Air-gapped OT relies on isolation and physical separation to limit access, while converged IT OT identity management assumes connected environments and governs access through identity controls. In practice, the first reduces exposure by separation, but the second supports modern industrial operations by adding visibility, access review, and revocation across cloud, on premises, and hybrid assets.
Why the distinction matters in real OT environments
Air-gapped OT and converged IT OT identity management solve different problems. Air-gapping tries to reduce exposure by keeping the OT environment physically and logically separate. Converged identity management assumes some level of connectivity and uses identity, privilege, and review controls to govern that access. The operational trade-off is simple: separation lowers reachability, while convergence improves control and visibility.
An air-gapped model is strongest when the environment can stay isolated with tightly managed transfer points, because the security boundary is the network break itself. A converged model becomes necessary when operations depend on remote support, shared platforms, analytics, vendor access, or hybrid infrastructure. In that setting, the question shifts from “can anything connect?” to “who can connect, what can they do, and how is that access revoked?”
The practical difference is not only architectural, it is also administrative. Air-gapped OT often relies on procedural controls, local approvals, and physical access discipline. Converged identity management adds centralized account ownership, access review, and faster revocation, which matters when access paths span cloud services, on-prem systems, and remote tools. For readers comparing the two, Ultimate Guide to NHIs is useful background on visibility, lifecycle, and Zero Trust mechanics that sit behind converged access control.
What changes in identity, access, and governance
In an air-gapped OT design, identity management is usually local, limited, and often less integrated with enterprise IAM. That can reduce the number of identities exposed to central systems, but it also makes discovery, review, and revocation slower and more manual. The main security benefit is reduced attack surface; the main limitation is that administrative discipline must compensate for the lack of centralized control.
In converged IT OT identity management, identity becomes the control plane for access across environments. That means stronger focus on account ownership, role assignment, least privilege, session review, credential rotation, and offboarding. This model is especially important when human administrators, vendors, and automation all need time-bound access to operational systems. The issue is not just authentication, but governance over standing access and privileged actions.
That is why lifecycle controls matter more in converged environments than in a purely isolated one. If a credential can reach both IT and OT assets, revocation speed, visibility, and scope boundaries become material to safety and resilience. The NHI Lifecycle Management Guide and Top 10 NHI Issues both map well to the converged model because they focus on ownership, rotation, offboarding, and excessive privilege.
When each model is the better fit
Air-gapped OT is usually the better fit when the operational requirement is high containment, the environment tolerates slow change, and remote integration is genuinely unnecessary. It is also easier to reason about when the main objective is to keep critical process control separated from corporate systems. But it becomes brittle when teams start introducing exceptions, temporary bridges, unmanaged laptops, or ad hoc transfer media.
Converged IT OT identity management is the better fit when operations need central visibility, remote administration, vendor access, auditability, or faster incident response. It works best when every access path is attributable and reviewable, and when privileged access is time-bound rather than persistent. In practice, this is the more realistic model for hybrid industrial estates, but it only works if identity governance is treated as part of the OT security design, not as an IT overlay.
For implementation context, NIST SP 800-82 Rev 3, OT Security Guide is the most direct external reference for OT segmentation and control design, while CISA Industrial Control Systems is useful for operational guidance and advisories around industrial environments.
Risk and Threat Considerations
Converged IT OT identity management creates a larger trust boundary, so compromise of a single privileged account, remote access path, or identity provider can affect both enterprise and operational assets. Air-gapped OT reduces that exposure, but the residual risk shifts to physical access, removable media, jump hosts, and exception handling.
Failure mechanism: In converged environments, overprivileged accounts, weak offboarding, and shared admin paths let an attacker move from a low-friction IT entry point into OT systems. In air-gapped environments, the common failure is boundary erosion, where temporary connectivity or manual transfers become the hidden bridge.
Impact: The impact of a converged identity failure can include unauthorized OT command execution, loss of monitoring integrity, and broader operational disruption. The impact of an air-gap failure is often smaller in count of exposed identities but higher in consequence if the isolation assumption is broken at the wrong moment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Access Control | Controls how access is governed across connected IT OT environments. |
| ID.AM — Asset Management | OT convergence depends on knowing which identities, assets, and boundaries exist. | |
| GV.OC — Organizational Context | The choice between air-gap and convergence depends on operational and trust assumptions. | |
| Recommendation — Apply PR.AC to enforce least privilege, review, and revocation across IT OT access paths. Maintain an accurate inventory of OT and connected assets to support governed access decisions. Define whether OT isolation or governed connectivity is the operating model and align controls accordingly. | ||
| NIST Zero Trust (SP 800-207) | JEA — Just-Enough-Access and Just-In-Time Access | Converged OT identity management needs time-bound, minimal access for administrators and vendors. |
| Continuous Verification — Continuous Verification | Connected IT OT environments need ongoing trust checks, not one-time access approval. | |
| Recommendation — Use just-enough, just-in-time access for OT administration instead of standing privileged access. Continuously verify identity, device, and session trust before permitting OT access. | ||
| CIS Controls v8 | 6 — Access Control Management | Directly addresses account ownership, privilege limitation, and revocation in converged environments. |
| 5 — Account Management | Covers lifecycle controls for accounts that span IT and OT systems. | |
| Recommendation — Centralize account ownership and promptly remove unnecessary OT access. Inventory, approve, and deactivate accounts across the OT access lifecycle. | ||
Practitioner Guidance
What to verify: Treat the model choice as a boundary question, not a naming question. Verify whether the site is truly isolated, whether exceptions exist, and whether remote access, vendor support, or cloud integration already means the environment is functionally converged.
Decision rule: If access can cross the IT OT boundary, manage it as converged and require ownership, review, and revocation evidence. If the environment is genuinely air-gapped, focus on boundary discipline, transfer controls, and the process used to approve every exception.
What practitioners underestimate: Air-gapped OT can hide governance gaps because the absence of connectivity creates a false sense of safety. Converged identity management can also be misused as a replacement for segmentation; it is a control layer, not a substitute for architecture.
Practitioner takeaway: The real distinction is not isolation versus identity in the abstract, it is whether the security model depends primarily on physical separation or on continuously governed access paths.
Related resources from NHI Mgmt Group
- What is the difference between attack surface management and NHI governance?
- What is the difference between patching a vulnerability and reducing identity blast radius?
- What is the difference between identity analytics and access policy enforcement in campus identity governance?
- What is the difference between using separate identity projects and using a shared session proxy across domains?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org