IT and OT convergence expands the number of pathways, protocols, and device types that must be trusted and controlled. When legacy systems, unmanaged devices, and connected sensors share the same environment, attackers can move laterally more easily if access is not tightly segmented. Identity-based controls help reduce that exposure by limiting unnecessary reach between assets.
Why IT and OT Convergence Creates More Paths for Lateral Movement
IT and OT convergence matters because it collapses boundaries that historically limited how far an attacker could travel after an initial foothold. When enterprise systems, engineering workstations, historians, remote access tools, and industrial controllers sit closer together, trust relationships multiply and segmentation becomes harder to reason about. NIST Cybersecurity Framework 2.0 is a useful lens here because it treats governance, asset visibility, and protective architecture as linked controls rather than separate concerns.
In industrial environments, lateral movement risk often rises not because one device is especially weak, but because the environment contains mixed trust levels, legacy protocols, and operational exceptions that were added for uptime. That combination gives an attacker more opportunities to reuse access, pivot through shared services, or abuse administrative pathways that were never designed for broad enterprise connectivity. In practice, many security teams discover this after remote access, vendor support, or flat network design has already created an unexpected bridge between business systems and control assets.
How Lateral Movement Happens Across Connected IT and OT Layers
Once IT and OT are interconnected, an attacker rarely needs a direct route to a controller or safety system. A more common path is to compromise a lower-friction IT asset first, then move through shared identity, remote administration, file transfer, monitoring, or engineering tooling until they reach systems with greater operational impact. The exact path depends on the environment, but the mechanism is consistent: every added trust edge can become a stepping stone.
Industrial networks often contain several features that make this easier. Windows-based engineering stations may share credentials or administration patterns with corporate endpoints. Remote support channels may bridge zones that were meant to stay separate. Legacy protocols can expose services without modern authentication. Even when the process is legitimate, the attacker may only need to inherit a trusted session, harvest credentials, or abuse an allowed management path to continue laterally.
- Shared identity and remote access can turn one compromise into several reachable systems.
- Flat or weakly segmented networks let discovery traffic become access to higher-value assets.
- Legacy OT devices may accept traffic that enterprise defenders cannot easily inspect or authenticate.
- Monitoring gaps matter because lateral movement often looks like normal maintenance activity until it is too late.
That is why zero trust concepts and strong identity governance are relevant even in industrial contexts. NIST SP 800-207 Zero Trust Architecture is especially useful when teams need to separate network location from access entitlement, while NIST SP 800-63 Digital Identity Guidelines helps frame stronger authentication for the identities that do traverse those boundaries. Where this guidance breaks down is in environments that cannot support segmentation or identity enforcement without disrupting essential operations, because the control design then has to be adapted to process constraints rather than applied as a generic IT pattern.
Where the Risk Is Highest in Mixed Industrial Environments
Tighter segmentation often increases operational overhead, so organisations have to balance resilience against maintainability and emergency access needs. That tradeoff becomes most visible in plants that rely on shared admin accounts, vendor connectivity, or aging assets that cannot be patched or reauthenticated in the same way as modern IT systems.
There are a few edge cases worth calling out. First, not every OT asset is equally exposed; systems isolated behind dedicated jump hosts or strict conduits are materially different from zones that share broad enterprise connectivity. Second, some industrial protocols are read-heavy and appear low risk, but read access can still support reconnaissance that precedes lateral movement. Third, converged environments sometimes use compensating controls such as allowlists or one-way gateways, but those controls only reduce risk if they are consistently enforced and monitored rather than assumed to be present.
Industry consensus is strong that visibility and segmentation matter, but there is less consensus on how much identity control can be pushed into older OT stacks without creating unacceptable operational fragility. For that reason, the real question is not whether convergence is “good” or “bad”; it is whether each connection has a clear business justification, a defined trust boundary, and a way to detect unexpected pivoting activity. MITRE ATT&CK Enterprise Matrix is helpful for thinking through how an attacker might chain discovery, credential access, and lateral movement across mixed environments, while NIST SP 800-53 Rev 5 Security and Privacy Controls provides a control vocabulary for access restriction, monitoring, and boundary protection. The guidance becomes less reliable when an organisation treats OT exceptions as permanent and unreviewed, because that is where hidden pathways tend to accumulate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Access Control | Convergence widens trust paths, so access restriction is central to lateral movement reduction. |
| DE.CM — Continuous Monitoring | Lateral movement in mixed IT/OT often blends into normal administration without strong monitoring. | |
| PR.PT — Protective Technology | Segmentation and boundary protection directly shape how far an attacker can travel after entry. | |
| Recommendation — Restrict cross-zone access to the minimum required and remove standing trust paths. Monitor cross-environment activity for unexpected pivoting and administrative reuse. Use protective boundaries to limit movement between enterprise and industrial zones. | ||
| NIST AI RMF | GV.1 — Governance and Roles | Mixed IT/OT trust paths need clear ownership and accountable approval for each connection. |
| Recommendation — Assign ownership for every cross-zone bridge and review it as a governed exception. | ||
| CIS Controls v8 | Control 6 — Access Control Management | Shared accounts and broad admin reach are common pivot points in converged networks. |
| Recommendation — Reduce lateral movement by tightening account scope and removing unnecessary access. | ||
| MITRE ATT&CK | T1021 — Remote Services | Remote admin and support channels are frequent pivot routes across IT and OT boundaries. |
| Recommendation — Hunt for remote-service abuse and unexpected administration across trusted conduits. | ||
Practitioner Guidance
What to prioritise: Map the actual conduits between IT and OT before debating tool choices. The most valuable review is usually not asset inventory alone, but the small set of accounts, jump paths, and management channels that can reach both sides of the boundary.
What to verify: Verify that every cross-zone pathway has a business owner, an authentication requirement, and a revocation path. If a pathway exists only because it has “always been there,” treat it as an exposure until proven otherwise.
What practitioners underestimate: Lateral movement in industrial networks is often enabled by ordinary administration, not exotic exploitation. The deciding factor is usually whether maintenance convenience has quietly become standing trust across zones.
Practitioner takeaway: The safest converged environments are not the ones with the most controls, but the ones where every permitted bridge is narrowly justified, observable, and hard to reuse outside its intended purpose.
Related resources from NHI Mgmt Group
- Why do shared VPNs and jump boxes increase lateral movement risk in OT networks?
- Why do perimeter VPNs increase lateral movement risk in enterprise networks?
- Why do living off the land attacks in OT increase lateral movement risk so sharply?
- Why do trusted management protocols increase lateral movement risk in enterprise networks?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org