TL;DR: OT environments are stretching across production systems, industrial networks, robotics, edge systems, cloud platforms, and modern applications, while static firewall rules, VLANs, IP addresses, and manual policy updates are increasingly brittle, according to Corsha. The governance shift is toward identity-driven verification for machine-to-machine communication, where access is continuously checked before traffic is allowed.
At a glance
What this is: This is an OT security infographic arguing that identity-driven verification of machine-to-machine communication is displacing static network segmentation as OT environments expand.
Why it matters: It matters because IAM, NHI and OT teams need controls that govern machine communication by identity and context, not by fragile network paths that become harder to maintain as systems converge.
Context
Operational technology segmentation is the practice of limiting which systems can talk to each other, but many environments still do that with static network rules rather than identity-aware controls. That model becomes harder to sustain when production systems, robotics, edge devices, cloud services and modern applications all need to communicate.
Corsha frames the governance gap as one of control design, not just network layout. The article argues that machine-to-machine traffic in OT should be continuously verified before it is allowed, which shifts the discussion from path permission to identity-driven authorization for non-human systems.
Key questions
Q: What breaks when OT segmentation depends on static network rules?
A: Static OT segmentation breaks when network location is no longer a reliable proxy for trust. As environments add cloud connectivity, robotics, edge systems, and modern applications, IP-based rules and manual policy changes become brittle, create hidden trust paths, and leave lateral movement opportunities that are hard to detect or audit.
Q: Why does machine identity reduce lateral movement risk in OT?
A: Machine identity reduces lateral movement risk because it forces each machine-to-machine connection to be authorised at the point of communication. That limits the value of broad network trust, so a compromised endpoint cannot automatically inherit the same freedom of movement across the environment.
Q: How do security teams know when OT segmentation is becoming unmanageable?
A: The clearest sign is when policy changes become constant just to preserve normal operations. If teams are repeatedly editing firewall rules, VLANs or IP-based exceptions to keep connected OT systems working, the segmentation model is describing the network layout but not governing real trust relationships.
Q: Should OT teams prioritise identity-driven controls over another firewall redesign?
A: Yes, when the environment includes mixed legacy and modern systems that cross multiple operational layers. Another firewall redesign can delay the problem, but it does not change the fact that trust is being inferred from network location instead of machine identity and real-time authorization.
Technical breakdown
Why static firewall segmentation breaks down in connected OT
Traditional OT segmentation assumes the environment can be mapped into stable zones and that IP addresses, VLANs and firewall rules remain a reliable proxy for trust. That assumption weakens when operational systems span cloud-connected services, robotics, edge layers and modern applications that change more often than the firewall policy around them. Static network controls answer where traffic is allowed to go, but not whether the communicating machine should be trusted in that moment. In practice, the policy update burden grows while security teams still lack a direct way to verify the machine behind the connection.
Practical implication: Treat network path control as incomplete unless it is paired with identity-based authorization for each machine-to-machine session.
How identity-driven OT segmentation changes the control point
Identity-driven OT segmentation moves enforcement from network location to machine identity. Instead of trusting a packet because it arrives from an allowed subnet, the control verifies the identity of the source and destination machines before communication is permitted. That model aligns with zero trust principles because trust is evaluated at the moment of access rather than embedded in an address or zone. For OT, the appeal is not abstraction but precision: the policy can follow the machine across legacy and modern systems without constant redesign of network boundaries.
Practical implication: Anchor OT segmentation to workload and machine identity so access decisions follow the system, not the subnet.
Why real-time verification reduces lateral movement risk
Lateral movement in OT becomes easier when an attacker or compromised machine can move through broadly trusted network segments. Identity-driven controls narrow that path by forcing each machine-to-machine request to pass an authorization check before communication starts. That does not eliminate compromise, but it reduces the value of shared network trust and limits how far one exposed endpoint can spread. The security gain comes from shrinking implicit trust and making each connection a separate decision rather than a standing allowance.
Practical implication: Use per-connection verification to reduce the blast radius of a compromised OT endpoint.
NHI Mgmt Group analysis
Static OT segmentation is now a governance liability, not just an architectural shortcut. The article shows that production systems, robotics, edge platforms and cloud services are all being pulled into the same operational fabric. Once that happens, IP-based trust and manual firewall maintenance stop expressing actual machine relationships. Practitioners should treat segmentation as an identity problem when machine communication spans heterogeneous environments.
Machine identity is becoming the correct policy boundary for OT. Network zones describe topology, but they do not prove who or what is communicating. Identity-driven segmentation aligns enforcement to the non-human subject itself, which is the only durable control point when machines move across environments. This is where NHI governance and OT security converge: the access decision has to follow the machine, not the address.
Real-time verification is the operational difference between zero trust as a slogan and zero trust as a control model. The article's model continuously checks machine-to-machine communication before it is allowed, which is the practical expression of Zero Trust Architecture in OT. That approach reduces dependence on one-time perimeter assumptions and makes policy survivable as systems modernise. The implication for practitioners is that segmentation strategy now has to be measured by authorization fidelity, not by rule count.
Identity-driven OT segmentation creates a new control concept: segmentation by machine relationship. This is not just finer-grained firewalling. It is a shift from permitting network paths to governing which machine identities are allowed to interact under which conditions. That concept will increasingly define secure convergence between legacy OT and modern connected systems, and it gives security teams a more stable governance model than subnet-based trust.
OT modernisation now depends on reducing the operational cost of trust decisions. Static policies become brittle because every environment change forces another manual exception or redesign. Identity-based controls lower that maintenance burden while making lateral movement harder. The practitioners who win here will be the ones who design for continuous authorization rather than periodic network cleanup.
From our research library:
- By 2029, 40% of enterprises that successfully implement zero trust within cloud service provider environments will rely on the advanced visibility and control capabilities offered by CNAPP solutions.
- Read next: Ultimate Guide to NHIs
What this signals
Segmentation by machine relationship: OT programmes are moving from address-based trust to policy that follows the communicating machine, which makes identity governance a control-plane issue rather than a network-cleanup task. That shift also creates a cleaner fit with Zero Trust Architecture, because verification now happens at the connection level instead of at the perimeter.
As connected OT environments absorb cloud and application layers, the practical question is no longer whether segmentation exists. The question is whether the segmentation model can survive continuous change without collapsing into manual exception management, and that is where identity becomes the more durable boundary.
For practitioners
- Replace subnet trust with machine identity checks Map the OT services that still rely on allowed IP ranges or VLAN membership and identify where machine identity can become the enforcement condition instead. Focus first on flows that cross legacy and modern environments.
- Inventory machine-to-machine trust paths Document which systems initiate connections, which systems receive them, and which relationships are currently implied by network placement rather than explicitly authorised. Use that inventory to find standing trust assumptions.
- Reduce manual segmentation drift Track every firewall or policy change required to preserve production connectivity and flag environments where policy updates are becoming routine maintenance rather than exception handling.
- Align zero trust controls to OT communication Apply zero trust to the communication event itself so each machine-to-machine request is evaluated before access is granted, rather than assuming the network location is sufficient proof of trust.
Key takeaways
- OT segmentation that relies on static rules becomes fragile as connected systems span legacy and modern environments.
- Identity-driven verification shifts enforcement from network location to the machine making the request, which tightens control over OT communications.
- The main governance task is to reduce standing trust and make each machine-to-machine connection an explicit authorization decision.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST Zero Trust (SP 800-207), NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Static OT paths often grant machines more reach than their task requires. |
| NHI-08 — Environment Isolation | The article is about isolating OT communication across mixed legacy and modern environments. | |
| Recommendation — Map OT connections to NHI-05 and remove network reach that exceeds each machine's task scope. Apply NHI-08 to separate OT communication domains by machine identity rather than by flat network zones. | ||
| NIST Zero Trust (SP 800-207) | 3.1 — Policy Enforcement Point | The article's real-time verification model depends on enforcing access at the decision point. |
| Recommendation — Place policy enforcement at the machine-to-machine request and verify before permitting traffic. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Identity-driven segmentation is fundamentally about authorising machine communication. |
| Recommendation — Use PR.AA-05 to govern which machines may communicate and under what conditions. | ||
| CIS Controls v8 | CIS-5 — Account Management | OT machine identities still require ownership and lifecycle control even when the network changes. |
| Recommendation — Extend account management discipline to machine identities that underpin OT connectivity. | ||
Key terms
- Identity-Driven Segmentation: Identity-driven segmentation is a control model that allows or denies communication based on verified identity rather than only on subnet, firewall, or VLAN placement. It is especially useful in operational environments where topology changes frequently and network paths no longer describe trust accurately.
- Machine-to-Machine Communication: Interactions where software systems exchange data or invoke actions without a person present in the loop. These connections are often legitimate business dependencies, but they still need identity governance because they can be abused through stolen credentials, over-scoped tokens, or automated attacks.
- Zero Trust: A security model that assumes no identity, human or non-human, should be trusted by default, even inside a network perimeter. Every access request must be verified, authorised, and continuously validated.
- Operational Technology: Operational Technology is the hardware and software that monitors or controls physical processes such as manufacturing lines, utilities, and transportation systems. Unlike standard IT, OT prioritises uptime and safety, so identity controls must be precise enough to reduce risk without interrupting essential operations.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org