When IT Manages OT

IT och OT pratar olika språk - Så lyckas ni med konvergensen

TL;DR

Conclusion

Successful integration is more about trust and clear processes than just network cables.

The challenge

IT and OT have different priorities; IT focuses on data security and confidentiality, while OT prioritises real-time operations and availability.

The solution

A clear boundary definition and a shared governance model that respects both disciplines’ needs.

The effect

A secure and stable environment where control systems are protected by IT standards without risking the operation of the facility.

Organisation, Competence and Responsibility in Tomorrow’s OT Environments

As automation systems become IP-based, it is not only the technical architecture that changes, but also the organisation’s allocation of responsibility. BMS systems increasingly use the same networks, the same security mechanisms and the same infrastructure as enterprise IT. The IT organisation thus becomes a direct prerequisite for building automation to function – regardless of whether this is formally stated or not.

This is fundamentally a management and governance question, not a technical detail.

From Enterprise IT to a Shared Platform

Traditionally, the IT department’s remit has been clearly tied to enterprise IT: users, clients, servers, applications and networks for office and business systems. Building automation and BMS have often been managed by facility management, operations teams or external suppliers, with their own systems and working methods.

When BMS becomes IP-based, this boundary is erased. The IT infrastructure becomes the shared platform for OT systems as well. This means decisions about networks, addressing, security and changes directly affect the building’s function. In practice, IT is already involved in OT operations – even if the organisation is not always structured for it.

Different Logics – IT and OT Have Different Prerequisites

A fundamental challenge is that IT and OT have historically been governed by different logics.

IT environments are often characterised by: frequent updates, standardised platforms, acceptance of planned outages, and focus on security updates and lifecycle management.

OT environments, by contrast, are characterised by: long lifespans, high requirements for continuous operation, limited tolerance for change, and systems directly linked to physical function.

When these perspectives meet without adaptation, friction arises. Operational disruptions, ambiguous decisions and gaps in responsibility are often organisational problems rather than technical ones.

Patching and Change – An Organisational Key Issue

One of the clearest areas where IT and OT logic differ is patching and change management. In IT, regular patching is a natural part of security work. In OT, the same update can mean risk of downtime, unforeseen side effects or compatibility problems. An outage in a BMS system affects not only IT functions, but also comfort, energy consumption and sometimes safety functions in the building.

When OT systems are on the same network and managed through the same processes as IT, adapted procedures are therefore required:

  • Separate change windows for OT
  • Requirements for testing before updates
  • Clear coordination with OT managers before changes to infrastructure

This is fundamentally a management and governance question, not a technical detail.

Competence – Mutual Understanding Rather Than Dual Expertise

A common mistake is trying to create roles that must fully master both deep IT competence and deep OT competence. In practice this is difficult to maintain and often leads to dependencies on individuals. A more sustainable strategy is to build mutual understanding:

  • IT needs to understand OT systems’ requirements for stability, lifespan and consequences of outages
  • OT needs to understand IP networks, addressing, certificates, segmentation and security principles
  • Specialist competence remains within each area, but with clear interfaces for collaboration

Organisational Models That Work in Practice

Organisations that succeed with IT/OT convergence often have a clear allocation of responsibility. IT is responsible for the platform: network infrastructure, IP addressing, DNS and DHCP, basic cybersecurity, certificate management and segmentation. OT is responsible for the systems: BMS function and logic, availability and performance requirements, validation of changes from an operations perspective. Shared responsibility covers: change management, incident management, documentation and lifecycle management.

The decisive factor is not exactly how the organisation is structured, but that responsibilities and decision paths are clear.

Common Mistakes

  • Moving OT to IT without changing working methods – IT applies existing processes without regard for OT systems’ operational reliability requirements
  • Unclear responsibility between IT and OT – Nobody owns the whole picture, leading to decision gaps and delays
  • Changes implemented without OT alignment – Technically correct changes have unwanted operational consequences
  • Overconfidence in hybrid roles – Individuals are expected to cover the entire competence spectrum without organisational support
  • Treating IT/OT convergence as a technology project – Organisational questions, training and governance are deprioritised

Who bears responsibility when the building goes digital?

When the IT department gets responsibility for the building’s OT environment, new challenges arise around security, lifecycles and operational responsibility. We help you define the processes and requirements that make the handover and daily management a success rather than a source of conflict.

author avatar
David Nordin

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Contact us