Operational technology (OT) and information technology (IT) have historically lived in separate identity worlds. IT networks authenticate humans and services through directory services, password managers, and API gateways. OT networks rely on network segmentation, physical controls, and proprietary protocols. Their identity models barely intersect.

This separation is no longer tenable. As critical infrastructure systems—power grids, water treatment, manufacturing—become increasingly digitized and networked, they host autonomous agents and monitoring systems that must operate across both OT and IT boundaries. A supply-chain optimization agent, for example, may consume IT data (ERP systems, inventory databases) and issue commands to OT systems (manufacturing equipment, logistics). Its identity must be verified in both worlds.

The convergence creates unique challenges. OT networks often use protocols—Modbus, Profibus, industrial Ethernet—that lack native identity constructs. Industrial equipment typically has fixed credentials hardcoded at manufacturing time. OT systems prioritize availability over the frequent authentication checks IT systems rely on. OT networks operate air-gapped or with minimal external connectivity, making centralized identity services infeasible.

Yet the security imperative is urgent. Industrial control systems are increasingly targeted by nation-states and ransomware operators. If an OT device’s identity can be spoofed—if an attacker can impersonate a legitimate sensor, actuator, or control system—the consequences can be physical: plant shutdowns, safety incidents, contamination.

Federal agencies managing critical infrastructure are recognizing this. The Department of Energy and CISA have begun issuing guidance on machine identity for industrial systems. NIST frameworks increasingly include OT identity as a baseline control.

The technical solution involves extending IT identity patterns into OT networks. This means retrofitting OT equipment with certificates or other cryptographic identity, implementing identity-based microsegmentation in OT networks, and building agent-aware monitoring for cross-domain transactions.

The vendor ecosystem is responding. Companies that have historically served either IT or OT are now building unified machine identity platforms. This is complex because OT equipment spans decades of design iterations and is often updated infrequently for safety and stability reasons.

Convergence also requires new thinking about identity lifecycle. An OT device might be in service for 20 years. Its certificate lifetime must span that period or employ automatic renewal without downtime. An agent that controls critical systems must have not just cryptographic identity but verifiable provenance—proof of where it came from, who authorized it, and what it is supposed to do.

Organizations operating both OT and IT networks cannot treat machine identity as two separate problems. Those that achieve convergence—unified identity frameworks spanning both worlds—will dramatically improve their resilience to compromise.