Because context determines whether a signal deserves expensive retention or can be routed elsewhere. If asset ownership, threat intelligence, and identity context arrive only after ingestion, the organisation has already paid full SIEM cost and lost the chance to make a timely routing decision. Pre-ingestion enrichment makes the pipeline itself a control point.
Why This Matters for Security Teams
OT telemetry is expensive to store, but the bigger problem is that raw events often lack the context needed to decide whether they belong in the security pipeline at all. Without enrichment, teams cannot reliably distinguish a PLC change from normal maintenance, a stale asset from an active production node, or an authenticated engineering session from suspicious remote activity. That creates noise, slows triage, and weakens containment when something is genuinely wrong.
Pre-ingestion enrichment is therefore not just a logging preference. It is a control design choice that improves routing, prioritisation, and downstream response. For OT, that matters because availability and safety often outweigh pure alert volume reduction. The NIST Cybersecurity Framework 2.0 places risk management, asset visibility, and detection planning at the centre of an operational programme, which is exactly where enrichment belongs.
Security teams often assume enrichment can wait until events are inside the SIEM, but in practice many OT incidents become visible only after the system has already been flooded with unactionable machine data and the useful context has been lost.
How It Works in Practice
In OT environments, enrichment should happen as close to the source as possible, before events are sent to the SIEM, data lake, or SOAR platform. The goal is to attach enough context for automated routing and meaningful prioritisation without changing the original telemetry. That context usually includes asset identity, site or line information, vendor or model data, criticality, expected communication patterns, user or service account attribution, and threat intelligence indicators when they are relevant.
A practical enrichment pipeline typically pulls from CMDBs, asset inventories, identity stores, network segmentation maps, and OT-specific reference data. For example, a network connection from a historian server to a controller may be normal in one plant and high risk in another, depending on ownership, zone, and approved function. Enrichment gives the event a decision profile so that the ingestion layer can route it to long-term retention, short-term monitoring, or immediate escalation.
- Tag events with asset criticality before they reach expensive storage.
- Map IPs, hostnames, and service identifiers to real OT assets and owners.
- Attach identity context so remote access, jump host use, and privileged sessions are visible.
- Normalize protocol-specific data so alerts are consistent across vendors and plants.
- Use threat intelligence selectively, because over-enrichment can create false confidence if indicators are stale.
This approach aligns with CISA guidance for ICS monitoring, which emphasises asset-aware detection and operational context, and with the MITRE ATT&CK for ICS model, which helps analysts relate observed activity to realistic attack paths. It also matters for identity governance because OT access often depends on shared engineering workstations, service accounts, and jump infrastructure, where identity context is the difference between normal operations and an abuse path.
These controls tend to break down when enrichment sources are fragmented across plants and vendors, because the pipeline cannot make reliable routing decisions from inconsistent asset, identity, and ownership data.
Common Variations and Edge Cases
Tighter enrichment often increases integration overhead, requiring organisations to balance faster triage against the cost of maintaining clean asset and identity data. In mature environments, that tradeoff is worth it. In smaller OT estates, the best practice is evolving toward lightweight enrichment that captures only the fields needed for risk decisions rather than attempting full schema normalization on day one.
There is no universal standard for how much enrichment is enough. Some teams enrich only high-value assets and privileged sessions, while others enrich all telemetry from critical zones. The right answer depends on process criticality, network segmentation, and how much trust exists in the source systems. If the CMDB is stale, enrichment can mislead analysts, so current guidance suggests treating enrichment data as a controlled dependency rather than a guaranteed source of truth.
OT identity also changes the design. Shared operator logins, vendor remote support, and break-glass access can make attribution difficult, so teams should enrich events with session broker data, jump host records, and approval context where available. Where OT and IT monitoring converge, enrichment should preserve protocol detail and zone information so that detection logic does not flatten important differences.
For highly regulated environments, this matters even more because NIST Cybersecurity Framework 2.0 style governance works best when telemetry is already decision-ready at ingestion. In practice, enrichment fails when organisations treat it as a one-time data project instead of an operational control tied to asset lifecycle and access governance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM | Enrichment improves continuous monitoring by adding asset and identity context. |
| MITRE ATT&CK | T0866 | OT telemetry becomes useful when mapped to ICS-specific adversary techniques. |
| NIST Zero Trust (SP 800-207) | Zero Trust depends on identity and context to make access and routing decisions. | |
| NIST AI RMF | The governance mindset applies when enrichment relies on automated classification and routing. |
Map enriched events to ICS techniques so analysts can separate normal operations from attack activity.
Related resources from NHI Mgmt Group
- What breaks when enrichment happens after ingestion instead of before it?
- Why do OT environments need different privileged access controls than enterprise IT?
- How should organisations manage privileged access in IoT and ot environments?
- Why do IoT and ot environments create different security risks from standard IT systems?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org