They work best when segmentation limits where access can reach and identity controls determine who may use the path. Segmentation without strong authentication still leaves a broad trust problem, while identity without segmentation can leave too much lateral movement once access is granted. The two controls are complementary, not interchangeable.
How SCADA segmentation and identity controls reinforce each other
In SCADA, segmentation is strongest when it constrains where a session can go, while identity controls constrain who can open that session in the first place. Used together, they reduce both the blast radius of a compromise and the chance that a permitted login becomes a bridge into control zones, engineering workstations, or vendor paths.
This pairing matters because industrial environments still rely on shared assets, legacy protocols, and tightly coupled remote access paths. A network boundary without strong identity can still become a broad trust corridor, while identity without segmentation can leave one compromised account able to reach far more systems than it should.
For OT environments, NIST’s operational technology guidance and OT and ICS Identity and Access Guide both reflect the same operating reality: network design and access governance have to be built together, not tuned independently. Segmentation defines the route, identity defines the permission to use it.
Where the control pair adds the most value
The combination works best at trust boundaries that already carry operational sensitivity, such as vendor remote access, engineering workstations, jump hosts, historian access, and paths into safety-adjacent systems. In those cases, segmentation limits which zones are even reachable, while identity and authorization decide whether the user, service, or session should proceed.
The practical gain is highest when access is temporary, role-specific, and observable. A technician, integrator, or support vendor may need a narrow path into one cell or conduit, but should not inherit lateral reach across the control network. That is where identity controls, session approval, and time-bound access complement microsegmentation or zone-and-conduit design.
For identity lifecycle discipline, the NHI Lifecycle Management Guide is relevant because access that is not provisioned, reviewed, rotated, and retired cleanly tends to outlive the segmentation assumptions that were built around it. In SCADA, stale access is not just an account problem, it becomes a pathing problem.
Zero trust principles also fit this pattern well. The Zero Trust Identity Guide and NIST SP 800-207 both support the same design principle: do not let network location become a proxy for trust. In OT, that means using identity, device posture, and explicit authorization as the decision layer that sits on top of segmentation.
Why SCADA needs both controls, not one substitute for the other
SCADA environments often fail when segmentation is treated as a perimeter and identity is treated as an admin convenience. If segmentation is the only guardrail, any authenticated session that reaches the zone may be over-accepted. If identity is the only guardrail, a compromised credential can still roam too widely once authenticated.
The best pattern is layered trust reduction. Segmentation should limit protocol exposure and reachable assets, while identity should limit which human, service, or vendor principal can use the path, for how long, and under what conditions. That combination is especially important where remote maintenance, shared toolchains, or third-party support are unavoidable.
That is also why OT security references such as NIST SP 800-82 Rev 3, OT Security Guide and CISA Industrial Control Systems consistently emphasise segmented architectures, controlled remote access, and defensible trust boundaries rather than flat networks with loose login control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-9 — Identification and Authentication (Service and External Systems) | SCADA paths often depend on service, vendor, and system-to-system authentication. |
| AC-4 — Information Flow Enforcement | Segmentation in SCADA is fundamentally about controlling which flows can cross boundaries. | |
| AC-17 — Remote Access | Vendor and maintenance access are common SCADA exposure points that need both identity and segmentation. | |
| Recommendation — Enforce strong authentication for system-to-system and remote OT access paths. Define and enforce zone boundaries so only approved OT flows can traverse them. Restrict remote OT access to approved paths, sessions, and conditions. | ||
| NIST Zero Trust (SP 800-207) | 1 — All data sources and computing services are considered resources | SCADA access should be decided per resource path rather than by network location alone. |
| 3 — Never trust, always verify | Combines identity verification with segment-controlled access for industrial environments. | |
| Recommendation — Treat each OT service and segment as a distinct resource requiring explicit policy. Verify identity and context before allowing any OT session to proceed. | ||
Practitioner Guidance
What to prioritise: Put identity controls at the exact choke points where SCADA access crosses a zone boundary, then verify that the boundary actually enforces that decision. If a principal can authenticate but still reach multiple cells, trust the segmentation less than you think.
What to verify: Test the full path, not just the login event. Confirm that remote access, jump hosts, vendor sessions, and engineering workflows all enforce the intended zone restrictions, session scope, and approval rules. A clean authentication flow is not enough if lateral movement is still available after entry.
What good looks like: A valid user or service can reach only the minimum OT segment needed for the task, with time-bound access, strong authentication, and auditable session behavior. The observable state is narrow reachability plus narrow authorization, not one compensating for the absence of the other.
Practitioner takeaway: In SCADA, segmentation and identity controls should be designed as one control plane for trust reduction. If either one is doing all the work, the architecture is probably carrying hidden lateral movement risk.
Related resources from NHI Mgmt Group
- How should security teams assess whether their identity controls work together as a system?
- What breaks when AI workloads rely on network segmentation instead of identity controls?
- Why do identity controls need to work with segmentation in Zero Trust programmes?
- How do identity controls and endpoint DLP work together in practice?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org