Designing Zero-Trust Cross-Domain Identity Architectures for Converged IT/OT Active Directory
About This Session
Industrial networks have widely adopted Microsoft Active Directory (AD) to manage authentication for Level 2/3 HMIs, Historians, and engineering tools. However, the misconfiguration of trust relationships between enterprise IT domains and industrial OT domains remains the single most common vector for ransomware propagation into critical physical environments. In corporate IT/OT AD trust configurations, we must analyze the structural failure modes that enabled ransomware to cascade into complete operational shutdowns in major historical incidents such as Colonial Pipeline and Norsk Hydro.
This presentation advances beyond generic best practice recommendations by dissecting the structural failure modes inherent in modern IT/OT AD trust configurations. It presents scenarios illustrating how a compromise of the enterprise domain can escalate into full administrative control of the OT domain through mechanisms such as Kerberos delegation abuses, insufficient security identifier (SID) filtering, and trusted domain bypasses. Following such a compromise, attackers may gain control over systems hosting engineering software, enabling them to alter programmable logic controller (PLC) logic or manipulate operator HMIs, thereby posing direct risks to plant safety and operational reliability.
To address these challenges, this presentation introduces a mathematically validated structural framework for Zero-Trust OT Directory Isolation. The proposed model employs directed acyclic graphs (DAGs) to continuously audit authentication path safety and to formally verify the absence of authentication pathways from untrusted corporate assets to Level 2/3 control systems. The implementation of this framework is demonstrated through cryptographically isolated, unidirectional trust relationships utilizing disconnected identity providers, offline Security Assertion Markup Language (SAML) tokens, and rigorously enforced tiering policies.
Target Audience & Sector Focus:
Primary Focus: OT System Administrators, IAM (Identity and Access Management) Architects, and Network Security Engineers.
Target Sectors: Cross-sector (applicable to Oil & Gas, Power Generation, Water Utilities, and general industrial infrastructure).
This presentation advances beyond generic best practice recommendations by dissecting the structural failure modes inherent in modern IT/OT AD trust configurations. It presents scenarios illustrating how a compromise of the enterprise domain can escalate into full administrative control of the OT domain through mechanisms such as Kerberos delegation abuses, insufficient security identifier (SID) filtering, and trusted domain bypasses. Following such a compromise, attackers may gain control over systems hosting engineering software, enabling them to alter programmable logic controller (PLC) logic or manipulate operator HMIs, thereby posing direct risks to plant safety and operational reliability.
To address these challenges, this presentation introduces a mathematically validated structural framework for Zero-Trust OT Directory Isolation. The proposed model employs directed acyclic graphs (DAGs) to continuously audit authentication path safety and to formally verify the absence of authentication pathways from untrusted corporate assets to Level 2/3 control systems. The implementation of this framework is demonstrated through cryptographically isolated, unidirectional trust relationships utilizing disconnected identity providers, offline Security Assertion Markup Language (SAML) tokens, and rigorously enforced tiering policies.
Target Audience & Sector Focus:
Primary Focus: OT System Administrators, IAM (Identity and Access Management) Architects, and Network Security Engineers.
Target Sectors: Cross-sector (applicable to Oil & Gas, Power Generation, Water Utilities, and general industrial infrastructure).
Speaker
Rupesh Shirke
Associate Principal - LTIMindtree
Rupesh Shirke is a distinguished Operational Technology (OT) and Industrial Control Systems (ICS) cybersecurity leader with over 17 years of experience safeguarding critical infrastructure. A PhD Candidate specializing in the integration of Artificial Intelligence with OT security, Rupesh bridges the gap between scholarly research and industrial reality. As a Principal Architect and CISSP, he designs enterprise-scale defense architectures aligned with ISA/IEC 62443. Driven by a deep passion for cyber-physical safety and mitigating kinetic risks, Rupesh is dedicated to protecting the vital global energy, water, and manufacturing systems that power our communities.
