IT and OT Convergence When You Are the Entire IT Department
The literature on IT and OT convergence assumes two organizations that need to be brought together. At most small utilities there is one person, and convergence already happened, without a plan, sometime around whenever the historian was connected to the business network so that management could see production dashboards. For that person, convergence is not a project. It is a condition. The question is how to manage it with the capacity that exists.
The Reference Models, and What to Take From Them
The Purdue model describes six layers from physical process at Level 0 to enterprise systems at Level 5, with a demilitarized zone between operations and enterprise. It was formulated for large manufacturing, and treating it as an architecture to implement will exhaust your budget before you reach Level 3. Take one idea from it: data should flow up, commands should not flow down without passing through a controlled point. If your enterprise network can originate a connection directly into a PLC, you have no meaningful boundary regardless of what your diagram claims.
IEC 62443 organizes systems into zones with defined conduits between them. Full certification is out of reach. The zone concept is not. Drawing three zones on a whiteboard—enterprise, operations, and control—and identifying every place traffic crosses between them is genuinely achievable in an afternoon and will change what you do next. NIST SP 800-82 Revision 3 is the most practically written of the three for a small operator. Read the risk management sections and skip the rest until you need it.
Six Moves, Ordered by Ratio of Risk Reduced to Effort Spent
Enumerate the crossings. Before segmentation, inventory. Every place the enterprise network touches the operations network: the historian replication, the reporting server, the engineering laptop that gets carried between both, the vendor VPN, the shared printer, the badge system, the HVAC controller somebody put on the business VLAN. The list is always longer than expected. The undocumented crossings are the ones that matter.
Harden the enterprise side first. This is counterintuitive to people who think of OT as the crown jewels, and it is correct anyway. Intrusions overwhelmingly begin in email and business systems and move laterally. Multi-factor authentication on email and remote access, endpoint protection on business workstations, and a tested offline backup will prevent more OT incidents than anything you deploy inside the plant.
Make vendor access session-based. Standing remote access is the single most common serious finding in small utility environments. The target state is access that is disabled by default, enabled on request for a defined window, and logged. If your integrator resists, that resistance is itself information about the maturity of the relationship.
Segment the highest-consequence path only. You will not segment everything. Pick the single path whose compromise causes physical consequence, usually enterprise to control network, and put a real boundary there with default-deny rules and explicit exceptions. One well-implemented boundary beats a comprehensive plan that stalls at forty percent.
Document at the level you would need at two in the morning. A hand-drawn network diagram photographed and stored somewhere retrievable. An asset list. A contact sheet with mobile numbers. Where the manual override procedures are kept. This is not compliance documentation. It is incident documentation, and its only quality criterion is whether it helps someone who is tired and alone.
Plan the degraded state. For each critical process, answer: can it run manually, for how long, who knows how, and where is that written down. Then verify by asking an operator rather than assuming.
On Monitoring
Every vendor in this space will try to sell you OT network monitoring. The technology is real and the detections can be genuinely good. It is usually the wrong purchase for a one-person shop, for a reason that has nothing to do with the product. Detection generates alerts, alerts require someone to triage them, and you are already the entire staff. An unmonitored monitoring system is a line item that produces a false sense of coverage.
If you have budget for one thing, buy tested backups and a restore drill. If you have budget for two, add managed detection with someone else's analysts on the other end. Buy visibility you cannot act on last.
The Reframe
Convergence in a small utility is not about integrating IT and OT practice. It is about accepting that one person carries the risk of both and building around that constraint rather than pretending it away. That means fewer controls, chosen more carefully, actually implemented, and rehearsed at least once. A short list that is real is worth more than a long list that is aspirational, and everyone reading a maturity assessment already knows which one they have.