Overview
Industrial networks remain a top priority for zero‑trust planning in 2026. This update revisits the longstanding split between network‑centric segmentation and identity‑first controls in operational technology (OT) environments, adds recent market and regulatory developments, and gives concrete, operational guidance for teams that must balance safety, uptime and modern access paradigms.
Background: what’s changed since mid‑2026
OT constraints—safety prioritization, legacy protocols, deterministic timing, and multi‑stakeholder ownership—still shape how zero trust is applied. What’s different today:
- Device identity at scale: Hardware roots of trust (TPM, DICE, secure elements) are now standard options on many new PLC and edge gateway lines. Vendors now routinely advertise device attestation capabilities that were rare two years ago.
- Protocol maturity: OPC UA over TLS and companion specifications have become the de‑facto secure stack for many greenfield projects and brownfield gateway retrofits, making identity integration easier where it’s supported.
- Regulatory pressure and procurement: Post‑NIS2 enforcement and heightened supply‑chain scrutiny in several jurisdictions have pushed buyers to require demonstrable access controls, ephemeral vendor sessions, and SBOMs for embedded components.
- Operational tooling advances: Lightweight service meshes for cloud‑connected OT workloads, AI‑assisted policy generation for segmentation, and managed OT security services have reduced some operational overheads previously cited as barriers.
Data and evidence: what practitioners are seeing in 2026
Observed trends across utilities, manufacturing and critical infrastructure in 2025–2026 include:
- More frequent use of gateway translation patterns: organizations increasingly deploy identity‑aware gateways to present modern certificates for legacy PLCs rather than attempting endpoint upgrades during production‑critical maintenance windows.
- Hybrid deployments dominate: few large operators adopt a pure identity‑first or pure segmentation posture; hybrid architectures combining protocol proxies with per‑session identity controls are common.
- Identity for vendor access is now standard procurement language: Request for Proposals (RFPs) commonly require ephemeral credentials, session recording and just‑in‑time (JIT) access for third‑party maintenance.
- Security automation adoption: staging policies in shadow mode, automated rollback on anomalies and policy‑as‑code templates have materially reduced accidental outages during segmentation rollouts.
These shifts are grounded in practical operational constraints: patch windows remain costly, and many legacy endpoints still cannot host agents. That reality makes gateways, proxies and local validation caches persistent components of OT zero‑trust programs.
Network segmentation: what still works and where it strains
Network segmentation—zones and conduits, protocol proxies, industrial firewalls—remains the primary risk‑control backbone where safety and latency are non‑negotiable.
Why segmentation remains essential
- Safety‑first compatibility: Non‑intrusive network controls introduce less risk to deterministic control loops than agent installs or changes to PLC firmware.
- Protocol enforcement: DPI and industrial protocol proxies can continue to block malformed commands that could lead to unsafe states.
- Operational familiarity: OT engineers and systems integrators have long operational playbooks for VLANs, DMZs and conduits aligned with IEC 62443 principles.
Where segmentation creates operational debt
- Scale and drift: Large, multi‑site environments experience ACL drift and configuration sprawl unless automated and continuously validated.
- Remote access windows: Temporary relaxations for maintenance remain a frequent cause of post‑maintenance incidents; many operators now require recorded, identity‑bound sessions to mitigate that risk.
- Coverage gaps: Removable media, local human‑machine interface (HMI) consoles and vendor laptops often bypass network boundaries and require complementary controls.
Identity‑first controls: progress and pragmatic limits
Identity‑first approaches—device certificates, hardware attestation and brokered zero‑trust access—have matured but still face real operational constraints in many brownfield OT environments.
Where identity adds the most value
- Vendor access and JIT permissions: Short‑lived credentials, recorded sessions and constrained protocol tunnels materially reduce standing access and exposure.
- Cloud and containerized OT workloads: For telemetry, analytics and control apps running in cloud or edge VMs, service meshes (mTLS, identity sidecars) provide fine‑grained policy and observability.
- Device provenance and supply chain: Device attestation (TPM/DICE) enables stronger lifecycle guarantees for newly procured controllers and gateways.
Practical limits still exist
- Endpoint capability gaps: Many in‑field PLCs and legacy I/O modules still cannot run modern PKI stacks or agents; gateways remain the pragmatic bridge.
- Availability requirements: Centralized identity services must be designed with local fallback and deterministic behavior to avoid creating new safety risks.
- Cross‑functional change management: Identity projects require procurement, OT, security and vendors to coordinate on cert lifecycles, automation and incident playbooks.
Hybrid patterns gaining traction in 2026
Operational teams are converging on hybrid architectures that pair segmentation with identity at appropriate boundaries. Four practical patterns that are now commonplace:
- Gateway identity translation (de facto standard for brownfield): Identity‑aware gateways translate modern certificates and attestations into legacy protocol sessions for PLCs. This permits per‑session logging and JIT vendor access without touching the endpoint firmware.
- Zone‑plus‑identity for vendor sessions: Production zones remain tightly segmented; vendor access is confined to ephemeral tunnels brokered by identity services and recorded for audit and forensics.
- Safety‑aware authorization: For safety‑critical commands, systems combine protocol validation at the proxy with identity checks and multi‑party approval before execution—integrating functional safety requirements into access policy.
- Service mesh in cloud/edge layers: Telemetry collectors, OPC UA gateways and analytics workloads use mTLS/service mesh patterns so that cloud‑hosted components can be governed by identity while the field network stays segmented.
New operational levers in 2026
Several operational practices and technologies have become mainstream:
- Local validation caches: Identity services now routinely provide local caches and offline token validation to preserve availability during network partitions.
- Policy as code + shadow mode: Teams use automated policy modeling and a shadow enforcement period to detect unintended operational impacts before changes go live.
- SBOMs and firmware attestation: Buyers increasingly require SBOMs for embedded controllers and attestable firmware chains as part of procurement contracts.
- AI‑assisted anomaly detection: OT‑specialized models that understand control plane semantics are supplementing, not replacing, deterministic safety checks; they are primarily used to prioritize operator investigation.
Implications for OT teams — decisions to make now
If you manage OT security, the central tradeoff is unchanged: reduce attack surface without creating new availability or safety risks. Practical implications:
- Start with inventory and flow mapping: Passive network discovery and asset tagging are prerequisites for either path and remain the highest‑ROI first step.
- Design for failure: Identity services must have local offline validation and graceful fallbacks; segmentation must tolerate emergency maintenance procedures without expanding permanent access.
- Negotiate vendor contracts: Make ephemeral, recorded access and minimum‑privilege access contractual requirements for third‑party maintenance.
- Invest in cross‑functional runbooks: Incident playbooks that include OT engineers, safety officers and vendors reduce the odds of an access control change causing downtime.
Updated roadmap and 90‑day checklist (Oct 2026)
Updated, pragmatic steps that reflect 2026 realities:
- Inventory & flows (weeks 0–4): Deploy passive monitoring to build canonical inventory, map flows and identify high‑risk cross‑zone traffic.
- Segment critical zones (weeks 4–12): Harden safety‑critical zones with protocol proxies and strict ACLs; use shadow mode and automated rollback for policy validation.
- Gateways for legacy devices (weeks 8–16): Deploy identity‑aware gateways to enable ephemeral vendor sessions without firmware changes to PLCs.
- Vendor controls and contracts (weeks 8–16): Require JIT access, recorded sessions and least‑privilege permissions as procurement clauses for all third parties.
- Measure & iterate (ongoing): Track mean time to isolate anomalous sessions, counts of maintenance ACL relaxations, and any production impact from security changes.
Multiple perspectives
Operators: Many OT managers emphasize safety and continuity; they prefer segmentation first and selective identity for vendor access. Security teams: Corporate security teams push identity‑first where possible to unify policy across IT and OT. Vendors: Industrial security vendors are shipping hybrid appliances—protocol proxies with built‑in identity brokers. Regulators and auditors: Enforcement and procurement expectations are tightening; auditors increasingly look for evidence of ephemeral access controls and SBOMs.
Outlook — what to watch through 2027
Near term (12–18 months) expectations:
- Wider baseline of device attestation on new hardware; more gateways supporting standardized device attestation (DICE/TPM).
- Rising use of managed OT zero‑trust services for organizations that lack onsite expertise.
- Further convergence of functional safety and cybersecurity processes: expect more guidance and case studies showing how to combine safety cases with identity‑based authorization.
Frequently asked questions
Should I replace segmentation with identity controls?
No. In most brownfield OT environments, segmentation remains the pragmatic backbone for safety‑critical devices. Identity controls are best applied where endpoints support them or at gateways and for remote/vendor access. The optimal program blends both.
How do I avoid creating a single point of failure with identity services?
Design identity services with local validation caches, geographically distributed PKI, and offline failover modes. Test recovery and failover during staged maintenance windows to ensure deterministic behavior that won’t affect safety functions.
Can legacy PLCs be made “zero trust” without firmware changes?
Yes—via identity‑aware gateways and protocol proxies that present modern certificates and enforce session policies on behalf of legacy devices. Gateways also provide logging and replay protection that endpoints often lack.
What role does service mesh play in OT?
Service meshes are useful where OT functions run as software in cloud/edge VMs or containers. They provide mTLS, policy enforcement and observability for those components while field networks remain segmented and safety‑controlled.
What immediate procurement changes should I require from vendors?
Require ephemeral, recorded remote access; SBOMs for embedded components; device attestation capabilities where available; and contractual obligations for patch windows and coordinated maintenance to avoid surprise outages.
Zero trust for OT in October 2026 is no longer an academic split between segmentation and identity. It is an operational design problem solved with layered controls: segmentation as the safety‑aware foundation, identity where endpoints and processes allow, and gateways, caches and service meshes to bridge the gap. Teams that treat availability and safety as first principles, automate policy testing, and bake identity into vendor access and procurement will make the most measurable progress in the coming year.