Organisations should treat IT and OT convergence as an identity and trust problem, not just a network integration project. Every connected device, service, and user needs strong authentication, certificate-based trust where appropriate, and clear policy boundaries. The goal is interoperability with least privilege, so operational flexibility does not create uncontrolled access paths across industrial systems.
Why This Matters for Security Teams
IT and OT convergence changes the trust model of industrial environments. A firewall can segment traffic, but it cannot prove that a controller, engineering workstation, service account, or integration broker should still be allowed to act once it is connected. That is why identity, credential lifecycle, and policy enforcement matter as much as network design. NHI Mgmt Group notes that only 5.7% of organisations have full visibility into their service accounts, and 90% of IT leaders say properly managing NHIs is essential for zero-trust implementation in its Ultimate Guide to NHIs.
The usual mistake is to extend IT controls into OT without adjusting for operational risk, then rely on shared accounts, static certificates, or broad allowlists to keep production running. That approach creates hidden trust paths between business systems and plant systems, especially when vendors, remote support, historians, and orchestration platforms are involved. Current guidance suggests treating every trust edge as explicit, short-lived, and auditable, rather than assuming that network location implies legitimacy. In practice, many security teams discover the weakest identity path only after a maintenance account, API key, or service credential has already bridged environments.
How It Works in Practice
Bridging IT and OT safely starts with separating transport connectivity from identity trust. Devices and services should authenticate with cryptographic identity where possible, then receive narrowly scoped access based on role, asset criticality, time, and task. For human operators, use phishing-resistant authentication and step-up controls for privileged actions. For machines, prefer workload identity and certificate-based trust over shared passwords or embedded secrets, aligned to guidance in NIST SP 800-63 Digital Identity Guidelines and NIST SP 800-53 Rev 5 Security and Privacy Controls.
In industrial settings, the practical pattern is usually:
- issue unique identities to controllers, gateways, historians, and integration services;
- bind certificates or tokens to device posture, environment, and purpose;
- apply policy at the request point, not just at the network perimeter;
- rotate secrets and certificates on a defined schedule, with break-glass exceptions tightly monitored;
- log authentication, authorization, and change events in a way that OT teams can actually review.
This is also where the NHI lifecycle matters. The 52 NHI Breaches Analysis shows how often machine identities and tokens become the weak point once they are reused across environments or left unrotated. The goal is not to make OT behave like a corporate cloud stack, but to enforce consistent identity proof across both domains while preserving deterministic operation. These controls tend to break down when legacy PLCs, vendor remote-access tools, or flat trust relationships cannot support unique identities or per-session authorization.
Common Variations and Edge Cases
Tighter identity controls often increase operational overhead, requiring organisations to balance security assurance against uptime, vendor access, and maintenance simplicity. That tradeoff is most visible in brownfield plants, where legacy OT assets may not support modern certificates, federated identity, or fine-grained authorization. Best practice is evolving, but there is no universal standard for every industrial protocol or asset class yet.
For older environments, compensating controls may be necessary: isolate unsupported devices, front them with authenticated gateways, restrict vendor access to just-in-time windows, and move privileged actions behind monitored jump hosts. Where certificate-based trust is feasible, keep certificate lifetimes short enough to reduce exposure, but long enough to avoid operational fragility. For remote operations, align identity policy with change windows and incident procedures so emergency access does not become standing access.
NHIMG research on the Top 10 NHI Issues and the Schneider Electric credentials breach reinforces the core lesson: industrial trust fails fastest where shared credentials, weak offboarding, and unclear ownership meet external connectivity. The right answer is not to block integration, but to define a narrow identity boundary that survives vendor change, outage recovery, and plant expansion.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Industrial bridges depend on unique, non-shared machine identities. |
| CSA MAESTRO | MAESTRO addresses trust, policy, and lifecycle control for agent-like workloads crossing domains. | |
| NIST AI RMF | AI RMF supports governance where autonomous orchestration affects OT trust decisions. | |
| NIST CSF 2.0 | PR.AC | Access control and identity proof are central to safe IT/OT convergence. |
| NIST Zero Trust (SP 800-207) | Zero trust requires continuous verification across IT and OT boundaries. |
Apply MAESTRO principles to constrain each cross-domain interaction to explicit, least-privilege trust.
Related resources from NHI Mgmt Group
- How should organisations expand Identity Governance and Administration delivery without weakening governance in regulated environments?
- How should organisations govern access to SAP workloads in RISE with SAP S/4HANA Cloud without weakening identity controls during migration?
- How should organisations streamline employee ID issuance without weakening identity verification?
- How should federal agencies modernize identity security without weakening procurement or partner controls?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org