# What is IT/OT Convergence?

> IT/OT convergence is the increasing integration of information technology with operational technology systems, data, processes, and teams.

- Canonical URL: https://yellowcube.eu/glossary/information-technology-and-operational-technology-convergence/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It can connect production, logistics, maintenance, engineering, analytics, and business applications so information moves between environments that were previously managed separately. Convergence may improve visibility and efficiency, but it also creates dependencies and attack paths that can carry an IT incident into processes with physical, safety, or availability consequences.

Convergence is not merely installing a network connection. It requires a defined business purpose, mapped data flows, joint governance, and an architecture that respects the different timing, reliability, lifecycle, and safety needs of OT. The secure design may exchange selected data through controlled services without allowing general-purpose enterprise access to control devices.

### Key points

- **Start with purpose and inventory:** Identify the operational outcome, affected assets, owners, trust boundaries, data direction, latency requirements, and consequences if the exchange is lost or manipulated.
- **Govern jointly:** Give IT, OT, engineering, safety, cybersecurity, and business owners clear decision rights for architecture, identity, changes, monitoring, incidents, and recovery.
- **Control the pathways:** Use segmentation, an industrial DMZ, brokers or proxies, least privilege, and explicit allowlists; prevent unnecessary direct routes between enterprise and control functions.
- **Operate for both environments:** Coordinate maintenance, vulnerability treatment, logging, time synchronization, backup, restoration, and incident actions with the plant or process state.
- **Important limitation:** Shared tools and connectivity do not erase OT’s safety and availability constraints. An IT-standard patch, scan, authentication change, or automated containment action can disrupt a physical process if it is not tested and coordinated.

### Related terms

[Operational technology (OT) security](<https://yellowcube.eu/glossary/operational-technology-security/>) · [Network segmentation](<https://yellowcube.eu/glossary/network-segmentation/>) · [Industrial demilitarized zone (IDMZ)](<https://yellowcube.eu/glossary/industrial-demilitarized-zone/>) · [Secure remote access](<https://yellowcube.eu/glossary/secure-remote-access/>) · [Industrial control system (ICS)](<https://yellowcube.eu/glossary/industrial-control-system/>)

### Sources

[NIST SP 800-82 Rev. 3: Guide to Operational Technology Security](https://csrc.nist.gov/pubs/sp/800/82/r3/final) · [NSTAC Report to the President on IT/OT Convergence](https://www.cisa.gov/sites/default/files/publications/NSTAC%20IT-OT%20Convergence%20Report%20%288-23-2022%29.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

