Who Is on the Wire? Identity Architecture Across the IT/OT Boundary

Most recent intrusions into industrial operations walked in through an identity nobody was managing, not a novel exploit. This practitioner feature article explains why identity behaves differently in operational technology (OT), where it breaks between enterprise IT and industrial control systems, and five vendor-neutral architecture patterns operators can apply: 1. Separate IT and OT identity domains, joined only through a broker in the IT/OT DMZ.2. Strong authentication at a single brokered entry point, with just-in-time, vaulted and recorded privilege inside the plant.3. Operator consoles designed for shifts, separating monitoring from actions that change the process.4. Certificate identities for devices, with authenticating gateways for legacy controllers.5. A pre-planned, drilled break-glass path for emergencies. The patterns are grounded in ISA/IEC 62443-3-3 (FR 1, identification and authentication control; FR 2, use control) and the April 2026 joint U.S. federal guide "Adapting Zero Trust Principles to Operational Technology," with the 2021 Colonial Pipeline incident and CISA advisory AA23-335A as case examples. The article includes one original reference-architecture figure and an identity-class summary table (1,861 words). Prepared as a feature article for ISA InTech.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-03
DOI
https://doi.org/10.5281/zenodo.23113199
Primary Topic
Smart Grid Security and Resilience
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
preprint

Who Is on the Wire? Identity Architecture Across the IT/OT Boundary

Olatunji Adeyanju, Abidemi M. Orimogunje, Friday Ogochukwu Ikwuogu
Zenodo (CERN European Organization for Nuclear Research)
Smart Grid Security and Resilience
preprint

Who Is on the Wire? Identity Architecture Across the IT/OT Boundary

Olatunji Adeyanju, Abidemi M. Orimogunje, Friday Ogochukwu Ikwuogu
preprint en

Abstract

Most recent intrusions into industrial operations walked in through an identity nobody was managing, not a novel exploit. This practitioner feature article explains why identity behaves differently in operational technology (OT), where it breaks between enterprise IT and industrial control systems, and five vendor-neutral architecture patterns operators can apply: 1. Separate IT and OT identity domains, joined only through a broker in the IT/OT DMZ.2. Strong authentication at a single brokered entry point, with just-in-time, vaulted and recorded privilege inside the plant.3. Operator consoles designed for shifts, separating monitoring from actions that change the process.4. Certificate identities for devices, with authenticating gateways for legacy controllers.5. A pre-planned, drilled break-glass path for emergencies. The patterns are grounded in ISA/IEC 62443-3-3 (FR 1, identification and authentication control; FR 2, use control) and the April 2026 joint U.S. federal guide "Adapting Zero Trust Principles to Operational Technology," with the 2021 Colonial Pipeline incident and CISA advisory AA23-335A as case examples. The article includes one original reference-architecture figure and an identity-class summary table (1,861 words). Prepared as a feature article for ISA InTech.

Zenodo (CERN European Organization for Nuclear Research)
Texas Tech University (US), Redeemer University (CA), Redeemer's University (NG)
Smart Grid Security and Resilience
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Who Is on the Wire? Identity Architecture Across the IT/OT Boundary — Olatunji Adeyanju, Abidemi M. Orimogunje, et al. · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS