Connecting OT and IT: Integration Patterns Without Production Risk


Cover image: OT-IT integration via edge gateways without interfering with the control system

A shift supervisor wants to view machine data on the office network. The IT security officer does not want to connect production control systems to the Internet. Both are right, and this is precisely where the real challenge of OT-IT integration lies.

In a nutshell

Edge Gateways translate legacy field protocols such as Profibus or Modbus into OPC UA or MQTT and at the same time separate the production network from IT. The Purdue reference model serves as the framework for OT-IT integration and IEC 62443 as the security standard, both from the start of the project. External wireless sensors do not touch the control system at all and can be fitted during ongoing operation.

The Framework: The Purdue Model and Zone Separation

The Purdue Reference Model has become the standard framework for this separation; it divides production networks into layers ranging from the field level to enterprise IT and remains one of the most widely used approaches to network segmentation to this day (Acronis, 2025). The model is older than many of today's IIoT architectures, but it remains a useful conceptual framework when it comes to determining who is allowed to communicate with whom and who is not.

Why Integrating OT and IT in Existing Facilities Is More Difficult Than Expected

Common Challenges in Established Systems and Their Solutions, according to allaboutautomation 08/2026
Hurdle How it manifests itself Approach to a Solution
Heterogeneous Control Systems Several generations of PLCs side by side Edge Gateway as a Translator
Legacy protocols Profibus, Modbus, proprietary formats, no OPC UA Normalization to OPC UA or MQTT
Lack of Segmentation Production network and office network are not separated Zones according to Purdue, rules according to IEC 62443
Old Windows PCs on machines No more updates available a separate, strictly isolated zone
No changes to the PLC are desired Warranty, Approval, Operational Risk External wireless sensors on the housing

In established businesses, integration rarely takes place in a uniform environment (allaboutautomation, 08/2026). Each control system uses its own language, developed at a time when no one had considered the possibility of later integration with higher-level systems.

In this situation, edge gateways act as translators. They normalize the various legacy protocols into common standards while also handling the segmentation between the production network and the higher-level IT infrastructure. For the machine itself, little changes—it continues to send its data as usual. It is only at the gateway that the data is converted into a format that modern analytics systems can understand.

Consider the security of OT-IT integration from the very beginning

A retrofit project that does not consider security until after the rollout ends up having to correct issues later—at significantly greater cost—that could have been planned for from the very beginning. The IEC 62443 standard for the security of industrial automation systems should therefore be part of project planning from the very beginning, not an after-the-fact verification step (allaboutautomation, 08/2026). This applies to issues such as zone separation, access rights to gateways, and the question of which data is even permitted to leave the production network.

A practical advantage of modern retrofit sensor technology is that it can often be installed entirely outside the existing control system. External wireless sensors do not interfere with the PLC and can be installed while the system is running (allaboutautomation, 08/2026). These sensors transmit their data directly to a gateway via their own network, bypassing the actual control level. This significantly reduces the risk to production safety because, in the worst-case scenario, only the sensor system would be affected—not the machine itself. For details on what such a setup looks like in practice, see the article on Retrofits for Existing Systems.

A step-by-step approach instead of a big leap

An OT-IT integration that connects the entire plant at once is rarely the fastest way to achieve the goal. It makes more sense to start with a single line or a single machine type, where the gateway, network segmentation, and security concept must prove themselves in practice. Errors in gateway configuration become apparent quickly in this setting and can be corrected without immediately affecting the entire production process.

This first step also reveals just how resilient the existing network infrastructure actually is. Some facilities have a stable Industrial Ethernet network, while others haven’t had a network upgrade in years. These differences are best assessed in a manageable pilot area before making major investments in cabling or wireless infrastructure.

After the pilot, it’s worth conducting a brief evaluation before moving on to the next phase. How many false alarms occurred, how stable was the gateway’s performance, and how well did OT and IT actually work together? These findings are directly incorporated into the next rollout phase.

The organizational side is often underestimated

The technical solution is rarely the biggest obstacle. Organization is often the greater challenge. OT and IT must jointly take responsibility for such a project, with clear areas of responsibility for the network, security, and data analysis (allaboutautomation, 08/2026). In many companies, the two departments report to different supervisors, each with different priorities and budgets. A gateway project driven solely by IT can easily overlook the operational realities of production. A project initiated solely by production often underestimates IT’s security requirements.

When Integration Isn't Worth ItWhen a machine remains isolated and its data never needs to leave the production network, the effort required for integration often outweighs the benefits. Before starting any project, it’s therefore worth asking who really needs this data and where. If you skip this step, you’ll end up building an infrastructure for data that no one ever looks at on a regular basis.

Designate a Pilot Area for IntegrationWe examine control generations, networks, and security requirements, and propose the area where the concept will prove its worth the fastest.

Discuss the pilot

Frequently Asked Questions

Does production have to be halted to integrate with OT and IT?

In most cases, no. External wireless sensors and edge gateways can often be installed during normal operation without interfering with the existing control system. A scheduled maintenance shutdown can make installation even easier, but it is rarely necessary.

What happens to old Windows PCs on machines?

Older, unmaintained computers used in machine control systems are a well-known security risk and should be handled with special care in network segmentation. They are often kept in their own, strictly isolated zone, while the actual data processing takes place via a separate gateway that does not require direct access to these systems.

Who is ultimately responsible for the security of the integration?

Ideally, this should be a shared responsibility between OT and IT, with clearly documented boundaries for gateway operation, network segmentation, and access rights. Without this clarification, security vulnerabilities often go undetected because both sides rely on the other.

The Next Step

Based on our own experience, torck supports OT-IT integration projects in established facilities—from the selection of edge gateways to integration with our own plant monitoring system. Our teams in Maxhütte-Haidhof, Vienna, and Rabat develop the software for industry and retail in-house and are familiar with issues related to network segmentation and responsibilities from our own projects. On our page for Plant Monitoring you can book an appointment.

Questions about this post?

Just a couple of sentences about your situation will suffice. The person responding builds these kinds of systems himself.

We'll respond within one business day.torck · code with torque
Florian Blischke
Managing Director of torck GmbH · Over 20 years of software development experience
Florian Blischke is the managing director of torck GmbH and has been working in software development for over 20 years. He is responsible for custom software solutions for industry and retail, ranging from the integration of physical processes and IoT to cloud architecture and data- and AI-driven systems. At torck, he oversees, among other projects, the Jouvoli energy platform and the KVM Fleet fleet management product. torck develops software at its locations in Maxhütte-Haidhof, Vienna, and Rabat, and places a strong emphasis on software that actually works in real-world operations.

Are you facing the same question?

We’ve been building software for industry and retail since 2017, based in Maxhütte-Haidhof, with teams in Vienna and Rabat. An initial consultation lasts 30 minutes and is free of charge. Afterward, you’ll know whether the project is worth pursuing—even if the answer is no.

More Articles

AI Funding Programs in Germany and Austria in 2026

AI Funding Programs in 2026 in Germany and Austria

Germany and Austria will fund AI projects in 2026 through several programs with varying funding rates and maximum grant amounts. This article categorizes the Research Grant, ZIM, KMU-innovativ, FFG, and aws programs and outlines the technical requirements for submitting an application.

Read more »