By NHI Mgmt Group Editorial TeamBased on Corsha: “title” (September 27, 2023)

TL;DR: As Industry 4.0 expands OT and IT integration, legacy systems, real-time constraints, and inconsistent security postures make machine-to-machine communication harder to govern, according to Corsha’s analysis. The issue is not connectivity alone, but whether identity, authorization, and auditability can be imposed without disrupting operational workflows.


At a glance

What this is: This is an analysis of why OT to IT communication security needs machine identity and access control, not just encrypted transport.

Why it matters: For IAM, PAM, NHI, and OT security teams, the issue is governing machine-to-machine trust across legacy and real-time environments without breaking operations.


Context

Industry 4.0 is increasing the volume and criticality of OT to IT communication, which exposes a governance gap that encryption alone does not close. The problem is not whether data can be protected in transit, but whether the machines exchanging that data can be identified, authorised, and audited in ways that fit industrial operations.

OT environments are different from enterprise IT because many assets are legacy, static, and latency-sensitive. That means security controls cannot assume frequent patching, interactive sign-in, or user-centric authentication patterns. The practical question is how to impose identity control on machine-to-machine communication without disrupting production.


Key questions

Q: How should organisations secure OT to IT communication without disrupting real-time industrial operations?

A: Organisations should treat OT to IT connectivity as a high-risk trust boundary, not a normal enterprise network extension. The practical baseline is strong identity and access control, network segmentation, real-time monitoring, and security by design. For machine-to-machine and API traffic, dynamic verification and least-privilege access reduce lateral movement while preserving operational continuity and visibility.

Q: Why do legacy OT systems create more identity risk than standard IT environments?

A: Legacy OT environments often rely on local admin accounts, vendor-owned software, and disconnected networks, which makes normal IAM visibility incomplete. That increases the odds of dormant accounts, excessive privileges, and unreviewed exceptions surviving for long periods. The risk is not just harder administration, but ungoverned access paths that can affect operations.

Q: What breaks when machine-to-machine access is not governed at the gateway layer?

A: When machine-to-machine access is not governed at the gateway layer, teams lose a consistent control point for authentication, authorisation, and monitoring. Sprawl follows quickly: unmanaged tokens, inconsistent policy enforcement, and weak visibility into which service or agent called what. That makes incident response slower and increases the chance of data exposure or unauthorized tool use.

Q: What is the difference between encryption and machine identity in industrial security?

A: Encryption protects data in transit, while machine identity proves the caller and enables policy decisions about access. In OT to IT communication, both are needed, but they solve different problems. Without identity, encryption can still protect the wrong connection.


Technical breakdown

Why encryption does not solve machine trust

Encryption protects confidentiality and integrity in transit, but it does not tell one machine which other machine is allowed to connect. In OT to IT flows, that missing trust layer becomes the real control problem: a secure channel can still carry unauthorised traffic if identity and authorisation are weak or absent. Identity control adds machine-level proof, policy enforcement, and auditability to the connection itself, rather than treating the network path as sufficient assurance. In industrial settings, that distinction matters because connectivity and trust are not the same thing.

Practical implication: Treat transport encryption as necessary but insufficient, and design machine authorisation separately from channel protection.

Why legacy OT breaks conventional IAM assumptions

Legacy OT systems were built for availability and deterministic operation, not modern identity plumbing. They often lack native support for federated identity, interactive MFA, or frequent credential rotation, and they may depend on fixed protocols that cannot absorb intrusive security changes. That creates a structural mismatch with IT security models that assume users can be challenged, sessions can be interrupted, and endpoints can be updated regularly. The result is that identity enforcement has to be introduced around the system, not inside the system, using controls that respect operational constraints.

Practical implication: Place identity controls at integration points and gateways where legacy OT cannot support them natively.

How per-machine authorization changes the control model

Per-machine authorization shifts security from coarse network segmentation to explicit control over which machine may call which service, for what purpose, and under what conditions. That is especially relevant in mixed OT and IT environments where asset diversity is high and standardisation is low. A machine identity model allows each API client or connector to be individually verified, monitored, and constrained, which improves traceability in hybrid deployments. The benefit is not just stronger security; it is also a clearer operational record of machine-to-machine trust decisions.

Practical implication: Use per-machine authorization to reduce shared access paths and improve traceability across hybrid industrial workflows.


  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.
  • reviewdog Action compromise 2025: A stolen maintainer token poisoned reviewdog/action-setup, leaking CI secrets including the tj-actions bot token used in the next attack.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

OT to IT communication security is now an identity problem, not a transport problem. Encryption can protect packets, but it cannot express which machine is allowed to initiate which industrial action. In hybrid OT and IT environments, that gap turns machine identity into the real boundary of trust. Practitioners should stop treating secure transport as the end state and treat machine authorization as the control that matters.

Legacy OT exposes a control mismatch that enterprise IAM cannot simply absorb. OT systems were built around stability, not continuous authentication, frequent credential changes, or user-style challenge flows. That means the usual assumptions behind enterprise IAM do not map cleanly to industrial protocols and real-time workflows. The implication is that governance must be engineered around the asset, not retrofitted onto it after the fact.

Per-machine access is the right granularity for industrial trust decisions. Shared credentials and network-level trust are too blunt for environments where assets, protocols, and operational criticality vary widely. A named concept here is machine-to-machine identity boundary: the point where one industrial system must prove who it is before another system will accept its traffic. Practitioners should think in terms of bounded machine trust rather than perimeter access.

Real-time operations make security latency a governance constraint. In OT, even small delays can affect safety or production, so identity controls must be designed for low-friction verification. That does not weaken the requirement for control; it changes how the control is delivered. Teams should judge security mechanisms by whether they preserve operational determinism while still enforcing identity.

From our research library:

What this signals

Machine-to-machine trust needs its own governance model: OT modernisation fails when teams assume user-centric IAM controls can be transplanted into industrial environments. The practical shift is to govern identity at the connection layer, where per-machine access can be verified without forcing legacy systems to behave like enterprise endpoints.

Industrial programmes should expect identity controls to become part of operational architecture, not a bolt-on security layer. That means the next design question is not whether encryption exists, but whether each machine, connector, or API call can be authorised in a way that survives real-time constraints and audit requirements.


For practitioners

  • Map OT to IT trust boundaries Inventory where industrial systems exchange data with IT applications, APIs, or analytics platforms, and identify every place where the current connection model relies on network trust alone.
  • Introduce machine identity at integration points Use connectors, gateways, or brokers to establish explicit machine identity where legacy OT assets cannot support native identity controls.
  • Separate transport security from authorization Keep encryption in place, but define an independent policy for which machine identities may invoke which services and under what conditions.
  • Design for low-latency enforcement Validate that authentication and policy checks do not break real-time workflows, especially where timing, determinism, or safety are operational requirements.

Key takeaways

  • OT to IT communication becomes harder to govern when teams rely on encryption alone and ignore machine identity.
  • Legacy OT systems create a mismatch with modern IAM because they cannot easily support interactive or frequently changing controls.
  • The most practical control shift is to enforce per-machine authorisation at integration points while preserving operational timing.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CSA Cloud Controls Matrix, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity and Access ManagementThe article is about controlling machine identity and access in cloud-connected industrial environments.
Recommendation — Apply IAM controls to verify and restrict machine-to-machine access across OT and IT integration points.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe core issue is whether machine access is explicitly authorised rather than assumed by network reachability.
Recommendation — Define and enforce machine authorisation rules at the point of connection, not just at the network perimeter.
NIST Zero Trust (SP 800-207)Zero Trust Architecture — Zero Trust ArchitectureThe article centers on continuous verification and explicit trust for industrial machine communications.
Recommendation — Design OT to IT integrations so every machine request is verified before access is granted.
NIST SP 800-53 Rev 5IA-9 — Identification and Authentication (Non-Organizational Users)Machine clients and external connectors need identity verification distinct from human authentication.
Recommendation — Use IA-9 to authenticate non-organizational machine clients before allowing access to OT-facing services.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article highlights machine-to-machine exploits that can spread once trust is overly broad.
Recommendation — Map weak machine trust to credential access and lateral movement pathways in your threat model.

Key terms

  • Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
  • OT to IT communication: OT to IT communication is the exchange of data or commands between operational technology and enterprise information systems. It creates a governance challenge because the two environments usually differ in uptime requirements, authentication maturity, patch cycles, and tolerance for security control latency.
  • Per-Machine Authorization: Per-machine authorization is the practice of allowing access based on the specific machine identity making the request, rather than on broad network location or shared credentials. It tightens accountability and reduces trust leakage across hybrid industrial environments.
  • Real-Time Constraint: A real-time constraint is an operational requirement where even small delays can affect process integrity, safety, or availability. In OT security, it means identity and policy controls must be lightweight enough to enforce without changing system behaviour in unacceptable ways.

Deepen your knowledge

NHI governance, machine identity security, and identity lifecycle management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 1, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org