IT/OT Integration: A Practical Plant Guide

A plain-English guide to IT/OT integration for plant teams, with real cases, common failure modes, and a practical 90-day pilot plan.

Two plant professionals walking between industrial equipment, a control panel, and an operator workstation

When a supervisor asks why a line stopped, the answer may be split across a control screen, a historian trend, a maintenance note, a manufacturing execution system (MES) order, and an enterprise resource planning (ERP) record. Every record can be correct. The work still slows down because nobody owns the sentence that connects them. That gap is what people usually mean by IT/OT integration. It does not put every system on one network or replace the plant’s controls. It gives IT and OT a bounded way to share the context needed for one plant decision.

The distinction matters because OT touches the physical world. NIST defines OT as programmable systems and devices that monitor or control physical processes, while ISA-95 maps the boundary between manufacturing operations and business planning. NIST OT guidance ISA-95 model This article is for operators, supervisors, maintenance leads, quality staff, and plant managers who do not need another architecture diagram. For deeper SCADA, historian, MES, and ERP mapping, see Why plant systems never talk. That article maps system layers; this one stays with people and decisions.

IT and OT are different jobs in the same plant

IT is the part of the business that stores, moves, protects, and presents information. In a plant, that can include identity services, business applications, databases, reporting, backups, and the enterprise planning system. OT is the part that senses, supervises, or changes the physical process: instruments, programmable logic controllers (PLCs), distributed control systems (DCS), supervisory control and data acquisition (SCADA), drives, safety systems, and the networks that keep those systems operating. NIST uses the physical interaction as the boundary, not the vendor label. NIST OT guidance

ISA-95 gives plant teams a useful map without pretending that every product fits one box. Its model describes physical production at level 0, sensing and actuation at level 1, monitoring and control at level 2, manufacturing operations management at level 3, and business planning and logistics at level 4. The standard puts MES and SCADA examples in level 3 and ERP in level 4, then focuses on the interface between those levels. ISA-95 model That is why the phrase “IT versus OT” is too blunt for daily work. The boundary is logical, and some systems sit near it.

Plant question IT usually owns the answer OT usually owns the answer
Which order should be planned or posted? ERP, planning, finance, identity The order’s effect on the running process
What is the asset doing now? A data service or report may display it The controller, SCADA view, or local instrument
What happened during the run? Storage, analytics, backup, and access Tag values, events, alarms, batches, and operator actions
Who may change the record or setting? Account, role, and audit controls Process authority, change control, and safe operating limits

The two sides also work on different clocks. OT often has to keep a process deterministic and available; IT often optimizes for throughput, maintainability, and broad access. NIST’s OT guidance says security measures have to address performance, reliability, and safety requirements, so a useful data feed cannot be allowed to disturb control timing. NIST OT guidance A delayed production report is inconvenient. A delayed interlock or an unavailable controller can be a safety event.

That does not make one side more important. It means each side needs a different approval test. IT asks whether the service is authenticated, recoverable, and supportable. OT asks whether the process meaning is correct, the timing is acceptable, and the change can be reversed without an unsafe state. An integration is working only when both answers are yes. ISA describes ISA-95 as a way for manufacturing and IT personnel to agree terms and interfaces before they build them. ISA-95 model

Why the two worlds were kept apart

The separation began as a sensible operating choice. Early control systems were built for specific machines and processes, often with proprietary hardware and protocols, and many ran on isolated networks. Office systems were built for people, documents, transactions, and a changing set of applications. NIST explains that OT systems initially had little resemblance to IT because they were isolated and used specialized hardware and proprietary protocols. As Ethernet, IP, and wireless devices moved into plants, connectivity increased along with exposure to cyber threats. NIST OT guidance

The buying cycle reinforced the split. A control system could be validated with a line and left in place for years, while ERP, historian, and MES projects arrived through different budgets. Each solved a local need and left its own names, timestamps, accounts, and change process. NIST’s smart-manufacturing standards report says disparate systems need information standards to exchange, understand, and use product, production, and business data. Being in the same building does not create that shared meaning. NIST standards landscape

ISA-95 was created for this exact boundary. ISA says the framework provides an abstract model for information exchange between manufacturing control functions and business functions, and helps manufacturing and IT personnel collaborate by defining common terms. It is a map of activities and objects, not a requirement to buy a particular vendor’s platform. ISA-95 model Agree what an order, a batch, a material, an asset, and a confirmation mean before arguing about connectors.

The priorities also grew apart. OT teams were judged on safe, stable production. IT teams were judged on service availability, data protection, access, and recoverability. NIST describes OT security as a balance of performance, reliability, and safety, with countermeasures that fit the system’s role. NIST OT guidance A control engineer may reject a query that can load a controller. An IT owner may reject an untracked file share that bypasses identity controls. Both objections are reasonable. The weak workaround is for operators to carry a USB drive or maintain a spreadsheet that nobody formally owns.

The world changed when plants needed remote support, production traceability, energy reporting, and analytics across lines. The answer was not to erase the boundary. CISA notes that industrial control environments still contain legacy technologies and protocols that were designed for operation and reliability, not modern cybersecurity. CISA ICS New data paths therefore have to pass through the old operating assumptions: least change, clear ownership, tested recovery, and a route that can be closed.

What the split costs on an ordinary shift

The first cost is not a failed network packet. It is the time spent rebuilding context. One system may call a pump P-204, another may call it P204A, and a third may attach the work to a work-center code. The historian may record values by event or deadband, MES may close a step at a shift boundary, and ERP may post by business date. NIST describes data integration and the connection between data acquisition and decision support as continuing barriers in smart-manufacturing analytics. NIST data analytics

When the records stay separate, a supervisor often sees one of four patterns:

What the plant sees What is missing A safer first repair
A downtime total that nobody can explain A shared asset and time definition One agreed asset ID and one event window
A quality result without the machine state A link between the lot, test, and equipment A read-only traceability join
A maintenance job with no production context The operating mode and recent events A context view with source and timestamp
A dashboard that bypasses the control network A documented security route and owner A segmented export through an approved boundary

These are data problems with operational consequences. A bad join can send a crew to the wrong asset, hide the duration of a hold, or make a change look approved when it was only suggested. Do not let an analytics tool guess. NIST’s operations-driven measurement work emphasizes that manufacturing performance improves through targeted applications and well-defined methods, not through a generic promise that more data will solve every problem. NIST performance measurement

Security is the second cost. If a plant exposes a controller network directly to an office network because a report needs a tag, it has traded a small reporting problem for a larger attack surface. NIST recommends logical separation between corporate and OT networks, including firewalls, unidirectional gateways, or an industrial demilitarized zone (DMZ) where appropriate. CISA also warns that legacy ICS devices and protocols may lack current security functions. NIST OT guidance CISA ICS The boundary is part of the integration design, not a detail to add after the data starts moving.

The third cost is ownership. A feed can run for months until a tag is renamed, a unit changes, or the line is reconfigured. If no OT owner can explain the process meaning and no IT owner can maintain the path, the feed becomes another unofficial system. Use this guide’s rule: agree on owners, data definitions, and the question before choosing technology. MESA lists a Metrics Guidebook and resources about common metrics and shared goals. MESA manufacturing analytics

Ask: “Which decision is delayed because two records cannot be joined, and what is the smallest safe path that would answer it?” That keeps the scope small enough to test.

Two public plants and what their examples show

Read case studies for mechanisms, not promises.

At Siemens’ Electric Motor Factory in Bad Neustadt, Germany, the company describes a high-variant plant that collects OT data from equipment, sensors, controllers, end-of-line tests, and quality assurance in a cloud solution. Interfaces to ERP and MES add production and traceability context, so test results for components can be connected to tests on a finished motor. Siemens presents a reduced-test-effort use case in which historical and current factory data support a rule about whether a particular final test step can be skipped. Siemens Bad Neustadt case

The lesson is the order of the work: collect equipment evidence, attach it to a product or component identity, bring in MES and ERP context, then test one question. Peter Zech, the factory’s Head of Innovation and Digitalization, describes the value of linking OT data to individual motors or components. Siemens Bad Neustadt case This is a Siemens description of its own factory, not an independent performance audit.

At Hindalco Industries’ fiber-reinforced plastic (FRP) plant in Hirakud, India, Siemens describes a different problem: heterogeneous technology, communication protocols, system generations, and original equipment manufacturers (OEMs) made a uniform security concept difficult. Hindalco reference The published reference says the implementation separated IT, OT, and a DMZ with firewalls, connected 22 plant locations with more than 15 kilometers of optical-fiber backbone, and used GPS-backed Network Time Protocol (NTP) to synchronize OT Windows systems and network devices. Hindalco reference The reference records completion in 2023. Hindalco reference It separates the services: a DMZ jump server provides secure remote access; Sinec INS collects logs for the customer’s security information and event management system (SIEM); a continuous threat detection server scans traffic between IT and OT; and a network-management server monitors network devices. Hindalco reference

Hindalco shows that integration can begin with safe traffic and visibility rather than a new production application. The reference records improved operations and security posture as benefits, but provides no independent before-and-after downtime study. Hindalco IT/OT reference

Both cases also show why the SCADA-historian-MES-ERP question needs a boundary. The Bad Neustadt example joins shop-floor evidence to product traceability. The Hindalco example focuses on network zones, time synchronization, and remote access. Neither case says that all systems should become one system of record. ISA-95 keeps the logical roles separate, while NIST asks teams to protect OT performance and safety as they add connectivity. ISA-95 model NIST OT guidance

Choose one connection before you choose a platform

Start with a decision, not a product catalog. A good first question has one asset or line, one time window, one person who needs the answer, and one action that still requires human approval. “Why did Line 2 stop between 14:00 and 14:30?” is testable. “Create a digital twin of the plant” is a program, not a pilot. ISA-95’s level model helps teams name which activity owns each part of the exchange. ISA-95 model

Then write four contracts before anyone builds a feed.

  1. Name the asset, order, batch, material, event, unit, and operating mode. Record aliases instead of silently replacing them.
  2. State whether the window uses controller time, historian time, MES shift time, or ERP posting time. Keep the original timestamp beside any converted one.
  3. Mark which system is allowed to decide each field. A report can suggest that a pump stopped; it cannot approve a work order or change a setpoint.
  4. Draw the permitted path, accounts, ports, logs, and rollback action. For OT data, include the DMZ or gateway decision before testing the payload.

These contracts expose the common failure: a connector that moves a value but does not carry its meaning. NIST’s standards landscape describes the need for systems to exchange, understand, and exploit data, not merely to copy bytes. NIST standards landscape

For a first pilot, prefer a read-only path. Read-only does not mean risk-free, but it prevents a reporting experiment from becoming an accidental control path. NIST’s OT guidance recommends security countermeasures that respect performance, reliability, and safety, and supports separating corporate and OT environments. NIST OT guidance CISA’s coverage of legacy ICS is another reason to test a route with the system owner instead of opening a broad port and hoping the old device behaves. CISA ICS

Choose a platform only after the question, ownership, and route are clear. A point-to-point connector may be enough for one stable transfer. A context service may be justified when several teams need the same asset, order, and time mapping. A replacement project belongs at the end of the diagnosis, when the current system cannot support the object model, approval path, or recovery requirement. Treat governance and aligned goals as this guide’s decision rule, not as a vendor prerequisite. MESA manufacturing analytics

A 90-day pilot that leaves the plant safer

A 90-day pilot should produce a decision packet, not a permanent architecture by accident. Keep the production path unchanged while the team proves whether a narrow, owned data path saves review time and preserves evidence.

Days Work Evidence to keep Stop condition
1-15 Choose one question, asset or line, owner pair, and baseline manual process Scope note, asset list, current screenshots or records, safety contact The question needs control writes or has no process owner
16-30 Agree names, units, timestamps, operating modes, and authority for each field Mapping sheet, time rule, source-of-truth table, acceptance checks The team cannot explain a field or its original timestamp
31-45 Build and test a read-only route in the approved zone or DMZ Firewall rule, account, logs, test payloads, rollback steps The route bypasses segmentation or lacks an accountable maintainer
46-60 Run in shadow mode beside the existing manual review Side-by-side answers, mismatches, missing context, operator notes The feed changes control behavior or creates unexplained discrepancies
61-75 Fix the mapping, document exceptions, and let operators challenge the result Revised mapping, exception register, training note, security review The system hides uncertainty or a reviewer cannot trace a value
76-90 Decide to stop, extend, or scale with a named owner and next boundary Decision record, measured review time, open risks, maintenance plan No owner accepts the path or safety/security sign-off is missing

The baseline should be ordinary. Count how many minutes a reviewer spends finding the records, how many manual joins are needed, how often the answer is returned for clarification, and which fields remain uncertain. Do not promise a universal productivity percentage. NIST’s operations-driven work treats performance measurement as an operations question with defined methods and targeted applications. NIST performance

During shadow mode, keep the existing operator procedure in force. The pilot may display a likely cause, a linked event window, or a traceability path. It should not silently close an order, alter a recipe, suppress an alarm, or issue a maintenance command. NIST’s OT guidance makes the performance, reliability, and safety boundary explicit, and ISA-95 provides a vocabulary for separating manufacturing activities from business transactions. NIST OT guidance ISA-95 model

At day 90, the decision can be “stop.” That is a useful result when the question was rare, the manual reconstruction was easy, or the route introduced more risk than value. Continue only if the answer is faster or easier to review, the mapping has an owner, the security boundary is documented, and operators can see the source and limit of the result. Scaling means adding one new boundary at a time, not turning a successful line pilot into an unowned plant-wide bus.

The pilot should record what it can answer, its limits, field owners, the action approver, and how to close the feed. That gives the next integration a usable starting point.

Frequently asked questions

What is IT/OT integration in a plant?

IT/OT integration is a controlled way to connect information systems with systems that monitor or change the physical process, while keeping ownership and safety boundaries explicit. NIST defines OT by its interaction with the physical environment, and ISA-95 describes the information exchange between manufacturing control functions and business functions. NIST OT guidance ISA-95 model In practice, the first useful connection may be a read-only traceability view or a downtime review, not a replacement for the plant’s control system.

Is OT the same thing as SCADA?

No. OT is the wider category; SCADA is one kind of supervisory system inside the operational technology environment. NIST’s OT definition includes programmable systems and devices that monitor or control the physical world, while ISA-95 lists SCADA among systems that manage manufacturing operations at level 3. NIST OT guidance ISA-95 model A plant can therefore integrate IT with several OT sources without treating SCADA as the owner of every production record.

Why should a plant avoid connecting an ERP system directly to a PLC?

A direct ERP-to-PLC link crosses different timing, safety, and ownership boundaries and can expose a controller to traffic it was not designed to handle. NIST recommends separating corporate and OT networks and tailoring controls to OT performance, reliability, and safety. NIST OT guidance CISA also documents the persistence of legacy ICS technologies and protocols. CISA ICS A mediated, read-only path through an approved zone is easier to review and close than a direct route whose authority is unclear.

What should a 90-day IT/OT pilot measure?

A 90-day pilot should measure whether one named plant question is answered faster and with less manual reconciliation, without changing control behavior or weakening the security boundary. Track the review time, number of manual joins, unresolved fields, mismatches, and the ability to trace each value to its source. NIST’s operations-driven measurement work supports targeted, defined applications rather than a generic claim about more data. NIST performance The pilot should also record a stop decision if the question is too rare or the route creates more risk than value.

Does IT/OT integration require replacing SCADA, MES, or ERP?

No. A first integration can preserve existing systems and add a narrow, owned data path around one decision that the plant can test and roll back. ISA-95 is technology-agnostic and describes activities and interfaces, while NIST’s guidance asks teams to protect OT requirements as they add connectivity. ISA-95 model NIST OT guidance Replacement may eventually be justified if a system cannot carry the needed objects, approvals, timestamps, or recovery controls, but a pilot should prove that need rather than assume it.

Sources