Network-centric controls tend to break down at the point where every new connection requires a rule change, a review, or a special path. In OT, that creates sprawl, inconsistent enforcement across vendors and sites, and a growing mismatch between operational needs and safety governance. Over time, the environment becomes harder to segment cleanly and harder to audit consistently.
Why network-centric OT controls start to fail as soon as access becomes operationally dynamic
Network-centric controls assume you can predefine who or what may talk to what, then keep that map stable. In OT, that assumption breaks quickly because vendors, sites, maintenance windows, and production changes constantly introduce new paths. Identity-driven access keeps the decision closer to the actor and the task, so access can be granted, bounded, and revoked without rewriting the network every time the operating model changes. OT and ICS Identity and Access Guide
The practical failure is not just administrative overhead. When access is expressed as static network reachability, teams end up compensating with exceptions, flat trust zones, and ad hoc firewall changes that slowly erode segmentation. That is why identity-aware access models are often paired with zero trust thinking in industrial environments: the control objective shifts from “is this source on the right network?” to “is this actor allowed to perform this action now?” Zero Trust Identity Guide
OT environments also punish inconsistency. Different vendors, controllers, and remote access paths rarely line up cleanly behind one policy layer, so network rules become uneven across plants and harder to review in a repeatable way. Identity-driven access gives you a more durable governance unit, because the review can focus on named users, service access, vendor access, and privileged sessions instead of a growing list of source and destination rules that drift apart over time. IAM and IGA Basics
Where segmentation, auditability, and vendor access become the first casualties
Once every new connection needs a special firewall path, segmentation stops being a clean design principle and turns into a queue of exceptions. That weakens auditability because the real question is no longer “what is segmented?” but “which temporary exception is still active, and why?” In practice, that makes it harder to prove least-privilege behavior across sites and harder to show that access paths match operational need rather than historical convenience.
Identity-centric access also matters because OT often depends on third parties, remote engineers, and maintenance tools that should be scoped to specific actions and time windows. If those relationships are handled only as network reachability, the organisation loses a precise way to separate routine operational traffic from privileged access that should be reviewed, time-bound, or revoked after use. That is exactly where OT governance becomes brittle: the control boundary becomes the subnet, not the accountable actor. Remote Access Identity Guide
For industrial networks, the better mental model is that segmentation supports containment, but identity determines authorization. Those are complementary controls, not substitutes. When the authorization model is weak, segmentation eventually gets used as a manual surrogate for access governance, and that is when change friction, review fatigue, and policy sprawl begin to dominate the environment. NIST SP 800-82 Rev 3 — OT Security Guide
What the operating model looks like when identity is the control plane
Identity-driven OT access works best when the access decision is tied to the session, the role, or the task, not to a permanently trusted route. That lets operators keep the network cleaner, because recurring needs are handled through policy and privilege rather than one-off connectivity exceptions. It also makes review more meaningful: you can ask whether a vendor, technician, or service path still needs access at all, instead of chasing the side effects of a rule that was added for a single incident months ago.
This model is strongest when paired with formal remote-access and privileged-access governance, because OT failures often come from overextended trust rather than from the initial connection itself. The practical objective is to keep network paths narrow while making the identity decision explicit, visible, and revocable. When that happens, segmentation becomes easier to maintain, because the network no longer has to carry the full burden of deciding who is allowed to do what. OT and ICS Identity and Access Guide CISA Industrial Control Systems
Risk and Threat Considerations
Network-centric OT access becomes risky when exceptions accumulate faster than they can be reviewed. Each new rule can create a new trust path, and attackers, contractors, or compromised remote tools can exploit those paths to move further than the original business need intended.
Failure mechanism: Static network trust expands through exceptions, shared routes, and poorly revisited vendor access, which makes it easier for one approved path to become a broader foothold.
Impact: The environment becomes harder to segment, harder to audit, and more exposed to lateral movement or misuse of remote access, especially where operational urgency suppresses normal review discipline.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | OT access should be limited to the minimum needed for each task. |
| IA-9 — Service Identification and Authentication | OT vendor tools and machine access often depend on authenticated non-user actors. | |
| Recommendation — Apply AC-6 to bound OT access by role, task, and necessity. Use IA-9 to authenticate service and machine access instead of trusting network location. | ||
| NIST Zero Trust (SP 800-207) | PR.AA-01 — Identity and Credential Management | Identity-driven OT access requires explicit, governed identities rather than implicit network trust. |
| Recommendation — Manage OT access through verified identities and bounded credentials. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | OT segmentation breaks down when access paths are managed through ad hoc network exceptions. |
| Recommendation — Centralise access approval and removal for OT connectivity. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | OT access decisions need a formal access-control policy rather than network-only rules. |
| Recommendation — Define OT access control rules that align with operational roles and needs. | ||
Practitioner Guidance
What to prioritise: Treat recurring vendor, maintenance, and operator access as an identity and privilege problem first, then map the minimum network exposure required to support it. If you start with the firewall, you usually end up encoding exceptions that outlive the job they were created for.
What to verify: Check whether every standing OT connection is justified by a current operational need, has an accountable owner, and can be revoked without reengineering the site’s segmentation model. If the answer is no, the control is probably carrying business convenience rather than security intent.
Practitioner takeaway: In OT, the network should constrain reach, but identity should decide authorization. If the network becomes the primary access decision point, exception management will eventually erode segmentation, auditability, and governance at the same time.
Related resources from NHI Mgmt Group
- What breaks when organisations manage non-human access with legacy shared secrets instead of identity-centric controls?
- What breaks when network controls are used instead of request-level policy for machine access?
- What breaks when access to servers and databases is managed through broad network reach instead of roles?
- What breaks when access decisions are tied to network location instead of identity?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org