Security teams should treat OT and IT convergence as an identity problem, not just a networking project. Start by defining which assets are truly critical, then limit access by default, use encrypted communications wherever possible, and verify certificates for machine-to-machine connections. Continuous monitoring is essential because visibility gaps across both domains can hide unauthorized activity until it affects operations or safety.
Identity boundaries become the control plane when OT meets IT
When OT and IT environments are connected, identity stops being an administrative layer and becomes part of the trust boundary itself. The main failure is not simply that more systems are exposed, but that older OT assumptions about fixed roles, isolated networks, and limited remote access no longer hold. Once convergence begins, access paths must be designed so that operators, engineers, vendors, and machines are each constrained to the minimum level needed for the task.
That makes identity governance central to resilience. If authentication is weak, shared, or poorly recorded, teams lose the ability to prove who or what initiated a command, changed a setpoint, or accessed a control interface. In connected OT environments, that weakens both cyber defence and safety assurance. In practice, many security teams discover the identity gap only after remote access, vendor support, or machine-to-machine integrations have already expanded faster than their control model.
How to apply identity controls across plant and enterprise connections
The practical starting point is to separate access by purpose, not by convenience. OT operators, corporate users, third-party support staff, and automated services should not share the same identity patterns or trust assumptions. Where possible, interactive human access should be tied to named individuals, while system-to-system access should use tightly scoped credentials, certificates, or other machine-bound trust mechanisms. For connected OT environments, that distinction matters because a single overbroad account can bridge multiple zones and create a path from routine administration into operational control.
Access design should also reflect how OT work actually happens. Some connections are temporary, such as maintenance windows or emergency troubleshooting, and others are persistent, such as historian feeds or remote monitoring. Temporary access should expire automatically and be approved for a defined task, while persistent integrations should be documented, reviewed, and monitored as standing dependencies. If the environment cannot support that discipline, the team should assume the exposure is cumulative rather than one-off.
Encrypted transport and certificate verification are important, but they only help when paired with lifecycle control. A certificate or token that is issued once and never reviewed becomes a long-lived trust anchor, which is risky in converged environments where assets, vendors, and architectures change over time. Teams should know where credentials are stored, who can issue them, how they are rotated, and what happens when equipment is retired or a supplier relationship ends. For machine-to-machine links, the key question is not just whether the connection works, but whether the identity behind it can be traced, constrained, and revoked without disrupting the plant.
- Map every cross-domain access path to a named owner and an explicit business purpose.
- Use the narrowest feasible identity for each role, service, or integration.
- Require strong authentication and review any shared, inherited, or default access model.
- Monitor logins, certificate use, and privilege changes across both OT and IT sides.
- Test revocation and recovery so that access can be removed without guesswork.
This guidance breaks down when legacy OT equipment cannot support modern authentication, because compensating controls then have to absorb more of the trust burden.
Where OT and IT convergence creates the most awkward access edge cases
Tighter identity controls often increase operational overhead, so organisations have to balance traceability against the need for safe maintenance and rapid recovery. That tradeoff is most visible where vendor access, emergency use, and automation all intersect in the same control environment.
One common edge case is shared operational accounts. They may feel practical on the plant floor, but they erase accountability and make it difficult to distinguish normal maintenance from misuse. Another is long-lived service connectivity between OT data sources and IT platforms. Those links are often justified as business-critical, yet they can outlive the original need and quietly accumulate privilege. A third edge case is remote support, where a supplier needs access to diagnose an issue but should not gain standing access to the broader environment. The safer pattern is time-bound, scoped access with logging and review, rather than permanent trust.
There is also a governance distinction between identity used for control and identity used for observation. Read-only monitoring may seem low risk, but in converged environments it can still reveal topology, process timing, and asset relationships that help an attacker plan later movement. The practical answer is not to block visibility, but to treat observability tooling as part of the access model and limit what it can reach. For connected OT, that is where many programmes under-estimate the real exposure.
In connected OT and IT estates, the hardest problems usually appear where convenience, safety, and accountability all compete for the same access path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 — Identity Management and Access Control | OT-IT convergence is primarily an access governance problem. |
| PR.AC-4 — Access Permissions and Authorizations | Connected OT depends on tightly scoped authorization for operators and integrations. | |
| DE.CM-1 — Monitoring for Unauthorized Access | Visibility gaps are a key failure mode in converged OT and IT estates. | |
| Recommendation — Define and enforce unique identities and least privilege across all cross-domain access paths. Restrict permissions to the minimum required for each OT or IT role and integration. Monitor identity events and cross-domain activity for unauthorized or unusual access. | ||
| CIS Controls v8 | 6 — Access Control Management | The question centers on controlling and reviewing access across mixed environments. |
| 8 — Audit Log Management | Traceability is essential when OT actions and support sessions cross trust boundaries. | |
| Recommendation — Centralize access review, least privilege, and revocation for OT and IT identities. Collect and retain logs that tie privileged actions to specific users, services, and sessions. | ||
| MITRE ATT&CK | T1021 — Remote Services | Remote support and administrative links are a common cross-domain exposure path. |
| Recommendation — Hunt for remote administration paths that could be abused to enter or move within OT. | ||
Practitioner Guidance
What to prioritise: Focus first on the identities that can cross from IT into OT or directly influence operational behaviour. Those paths create the highest consequence if they are over-privileged, difficult to trace, or impossible to revoke quickly.
What to verify: Confirm that every cross-domain account, certificate, and remote support path has an owner, an expiry or review point, and a clear reason for existence. If any of those three are missing, treat the access path as an unmanaged dependency rather than a controlled service.
Decision rule: If an access path can change a process, stop a system, or bypass an operator workflow, it should be governed as privileged access even when it is implemented as a technical integration rather than a traditional login.
Practitioner takeaway: The most reliable convergence programmes do not try to make OT look like IT; they preserve OT operational constraints while forcing every identity path to remain explicit, bounded, and revocable.
Related resources from NHI Mgmt Group
- How should security teams govern Slack access like other high-value identity systems?
- How should security teams secure connected OT devices without relying on the old air gap?
- How should security teams govern AI vendors connected to OT systems?
- How should security teams secure hybrid data pipelines across cloud, on-prem, SaaS, and OT/IoT systems?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org