TL;DR: As OT and IT boundaries dissolve, identity becomes the control plane and the weakest link because legacy OT systems, orphaned accounts, excessive privilege, and unreliable manual reviews leave access difficult to see and govern, according to Gathid. The problem is not integration itself but the assumption that IT IAM models can be retrofitted into disconnected operational environments without creating new risk.
At a glance
What this is: This analysis says OT and IT convergence creates an identity governance gap because legacy OT access models do not fit modern IAM assumptions.
Why it matters: It matters because IAM, IGA, and PAM teams have to govern human, service, and machine access across environments that may be disconnected, vendor-owned, or operationally sensitive.
Context
OT and IT convergence means industrial and enterprise systems now share more data, more access paths, and more operational dependency than they were designed to support. In that environment, identity becomes the practical control layer for both human and machine access, but traditional IAM assumes connectivity, central visibility, and modern protocols that many OT estates do not have.
The governance gap is not the existence of integration itself. The gap is that identity review, privilege control, and audit evidence are being asked to function across legacy OT systems, air-gapped networks, vendor-managed software, and local administrator accounts without a shared source of truth.
Key questions
Q: What breaks when IT IAM is extended into OT without redesigning the model?
A: The model breaks when it assumes OT can behave like IT. Legacy systems, air-gapped networks, local admin accounts, and vendor-owned software often cannot support the integrations, telemetry, or constant connectivity that central IAM expects. That leaves visibility incomplete, reviews stale, and access evidence too weak for confident governance.
Q: Why do legacy OT systems create more identity risk than standard IT environments?
A: Legacy OT environments often rely on local admin accounts, vendor-owned software, and disconnected networks, which makes normal IAM visibility incomplete. That increases the odds of dormant accounts, excessive privileges, and unreviewed exceptions surviving for long periods. The risk is not just harder administration, but ungoverned access paths that can affect operations.
Q: How can security teams tell whether identity governance is working in a utility?
A: Look for evidence that access reviews are completed on schedule, stale access is removed quickly, and entitlement history is traceable across cloud, hybrid, and legacy systems. If teams cannot prove who approved access, when it changed, and when it was revoked, governance is incomplete. The signal is operational evidence, not policy documentation alone.
Q: How should organisations balance OT access control with operational continuity?
A: Use governance methods that observe and model access without forcing invasive changes into production networks. The practical balance is to improve visibility and least privilege while avoiding controls that require downtime, constant protocol support, or architecture changes that increase operational risk.
Technical breakdown
Why traditional IAM assumptions fail in OT environments
Traditional IAM was built around centrally managed systems that can authenticate, report, and synchronise state reliably. OT environments often do not meet those assumptions because they include air-gapped assets, vendor-owned software, local admin accounts, and devices that cannot tolerate invasive agents or constant protocol chatter. That makes the identity source fragmented rather than singular. When access is distributed across disconnected systems, the governance question shifts from provisioning efficiency to evidencing who can reach what, through which account, under which operational constraint.
Practical implication: treat OT identity as a distributed evidence problem, not a simple IAM extension project.
How digital twins change identity visibility without disrupting operations
A digital twin is a virtual representation of the identity environment that mirrors users, accounts, permissions, and roles without requiring full bidirectional integration. In OT, that matters because you can model access relationships and state changes without inserting tooling that could disrupt production or force risky architecture changes. The value is not just visibility. It is the ability to reason continuously over access even when the underlying systems cannot be centrally controlled in the same way as IT assets.
Practical implication: use a digital twin to build a current access map before attempting any invasive OT integration.
Why knowledge graphs surface privilege risk that standard reviews miss
Knowledge graphs model relationships between identities, systems, roles, owners, and policies. In converged OT and IT estates, that relational view exposes toxic combinations, privilege creep, and service accounts whose ownership or purpose is unclear. A spreadsheet can show that an account exists. A knowledge graph can show how that account connects to sensitive systems, conflicting roles, and downstream impact if access changes. That makes it especially useful where manual recertification is already stale by the time it is completed.
Practical implication: use relationship modelling to find access paths and ownerless accounts that routine recertification will miss.
NHI Mgmt Group analysis
OT and IT convergence creates an identity governance boundary problem, not just an integration problem. The article shows that the real challenge is fitting modern identity controls into environments that were never designed for centralised governance. That is why visibility, auditability, and privilege decisions become harder at the exact moment operational dependency increases. Practitioners should treat convergence as a change in governance model, not only architecture.
Legacy OT access collapses the assumptions behind conventional IAM. Traditional IAM assumes stable protocols, continuous connectivity, and a single source of truth. OT breaks that premise through disconnected networks, vendor-owned systems, and local administrator accounts that sit outside normal lifecycle control. The implication is that access governance must be reasoned over as a living model, not enforced only at the point of provisioning.
Manual access review becomes identity debt in converged environments. When reviews are slow, stale, and disconnected from operational context, they no longer provide assurance about current access. That leaves dormant accounts, excessive privilege, and toxic role combinations to persist unnoticed. The practical conclusion is that recertification in OT must be continuous, contextual, and tied to asset reality rather than calendar cadence.
Digital twin identity modelling defines the new control plane for OT governance. The article’s strongest signal is that security teams need a way to see access without forcing disruptive integration. Digital twins and knowledge graphs together create a risk intelligence layer that can represent access relationships, ownership, and downstream impact. Practitioners should think of this as governance over relationships, not just records.
Identity blast radius: In converged OT and IT estates, the consequence of a single misconfigured identity can extend from data exposure into production disruption and public-safety impact. That is why identity governance in OT is no longer a back-office access task; it is part of operational resilience. Teams should elevate identity evidence to board-level risk language.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
- Read next: IGA Buyer's Guide
What this signals
Digital twin governance is emerging as the practical bridge between central IAM and disconnected operational estates. The key shift is to model access relationships continuously, even when OT systems cannot support normal integration patterns. That lets teams govern identity state without forcing architecture changes into environments where uptime is non-negotiable.
Identity debt in OT is not just about stale accounts. It is the accumulation of ownership gaps, privilege ambiguity, and evidence that arrives too late to be useful. Security leaders should expect convergence projects to fail if they still rely on review cadences designed for stable IT directories.
For practitioners
- Inventory the full identity landscape Map employees, contractors, third parties, service accounts, and machine users across OT and IT systems, including any local admin accounts that never touch central IAM.
- Build a unified identity model Create a continuously updated access map that represents disconnected OT systems, ownership, roles, and permissions even when direct integration is impractical.
- Use relationship analysis to uncover toxic access Model how identities connect to sensitive systems so you can find privilege creep, conflicting roles, and ownerless service accounts before they become operational risk.
- Replace stale reviews with continuous validation Move away from annual or quarterly access checks and validate identity state against current OT reality, especially where manual review results lag operational change.
- Enforce least privilege on sensitive OT access Use current identity data to remove unnecessary access paths and tighten role scope for accounts that can reach high-consequence systems.
Key takeaways
- OT and IT convergence changes identity governance from a directory problem into a cross-environment evidence problem.
- The main risk is not integration itself, but the mismatch between modern IAM assumptions and legacy operational systems.
- Teams need continuous identity modelling, relationship analysis, and non-disruptive governance methods to keep access provable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Excessive privileges in OT service and machine accounts are a central risk in the article. |
| NHI-01 — Improper Offboarding | Dormant or orphaned OT accounts reflect incomplete identity offboarding and lifecycle control. | |
| Recommendation — Audit OT service and machine accounts for overprivilege and remove access that is not operationally required. Track OT identities through joiner-mover-leaver processes and revoke accounts that no longer have an owner or purpose. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | The article centres on excessive access and the need to enforce least privilege across converged estates. |
| Recommendation — Apply least-privilege controls to OT and IT accounts so access scopes match current operational need. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | This CSF control directly maps to governing permissions and entitlements across fragmented environments. |
| Recommendation — Maintain authoritative entitlement data for OT and IT identities so permissions remain traceable and reviewable. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Cloud-connected OT and hybrid IT environments need IAM coverage across distributed identity sources. |
| Recommendation — Model identities and entitlements under the IAM domain so access can be governed across cloud and operational systems. | ||
Key terms
- Identity Debt: Identity debt is the accumulation of unowned, over-permissioned, or poorly governed non-human identities that security teams cannot cleanly inventory or retire. It usually grows when experimentation outruns access governance, leaving service accounts and tokens active long after their original purpose has passed.
- Digital Twin: A digital twin is a high-fidelity virtual representation of a physical system, environment, or process. In security and identity work, it becomes sensitive when it is used to generate data, validate models, or control real-world decisions, because access to the twin can expose operational knowledge and deployment paths.
- Knowledge Graph: A knowledge graph is a data model that stores entities and the relationships between them instead of treating records as isolated rows. In security, it helps teams explain how identities, permissions, tokens, and resources connect, which is essential for understanding access paths and risk propagation across SaaS and NHI environments.
- Toxic Role Combination: A set of permissions that should not exist together in one identity because they create conflict, excessive access, or separation-of-duties risk. Graph analysis is useful here because it can trace how multiple roles intersect across systems and reveal hidden combinations that standard reports miss.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org