owner, manager, or lifecycle event, then access reviews become a best-effort exercise instead of a trustworthy control. That weakens both governance and the operational confidence that the record reflects reality.
What this does to access review and audit evidence
Local-only management usually means the evidence trail is fragmented. One plant may know who asked for access, another may know who approved it, and a third may know whether the account is still being used, but none of those fragments creates a clean end-to-end answer. That makes it hard to prove that access was granted, reviewed, and revoked consistently across the OT estate.
For auditors and internal control owners, the failure is often visible in the same three questions: who has access, why they have it, and who can revoke it today. If those answers depend on tribal knowledge, spreadsheet exports, or plant-by-plant exception handling, the control may exist on paper while accountability has already drifted in practice.
Aligned identity records matter because OT environments often include shared workstations, vendor access, and long-lived operator accounts. Those patterns can be managed, but only if the access record is current enough to support review, incident response, and post-event reconstruction. For OT-specific identity patterns, see OT and ICS Identity and Access Guide.
Why operational trust breaks before the outage does
The most damaging effect is not always immediate compromise. More often, teams lose trust in the access record itself. Once plant staff know that local accounts may survive role changes, emergency exceptions, or contractor offboarding, they stop relying on the directory as a source of truth and start relying on informal memory instead. That creates a hidden control failure even when production still appears stable.
This is also where OT differs from a purely office IT environment. Plant operations often need fast recovery, remote maintenance, and vendor support, so the directory has to support continuity without turning into permanent access sprawl. The control challenge is to keep local agility while preventing siloed accounts from becoming permanent exceptions that nobody owns.
A useful way to think about the break is that the plant silo preserves access but destroys traceability. The environment may still function, yet every unresolved account increases the chance that an access decision is stale, unauthorised, or impossible to explain after the fact. In OT, that is an operational reliability issue as much as an identity issue.
Risk and Threat Considerations
Local OT silos increase the chance that stale accounts, shared credentials, and orphaned vendor access remain usable long after the original business need has ended. The risk is not only unauthorized access, but also the loss of reliable evidence when an incident, audit, or safety review needs to prove who could reach a control system at a specific time.
Failure mechanism: Plant-local administration decouples access from enterprise joiner-mover-leaver events, so revocation, recertification, and ownership tracking degrade over time. That creates persistent valid access with weak attribution and inconsistent revocation.
Impact: Teams lose confidence in the access record, audit evidence becomes incomplete, and an attacker or insider may inherit access that should have expired. In an OT environment, that can complicate incident containment and extend the blast radius of a compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Local OT accounts need lifecycle control so stale access can be revoked and tracked. |
| IA-4 — Identifier Management | The question is about account ownership, traceability, and identity drift across plant silos. | |
| AC-2 — Account Management | Joiner-mover-leaver drift is fundamentally an account lifecycle and revocation problem. | |
| Recommendation — Manage OT credentials centrally and revoke or rotate them when personnel or roles change. Assign, track, and retire OT identifiers so each account remains attributable to a current owner. Enforce timely OT account provisioning, review, and disabling through a formal lifecycle process. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Local silos weaken access control consistency and revocation across the OT environment. |
| A.5.18 — Access rights | The issue is whether access rights remain valid after role changes or offboarding. | |
| Recommendation — Define and enforce consistent access control rules for OT identities across sites and teams. Review and remove OT access rights promptly when business need or ownership changes. | ||
| CIS Controls v8 | CIS-5 — Account Management | The page concerns stale local accounts, ownership drift, and access review gaps. |
| Recommendation — Inventory OT accounts and retire those that no longer map to an active business need. | ||
| NIST CSF 2.0 | PR.AA-01 — Identities and credentials are issued, managed, verified, revoked, and audited for authorized users, devices, and services | The core failure is unmanaged identity lifecycle and poor revocation across silos. |
| GV.OC-01 — Organizational context is established and communicated | Local silos break the organization-wide view of who should own OT access. | |
| Recommendation — Unify OT identity issuance, review, and revocation so access stays current and auditable. Define corporate ownership for OT identity decisions and communicate it to plant operators. | ||
| NIST Zero Trust (SP 800-207) | 5.4 — Policy Decision Point and Policy Engine | A central policy model helps stop local silos from becoming the sole authority on access. |
| Recommendation — Route OT access decisions through a central policy point so local exceptions stay governed. | ||
Practitioner Guidance
What to verify: Every OT account should have a current owner, a documented business purpose, and a revocation path that is not limited to the plant that created it. If those fields cannot be produced quickly, the record is not operationally trustworthy.
Decision rule: If a local OT account cannot be reconciled to a corporate lifecycle event or approved exception, treat it as an exception requiring review rather than as a standing asset. If it can be reconciled, keep the local autonomy only where it is clearly bounded and auditable.
What practitioners underestimate: The biggest problem is often not excess access on day one, but the slow collapse of evidence quality. Once the directory stops reflecting real employment and role changes, every later review becomes weaker even if no incident has yet occurred.
Practitioner takeaway: OT identity management has to preserve plant uptime without letting local convenience become the only source of truth; if access cannot be traced back to current business ownership, it is already a control failure.
Related resources from NHI Mgmt Group
- What breaks when service accounts and workload identities are managed in separate silos?
- What breaks when fraud controls are managed only inside individual business silos?
- What breaks when cloud identities, roles, and permissions are managed in silos across different CSPs?
- How should security teams govern non-human identities at scale?