IT-OT convergence has been a stated priority for industrial organisations for more than a decade. Progress has been slower than the technology would suggest it should be. The hardware and software to connect OT systems to enterprise networks exists, works reliably, and is widely deployed. The obstacle is not technical interoperability — it is human and organisational interoperability.
IT departments and OT engineering teams have fundamentally different definitions of success, different risk appetites, and different accountability structures. IT measures performance against security metrics, patch compliance rates, and uptime of business systems. OT measures performance against production throughput, process stability, and equipment availability. When a proposed network integration requires taking a production system offline for a change window, these two cultures collide directly — and in most organisations, OT wins, because a production stoppage has an immediate, visible cost, while a security gap has a deferred, uncertain one.
What is changing this dynamic is not technology — it is regulation and AI. NIS2 places cybersecurity obligations on industrial operators that cannot be met with OT and IT teams operating in silos. And the AI capabilities that manufacturing and energy companies want to deploy — predictive maintenance, autonomous optimisation, real-time analytics — require seamless data access to OT systems that isolated network architectures cannot provide.
The Cultural Divide: How Each Team Sees the World
This is not a failure of either team. OT's caution is rational: an unexpected system interruption on a production line can cost €100,000–€150,000 per hour in lost output, plus the safety implications of an uncontrolled process state change. IT's urgency around patching is also rational: unpatched systems with known vulnerabilities are exposed. The problem is that neither team has the mandate, the authority, or the language to resolve the conflict at the level where it actually occurs — in the decisions about individual change requests, firewall rules, and network integrations.
The Three Root Causes of Stalled Convergence
1. No Shared Governance
In most organisations, IT security reports to the CISO. OT engineering reports to the Head of Operations or Plant Manager. These two reporting lines converge at the CEO or COO level — and that is where conflicts escalate to when they cannot be resolved lower. The result: security decisions that should take days take months, because every disagreement requires escalation to leadership level. The absence of a shared governance forum — with representatives from both IT and OT, empowered to make binding decisions on convergence issues — is the most common root cause of stalled programmes.
2. Fragmented Vendor Ecosystem
The automation vendors who supply DCS, PLC, and SCADA systems to OT teams have historically competed on capability, not interoperability. Each vendor's proprietary historian, proprietary protocols, and proprietary configuration tools create data silos that make IT-OT data integration a custom engineering project for every connection. The landscape is improving — OPC-UA is becoming a common standard, and cloud connectivity is now a standard feature of most modern platforms — but the installed base of legacy systems still speaks proprietary languages that require vendor-specific adapters.
3. Legacy Infrastructure with No Upgrade Path
A PLC installed in 2005 to control a critical process will run for twenty to thirty years if the plant allows it. It was not designed for network connectivity, does not support modern authentication, and cannot be patched without a software upgrade that may require a full production line validation. The asset simply does not fit the IT change cadence. Meanwhile, the IT team sees an unmanaged device on a connected network and flags it as a risk. Both assessments are correct — and the resolution requires a risk-based approach that acknowledges the operational constraints.
The technology required for IT-OT convergence largely exists. The capability gap is governance: shared ownership of decisions, shared metrics for success, and a common risk framework that both IT and OT teams can work within.
Legislation as the Ultimate Catalyst
While culture is slow to change, legal liability is not. NIS2 creates a non-negotiable driver for IT-OT convergence by holding management bodies personally accountable for cybersecurity outcomes across the entire operational environment — including OT systems that IT teams have previously had no visibility into.
When the CISO's NIS2 gap assessment reveals that critical OT systems are unmonitored, unpatched, and running with shared vendor credentials, the response is no longer "OT will handle it." The directive makes both IT security and OT operations jointly accountable to the same regulatory framework. This forces the governance conversation that organisations have been deferring.
| Convergence Driver | What It Forces | Why It Works Now |
|---|---|---|
| NIS2 Directive | Joint IT/OT accountability for cybersecurity compliance; management liability | Legal and financial consequences that override cultural hesitancy |
| AI and Predictive Analytics | OT data must be accessible to enterprise AI systems for predictive maintenance, optimisation | Business case is now compelling and measurable |
| Energy Cost Pressure | Energy optimisation AI requires real-time OT data access to production systems | 10–15% energy cost reduction justifies the integration investment |
| Vendor Modernisation | New OT platform releases (ABB 800xA 7.0, Siemens PCS neo, Emerson DeltaV v16) include native IT connectivity | New deployments can connect securely without custom adapters |
AI: The New Driver — and the New Risk
The emergence of AI as a core operational capability is creating a new kind of urgency around IT-OT convergence. Predictive maintenance AI that can reduce unplanned downtime by 20–40% depends on access to OT historian data. Energy optimisation algorithms that can cut energy cost by 10–15% depend on real-time visibility into production load and equipment state. Quality control AI that detects early signs of process deviation depends on SCADA data.
All of these capabilities require the OT network to be accessible — to data pipelines, to analytics platforms, and ultimately to AI agents that will act on what they learn. An organisation that keeps OT isolated cannot deploy industrial AI at scale. Convergence is no longer optional for companies that want to compete on operational efficiency.
The risk dimension is equally real. As AI becomes embedded in critical infrastructure — managing energy systems, optimising production, and providing situational awareness to operators — the OT systems that AI depends on become high-value targets. Disrupting the data pipelines that feed an AI-managed energy grid is a new class of attack. Securing the IT-OT integration is as important as building it.
Overcoming the Divide: Practical Steps
Start with the Pitch, Not the Network
Convergence programmes that lead with IT security requirements typically meet resistance from OT teams who see the initiative as IT imposing constraints on operations. Programmes that lead with an OT-valued business case — "this integration enables predictive maintenance that reduces your unplanned downtime" — create an ally in the OT team rather than an adversary. The same technical work is required in either case; the framing determines whether OT engineering is a partner or an obstacle.
Prove It in a Lab Before the Plant
OT teams are risk-averse because the cost of a production mistake is high. Allowing them to test IT-OT integrations in an off-site lab or digital twin environment — with their own engineers in control of the testing — builds the trust necessary for production deployment. One vendor who does this well is ABB, whose customer demonstration centres allow operators to test new integrations on representative process configurations before committing to their live system.
Establish Shared Governance with Joint KPIs
The most effective convergence programmes create a joint IT-OT governance forum — typically chaired by the Head of Operations or a newly created role (OT Security Manager, Digital Operations Director) — with representation from both teams and the authority to make binding decisions on integration requests. This forum measures itself against shared KPIs:
- Time to resolve IT-OT integration requests (target: days, not months)
- OT security incident rate (shared with IT Security)
- AI-enabled savings from converged data access (business case for convergence investment)
- NIS2 compliance posture (shared regulatory obligation)
Simplify the First Integration
The first IT-OT integration in an organisation should not be the most ambitious one. A read-only data connection from the OT historian to an enterprise analytics platform — requiring no changes to the OT control system, no new devices in the OT network, and no modification of control logic — demonstrates the value of integration with minimal risk. Use the first success to build momentum and trust before proposing integrations that require deeper OT network access.
The Future Is Integrated
The industrial companies that will lead in the next decade — in manufacturing efficiency, in energy performance, in operational resilience — will be those that have successfully integrated IT and OT into a coherent operational architecture. NIS2 removes the option of continued separation. AI makes integration economically compelling. The question is not whether IT-OT convergence will happen, but whether it will be designed deliberately or forced by circumstances.
The organisations that succeed will be those that treat convergence as a governance programme first and a technology programme second — starting with shared ownership, shared metrics, and a joint forum empowered to make decisions. The technical work follows; the human and organisational work is the harder part, and it has to come first.