The boundary between business systems and production systems stops being meaningful. A single credential or federation path can become a plant-impacting path, which turns what looks like an access issue into an uptime issue. Teams need to govern those identities as operational risk, not just account inventory.
When Manufacturing Identities Cross the IT and OT Boundary
The practical break point is not just technical integration, it is control ownership. Once a manufacturing identity can authenticate to both enterprise and plant environments, the same trust path can carry routine access, vendor support, and misuse into systems where availability and safety matter more than convenience.
That shifts the problem from “who has an account” to “what can this identity reach, on what terms, and with what blast radius if it is abused.” In converged environments, identity decisions become part of operations design, not a back-office IAM hygiene task.
At that point, segmentation, federation, and privilege design have to be treated as a single exposure surface. A credential that looks harmless in IT can become the bridge into production if the path is allowed to traverse tiers, translate trust, or reuse the same control plane across both domains.
Where the Failure Shows Up First
The first failure is usually not a dramatic compromise, it is trust expansion. When one identity spans office systems and production systems, teams often inherit hidden assumptions about approvals, session lifetime, vendor access, or emergency use that were acceptable in IT but unsafe in OT.
That is why plant access needs to be evaluated as an operational dependency. If the identity can reach historians, engineering workstations, remote access gateways, or control-layer services, the question is no longer whether the account is “shared” or “service-like”, but whether its path can affect uptime, safety interlocks, or recovery procedures.
Practitioners should also expect governance drift. Ownership is often split between IAM, infrastructure, and operations teams, so revocation, rotation, and exception handling become slow just where fast containment is most important.
What Changes in Access Governance Once IT and OT Share Identities
Access governance has to move from user provisioning to path governance. That means documenting which identities can cross the boundary, why they are allowed, and what compensating controls keep an IT compromise from becoming an OT event.
In practice, OT and ICS Identity and Access Guide is the right internal reference point because it treats remote access, shared accounts, segmentation, and privileged access as operational controls rather than abstract identity topics.
For the broader identity model, Ultimate Guide to NHIs, what are Non-Human Identities is useful when the manufacturing path depends on service accounts, tokens, or machine-to-machine trust. Those are often the mechanisms that quietly bridge IT and OT.
Where teams need programme-level ownership, Identity Security Programme Guide helps frame the issue as a governed operating model, which is important when multiple teams own different pieces of the same access path.
Risk and Threat Considerations
When manufacturing identities reach both IT and OT, the main risk is cross-domain blast radius. A compromise that begins as ordinary credential theft, vendor abuse, or session hijacking can turn into plant disruption if the same trust path can reach production systems without meaningful isolation.
Failure mechanism: Shared or federated access paths, weak segmentation, and overprivileged credentials let an attacker move from enterprise access into plant-accessible systems, then pivot toward remote administration or operational services.
Impact: The result can be loss of availability, unsafe operational change, delayed recovery, and a much wider incident because IT containment no longer contains the problem.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-9 — Identification and Authentication (Non-Organizational Users) | Covers federated and external identities that can span IT and OT trust boundaries. |
| AC-6 — Least Privilege | Limits what a cross-domain manufacturing identity can do if compromised. | |
| IA-5 — Authenticator Management | Addresses lifecycle, rotation, and protection of credentials used across IT and OT. | |
| Recommendation — Require strong federation controls for any identity that can cross into production systems. Restrict cross-domain identities to the minimum production actions they truly need. Enforce rotation, protection, and recovery rules for credentials that reach both domains. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Shared service and machine identities can become plant-impacting if overprivileged. |
| NHI-08 — Environment Isolation | Crossing IT and OT boundary without isolation is the core exposure in this topic. | |
| Recommendation — Review machine and service identities for excessive production permissions. Separate IT and OT trust zones so one identity cannot traverse both by default. | ||
Practitioner Guidance
What to verify: Confirm whether the identity can reach OT through direct login, federation, VPN, jump host, vendor portal, or privileged session tooling. If any path is reusable across both environments, treat it as a high-priority exposure until you can prove the blast radius is constrained.
Decision rule: If an identity can affect production uptime, do not manage it as a routine account. Put it under operational owner review, require explicit business justification, and make revocation and break-glass handling testable rather than assumed.
What practitioners underestimate: The dangerous part is often not permanent admin privilege, but a “temporary” path that becomes permanent through exceptions, shared support processes, or vendor dependency. Those paths deserve the same scrutiny as standing privilege because they can produce the same outcome.
Practitioner takeaway: In IT/OT convergence, the access question becomes a resilience question, so the control objective is not just to authenticate users or systems, but to keep any single identity from becoming a plant-impacting trust bridge.
Related resources from NHI Mgmt Group
- What breaks when OT systems are not segmented in manufacturing environments?
- What breaks when manufacturing security teams do not have asset context for IT and OT systems?
- How should security teams govern non-human identities at scale?
- How should security teams govern non-human identities for compliance?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org