Because the resistance is usually rooted in legitimate operational safety concerns, not stubbornness. OT systems often cannot absorb live IAM syncs without introducing downtime or control instability, so the risk is stale access rather than over-centralisation. The challenge is to gain visibility and lifecycle control without violating the plant's safety model.
Why OT Identity Governance Breaks When You Force IT-Style Integration
The core issue is that OT identity governance sits inside a control environment where availability and deterministic behaviour matter more than rapid centralisation. Safety teams resist integration because live synchronisation, aggressive recertification, or brittle connectors can destabilise operational systems. The real governance problem is therefore not lack of intent, but how to gain account visibility, ownership, and lifecycle control without changing the plant’s safety characteristics.
That tension is why OT identity work often fails when it is treated as a standard IAM rollout. OT assets may depend on shared access patterns, vendor access, legacy protocols, or segmented supervisory layers that cannot tolerate constant changes. A governance model that ignores those constraints creates operational risk first, then identity risk second.
What Risk OT Identity Governance Is Actually Trying to Reduce
In OT, stale access is dangerous because it can outlive the job, the shift, or the vendor engagement that justified it. When access reviews are delayed or ownership is unclear, dormant accounts, over-privileged service access, and unmanaged vendor paths accumulate quietly. That is why a control model focused on visibility and lifecycle discipline is more useful than one focused only on central policy enforcement. For a broader lifecycle view, NHI Lifecycle Management Guide is directly aligned with the same provisioning, rotation, and offboarding problem.
Governance also has to respect OT segmentation and change windows. If the control plane cannot safely touch an asset in real time, the answer is not to remove governance, but to redesign it around low-impact discovery, periodic certification, and clearly owned exceptions. That is where OT identity differs from office IT: the acceptable control objective is usually bounded visibility and accountable lifecycle management, not perfect synchronisation at all times.
OT programmes often fail when they assume every identity can be managed through the same workflow. The safer pattern is to classify accounts by operational criticality, vendor dependency, and whether a change can be automated or must remain manual. That distinction matters because a failed identity update in OT can become a plant incident, not just an access issue. A practical comparator is OT and ICS Identity and Access Guide, which focuses on shared accounts, vendor remote access, IEC 62443 identification requirements, PAM for OT, and segmentation.
Why Safety Teams Resist Integration, and Why That Resistance Is Rational
Safety teams usually resist integration because they are protecting the control system from side effects that IT teams can absorb but OT cannot. A polling agent, connector failure, synchronisation loop, or poorly timed entitlement update can interrupt an engineering workstation, a historian, or a controller-supporting process. In a plant context, even a control that is correct on paper can be unacceptable if it changes timing, load, or operator trust in the system.
The same applies to vendor and shared-access patterns. OT environments often inherit access models that were designed to preserve continuity, not to satisfy modern governance ideals. The risk is not that these patterns exist, but that they remain undocumented and unowned. That is why the governance question must begin with inventory, ownership, and exception handling, not with tool replacement. If you need a checklist for evaluating whether the controls are actually closing the loop, Access Reviews and Certification Guide is useful because it emphasises risk-based review design and remediation rather than rubber-stamping.
How to Gain Control Without Violating the Plant Safety Model
The practical answer is to separate visibility from enforcement. Start by discovering who can access what, who owns each account, and which access paths are tied to safety-critical operations. Then decide which accounts can support lifecycle automation, which require scheduled review, and which must be governed through compensating controls such as manual approvals, segmented admin paths, or tightly scoped vendor windows. For broader governance structure, IAM and IGA Basics provides the foundational distinction between authentication, authorization, provisioning, and access governance.
Good OT identity governance also depends on role design and exception discipline. If every engineer, integrator, and supplier gets custom entitlements, the environment will drift into privilege creep and no one will be able to prove why access exists. If roles are too coarse, safety teams will reject them because they blur operational boundaries. The workable middle ground is smaller, explicitly owned access bundles with documented exceptions and expiry points. A role-oriented operating model is easier to sustain when paired with Role Mining and Role Design Guide and a disciplined certification process.
When governance is mature, the plant can answer three questions quickly: who has access, why they have it, and when it will be removed. If those answers are missing, the system is exposed even if no integration has yet been approved. That is the point safety teams often understand best: the goal is not to integrate everything, but to make access defensible without introducing instability. The strongest operating model is one that preserves safety boundaries while still shrinking the population of unknown, stale, or excessive access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.SC-01 — Cybersecurity Supply Chain Risk Management Strategy | OT identity governance depends on vendor and supplier access paths in the plant. |
| Recommendation — Define supplier-access governance and review vendor identity paths in OT. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | OT identity governance must manage credentials, rotation, and stale access safely. |
| AC-2 — Account Management | The question centers on account visibility, ownership, provisioning, and offboarding in OT. | |
| Recommendation — Enforce credential lifecycle controls for OT accounts and access paths. Maintain account inventory, ownership, and timely deprovisioning for OT. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | OT governance needs defined identity ownership and lifecycle control. |
| A.5.18 — Access rights | The risk is stale or excessive OT access that must be reviewed and removed. | |
| Recommendation — Assign and govern identities with explicit ownership and lifecycle rules. Review and remove OT access rights on a defined schedule. | ||
Practitioner Guidance
What to prioritise: Start with inventory and ownership before automation. In OT, knowing which accounts are shared, vendor-managed, dormant, or safety-sensitive is more valuable than trying to centralise every control on day one.
Decision rule: If a proposed sync or review action can affect control timing, availability, or operator trust, treat it as a safety-impacting change and route it through OT change governance rather than standard IAM rollout.
What to verify: Verify that each account has an owner, an expiry or review path, and a clear reason for existence. If any of those are missing, the access should be treated as an exception, not as business as usual.
Practitioner takeaway: OT identity governance works when it reduces unknown access faster than it increases operational fragility; if a control makes the plant less predictable, it is the wrong control even if it looks better on paper.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org