Skip to content
Choice Solutions Limited

IT/OT convergence

IT/OT convergence and operational reality

IT and OT carry different priorities, different lifecycles, and different definitions of risk. Convergence works when the boundary between them is designed, not assumed.

7 minute read

Two engineering cultures, both correct

Enterprise IT optimizes for confidentiality, patch currency, and rapid change. Operational technology optimizes for availability, determinism, and equipment safety, often on assets with twenty-year lifecycles that cannot be patched on an enterprise cadence.

Neither position is wrong. Problems appear when one set of assumptions is applied to the other domain — an enterprise patch policy imposed on a control network, or an unmanaged plant network exposed to enterprise traffic.

Engineer the boundary explicitly

A workable convergence design makes the boundary a first-class part of the architecture: segmented zones, defined conduits between them, controlled remote access, and an explicit list of what data is allowed to cross in each direction.

Published guidance is useful here. NIST's guide to operational technology security sets out zone and conduit thinking, risk management for OT, and the practical differences from enterprise IT security programmes.

  • Segment by function and consequence, not by convenience of existing cabling.
  • Define each crossing point, its direction, and the data it carries.
  • Route remote access through controlled paths with plant-side authorization.
  • Agree change control that both IT and plant engineering can actually follow.

Data without context is not information

Most plants already produce more measurement than anyone uses. The gap is context: what a value means, whether it was valid at the time it was recorded, what state the asset was in, and how to reconcile conflicting sources.

Historians, edge collection, and integration layers should be designed to carry that context alongside the value. Without it, enterprise reporting produces numbers that plant teams do not recognize — and correctly do not trust.

Exceptions are the design, not an afterthought

Interfaces between plant and enterprise systems fail in ordinary ways: a link is down, a value arrives late, a batch is incomplete. If the design has no defined exception path, those cases quietly become data quality problems that surface months later.

We treat the exception path as part of every integration: incomplete or delayed information is held for review and reconciliation rather than passed through as though it were complete.

Ownership at the boundary

The most common operational failure in convergence is not technical. It is that nobody owns the boundary. Firewall rules, remote access accounts, historian tags, and interface monitoring each need a named owner on both sides.

Getting that agreed early is usually harder than the engineering, and it is what determines whether the design still holds two years after go-live.

Convergence is not IT taking over OT, or OT resisting IT. It is a deliberately engineered boundary that both teams can operate.

References

Apply this to your environment.

Bring us the specifics — the estate, the constraints, the systems involved — and we will tell you what the work would actually look like.