Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations secure access when IT and…
Governance, Ownership & Risk

How should organisations secure access when IT and OT environments are converged?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Governance, Ownership & Risk

Organisations should treat IT and OT convergence as a shared security programme, not a network project. Start with unified governance, then apply baseline controls, continuous monitoring, role-based access, and regular risk assessments across both environments. Because OT systems often include legacy devices and safety-critical processes, access decisions must balance operational continuity, security, and physical safety.

Converged IT and OT Access Needs a Shared Control Model

When IT and OT converge, access can no longer be managed as two separate problems. The real challenge is that the same authentication, entitlement, and monitoring decisions now affect both business systems and safety-critical environments. Organisations should define one access model, but tune it to the different tolerance for downtime, change, and operator action in each domain.

In practice, that means separating the control objective from the transport. Remote access, administrative access, engineering access, and vendor access should all be governed consistently, even if the supporting tooling or network paths differ. For OT, the access model must account for legacy protocols, shared workstations, maintenance windows, and systems that cannot tolerate frequent agent installs or disruptive policy changes.

A useful starting point is to inventory who and what needs access, then classify access by function and blast radius. Operators, engineers, service accounts, jump hosts, and third-party connections should not be treated as interchangeable just because they reach the same plant assets. The CISA Industrial Control Systems resources are useful here because they anchor access decisions in real operational constraints rather than abstract policy language.

How to Balance Security, Continuity, and Safety

Access design in converged environments works best when it is least-privilege by default, but exception-aware in execution. A technician may need broad access during maintenance, yet that same access can be unsafe during production. Organisations should therefore distinguish standing access from approved just-in-time access, and treat any permanent high-privilege path as an exception that needs explicit ownership.

Role design matters because OT access is often organisationally messy. One role might allow viewing telemetry, another may permit parameter changes, and a third may issue commands that affect physical processes. If those permissions are collapsed into a single “admin” role, the environment becomes difficult to govern and harder to audit. The more constrained the role, the easier it is to verify that a human or tool can only do what the operational context requires.

Authentication strength also needs to match the consequence of misuse. In converged settings, remote access paths often become the easiest route to sensitive OT assets, so credentials should be strongly protected and, where possible, bound to specific users, devices, and destinations. Organisations that want implementation guidance can map this to NIST SP 800-82 Rev 3, OT Security Guide and the access-control expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls.

Operating Converged Access Without Losing Visibility

Convergence increases the need for continuous monitoring because access paths that are acceptable in IT can be dangerous in OT if they are rarely used, poorly reviewed, or shared across teams. Logs should show who accessed which system, from where, using what method, and whether the action was read-only or control-affecting. Without that separation, incident response tends to stall at “someone was on the network” rather than “someone changed the process state.”

Monitoring should also include access review and exception review. OT teams often rely on trusted maintenance relationships, but trusted does not mean current, necessary, or bounded. Review cadence should therefore be driven by criticality and change frequency, not by calendar convenience alone. Where possible, organisations should converge on common reporting and escalation rules even if the underlying platforms remain different.

For a control baseline that spans inventory, account management, logging, and vulnerability reduction, CIS Controls v8 provides a practical operating model, while ISO/IEC 27001:2022 Information Security Management is useful when access governance must sit inside a broader management system with defined ownership and review discipline.

Risk and Threat Considerations

Converged environments raise the consequence of access failure because one weak credential, one overly broad role, or one poorly governed vendor path can cross from IT into OT and create operational or physical impact. The main risk is not just unauthorized access, but access that is technically legitimate yet operationally unsafe for the process state, timing, or safety envelope.

Failure mechanism: Shared or long-lived access paths, weak segmentation, and excessive privilege let a compromise, misuse, or maintenance exception reach systems that were never meant to be broadly reachable. If OT access is managed like ordinary IT access, attackers and insiders can exploit the trust built into remote support, operator convenience, or legacy exceptions.

Impact: The result can be process disruption, unsafe changes, loss of visibility, or delayed recovery because the same access path may control both business functions and physical operations. In a converged model, access mistakes are not limited to data exposure, they can become availability and safety events.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeConverged access hinges on limiting what each role can do across IT and OT.
IA-2 — Identification and Authentication (Organizational Users)Named users must be strongly authenticated before reaching shared converged assets.
AU-2 — Event LoggingUnified access visibility depends on logging who accessed OT and what they did.
Recommendation — Enforce least privilege for every operator, engineer, and vendor access path. Require strong user authentication for all human access into converged environments. Log access events with user, source, target, and action detail across IT and OT.
CIS Controls v8CIS-5 — Account ManagementConverged access depends on governed accounts, ownership, and timely revocation.
Recommendation — Centralize account ownership, review, and deprovisioning across IT and OT.
ISO/IEC 27001:2022A.5.15 — Access controlA unified access model maps directly to Annex A access-control governance.
A.8.2 — Privileged access rightsOT convergence often fails through unmanaged admin and maintenance privilege.
Recommendation — Define and enforce access rules consistently across converged environments. Restrict and review privileged access on OT-facing systems and paths.

Practitioner Guidance

What to prioritise: Build a single access governance model first, then adapt controls for OT constraints such as maintenance windows, legacy endpoints, and safety-critical roles. If the only way to make access “work” is to leave permanent broad privilege in place, the design is not ready for convergence.

What to verify: Confirm that every remote, vendor, operator, and engineering path is tied to a named purpose, a named owner, and a revocation process. Verify that the access review process can distinguish read-only visibility from command authority, because that difference is often where convergence fails in practice.

Practitioner takeaway: The right model is not maximum restriction, it is controlled reachability, where every path into OT is deliberately granted, observable, and limited to the smallest operational purpose that still keeps the plant safe and available.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org