First, What Is 'Identity Management'?
At its core, Identity and Access Management (IAM) is about making sure the right people can access the right things at the right time—and keeping the wrong people out. Think of it as the digital bouncer for a company's systems. In an office setting, this
means ensuring an accountant can access financial software but not engineering blueprints. For critical infrastructure, the stakes are exponentially higher. Here, IAM determines who can open a floodgate, reroute electricity, or change the chemical mixture in a water supply. Getting it wrong isn't just an IT headache; it's a public safety crisis waiting to happen.
The Two Tribes of Infrastructure Security
The disagreement among engineers isn't about the goal, but the philosophy. It boils down to a fundamental culture clash between two worlds: Information Technology (IT) and Operational Technology (OT). The IT security team, who manage corporate networks and data, live by modern security dogmas like Zero Trust—trust no one, verify everything, and patch systems constantly. Their world is digital, and their priority is protecting data. The OT engineers, who manage the physical machinery, have a completely different mantra: Do no harm. Their world is one of physical consequence, where a system reboot isn’t a minor inconvenience but a potential city-wide blackout. Their priority is safety, reliability, and keeping the lights on, literally. A security measure that could interfere with a physical process is seen as a greater risk than the threat it’s meant to stop.
The Battle Over Old vs. New
This philosophical divide plays out in heated debates over technology. The IT camp advocates for blanketing critical systems with the latest security tools, often centralized and cloud-based, arguing that the threat from sophisticated hackers demands it. They see the isolated, aging systems of the OT world as a massive, unacceptable risk. The OT camp pushes back, pointing out that their world is different. You can't just install a modern security agent on a 30-year-old controller running a hydroelectric dam. Many of these systems were designed before the internet became a threat, built for decades of isolated service. For OT engineers, the IT approach feels like performing open-heart surgery with a toolset designed for fixing a smartphone. They argue for slower, more cautious integration and for security solutions tested and proven not to disrupt fragile, real-time operations.
So, What's the 'Real' Reason?
The real reason for the disagreement is not technical, but cultural and practical. It’s a collision of priorities. The IT security world is built on agility and constant updates to fight a fast-evolving digital threat. The OT world is built on stability and predictability to ensure the safe, continuous operation of physical machinery. Neither side is wrong. The IT team is correct that air-gapped systems are largely a myth today and that OT is a prime target for attackers. The OT team is correct that a security tool causing a power grid failure is a catastrophic own-goal. The friction comes from trying to apply one culture's solutions to the other's unique problems without a deep understanding of the trade-offs. It's the messy, unavoidable reality of protecting 21st-century threats on 20th-century infrastructure.











