OT/IT Convergence: Architecture Patterns That Work
For Australian industrial operators, the boundary between Operational Technology (OT) and Information Technology (IT) has shifted from a physical air-gap to a contested architectural battleground. Driven by decarbonisation mandates, predictive asset management, and the need for operational visibility across distributed assets—from the Pilbara to the Hunter Valley—enterprises are connecting operational systems to enterprise networks at scale. However, connecting mission-critical control loops directly to enterprise systems introduces systemic cyber, operational, and safety risks. Bridging this divide requires architecture patterns that respect deterministic control while enabling modern enterprise telemetry.
1. The Hardened Industrial DMZ (IDMZ) and Level 3.5 Isolation
The traditional Purdue Enterprise Reference Architecture remains relevant, but its implementation has evolved. The most reliable pattern for securing the interface between Level 3 (Operations Management) and Level 4 (Enterprise Systems) is a strictly enforced Industrial Demilitarized Zone (IDMZ), designated as Level 3.5. Direct routing between enterprise networks and plant-floor control networks must be completely prohibited.
To implement this pattern effectively across heavy industrial facilities, engineering teams should apply three baseline rules:
- No shared credentials: Active Directory domains in OT must be structurally independent of corporate Azure AD or on-premises forests. Compromise of corporate identity must not grant administrative access to the OT environment.
- Terminated sessions: All remote engineering access must terminate in the IDMZ using an intermediate jump host, protected by multi-factor authentication (MFA) that can function deterministically or degrade safely during wide-area network (WAN) outages.
- Strict protocol breaks: Operational protocols (Modbus, EtherNet/IP, DNP3, OPC DA) must never traverse the IDMZ boundary. Only secure, application-layer proxies and brokers should be permitted to exchange payloads across the boundary.
2. Edge-Brokered Telemetry via Unified Namespace (UNS)
Legacy architectures relied on cyclic polling and point-to-point data pipelines. An enterprise analytics platform querying an OT historian directly creates unnecessary load on Level 3 systems and introduces attack vectors into the control network. A more robust pattern is the Unified Namespace (UNS), underpinned by an edge-brokered publish-subscribe (Pub/Sub) model using protocols such as MQTT Sparkplug B.
In this pattern, an industrial edge device sits within Level 3, interfaces locally with field controllers, contextualises the operational data (adding engineering units, scaling, and quality tags), and initiates an outbound-only connection to an IDMZ-resident broker. The enterprise platform then consumes this contextualised data from the broker rather than interrogating the field devices.
- Outbound-only transport: Control network firewalls only permit outbound stateful TCP sessions initiated from Level 3 into the IDMZ, blocking all inbound connection requests.
- Decoupled consumers: New IT analytics tools, machine learning pipelines, or maintenance platforms can be introduced at Level 4 without altering or testing field controller workloads.
- Payload contextualisation: Data is structured at the source, preventing the creation of data swamps in corporate cloud environments where industrial context is lost.
3. Micro-Segmentation and Zero-Trust Cell Architecture
Treating the entire OT network as a single trusted zone is an operational failure mode. If an adversary or a misconfigured asset breaches the boundary, flat networks allow lateral movement across safety instrumented systems (SIS), programmable logic controllers (PLCs), and human-machine interfaces (HMIs). High-availability industrial architectures rely on micro-segmentation aligned with IEC 62443 “Zones and Conduits.”
Each physical process unit—such as a flotation circuit, a compressor train, or an automated stacker—should form an independent security zone. Communication between these operational cells must be restricted via industrial firewalls enforcing deterministic communication profiles.
- Safety System Isolation: Safety Instrumented Systems (Level 1) must remain segregated from basic process control systems (BPCS), with read-only conduits permitted only under strict architectural justification.
- Intra-zone confinement: Peer-to-peer communications between devices in different functional areas are denied by default, limiting the operational blast radius of any individual hardware failure or malicious intrusion.
- Hardware-enforced inspection: Conduits should utilise deep packet inspection (DPI) capable of validating industrial protocol commands, ensuring that write-commands cannot be injected into read-only operational telemetry streams.
4. Survivable Edge Autonomy Over Cloud Dependency
Cloud connectivity brings powerful operational modelling and fleet-wide visibility, but Australian industrial sites frequently operate in high-latency, intermittently connected environments. Under no circumstances should closed-loop control or critical operational decisions depend on cloud availability.
The architecture must enforce survivable local autonomy. Control loops, alarm processing, interlocks, and critical operator interfaces must run on deterministic, local hardware at Levels 1 and 2. Edge gateways should implement store-and-forward mechanisms that retain high-resolution operational data locally during upstream link dropouts and backfill enterprise repositories automatically upon link restoration, preserving data integrity without compromising site safety.
Building Resilient Convergence
Successful OT/IT convergence is not achieved by applying standard corporate networking principles to industrial operations, nor is it achieved by isolating operations behind an unworkable air-gap. It requires deliberate engineering that respects operational determinism, regulatory requirements like the SOCI Act, and international benchmarks such as IEC 62443.
By establishing rigorous IDMZ boundaries, adopting edge-brokered communication models, and strictly enforcing cell-level micro-segmentation, asset owners can unlock enterprise data value without compromising process safety or asset availability.
Explore our industrial network and systems integration services to review our technical capabilities, or speak directly with our engineering team via our contact page to discuss your site architecture.
