Governance and Architecture for the Cyber‑Physical Enterprise

Every industrial enterprise now operates across a boundary its governance was never built to hold: the points where enterprise IT, operational technology, and persistent vendor connections meet the systems that drive physical equipment.

Every digital instruction that reaches a physical actuator crosses it; every reading that leaves the plant passes through it.

Why is IT/OT convergence so hard to accomplish? A short, diagnostic paper on the structural reasons IT/OT convergence has resisted resolution for two decades. Download the paper →

This site addresses the structural governance problem that IT/OT convergence creates. The diagnosis leads to a governance mandate, the mandate to an architectural specification, the specification to measurable outcomes, and the outcomes to engagement tracks that carry the work into the enterprise.

The Territory

IT/OT Convergence is not a technology trend. It is a structural condition.

Two disciplines with fundamentally different purposes, different governance logics, and different relationships to physical consequence have been forced to share infrastructure, data, and decision space. The connectivity is real. The consequences are physical. The governance, overwhelmingly, is absent.

Timeline of IT, OT and IT/OT Convergence – from early computing and mechanical automation through the DMZ, IDMZ, to the TGB with its five functions: mediation, governance, semantics, monitoring, segmentation.
The timeline of IT, OT, and their convergence – and the boundary architectures that emerged at each stage. The DMZ separated two IT trust domains. The IDMZ segmented networks. The TGB governs the interaction between domains of fundamentally different consequence.
The Central Argument

Three actors, three governance logics, one void.

The Operator carries consequence-ownership. Corporate IT carries enterprise digital governance. The Vendor ecosystem carries product-boundary governance. Each logic works within its own domain. None encompasses the boundary where all three meet. That boundary is the governance void – and the TGB is the architectural mechanism through which it is structurally resolved.

Diagram showing the three enterprise domains – Operator, Corporate IT, and Vendor – converging on a governance void that is resolved by the TGB and its three functions: traffic mediation, governance translation, and semantic translation.
The governance void – no actor owns the boundary – resolved by the TGB with its three inseparable functions. Traffic mediation alone is an IDMZ. All three functions together are the TGB.

Structural Diagnosis diagnoses the void. Governance Mandate derives the mandate. Governed Boundary specifies the architecture. Together, they are what governance architected into existence looks like.

In Practice

When the boundary is ungoverned, it fails in patterned ways.

Four cases. Each card shows which of the TGB's three functions – traffic mediation, governance translation, semantic translation – were absent when the failure occurred. The three functions operate as a stack, and the cases trace the stack upward: from traffic mediation alone, to traffic plus governance, to the full collapse where all three are absent.

May 2021 · Pipeline · USA

Colonial Pipeline

IT pivot forces OT shutdown – absent demarcation

Ransomware entered via a legacy VPN account without multi-factor authentication and encrypted Colonial's IT environment. The OT pipeline network itself was not encrypted, yet 5,500 miles of pipeline were taken offline as a precaution. The shutdown was a direct consequence of absent IT/OT demarcation and governance. The TSA issued the first mandatory OT cybersecurity directives ever imposed on the U.S. pipeline sector in response.

5,500 mi offline · 6 days shutdown · $4.4M ransom · TSA SD-02B
Absent TGB functions Traffic mediation Governance translation Semantic translation
March 2019 · Aluminium · Norway

Norsk Hydro

IT to OT lateral spread via Active Directory

LockerGoga ransomware entered via a spear-phishing attachment and propagated through Windows Active Directory to reach 160 sites and 20,000+ systems. OT plants were switched to manual operation to contain the threat before it could reach industrial control systems. Hydro refused to pay and rebuilt from clean backups, incurring months of reduced output in the process.

$70M+ loss · 160 sites · 20,000+ systems · months to recover
Absent TGB functions Traffic mediation Governance translation Semantic translation
August 2017 · Petrochemicals · Saudi Arabia

Petro Rabigh – TRITON

Safety system targeted after 90-day IT dwell

Attackers entered the corporate IT network at least 90 days before deploying TRITON against Schneider Electric Triconex Safety Instrumented Systems – the first malware ever engineered specifically to disable industrial safety backstops. An accidental safe-state shutdown revealed the intrusion. Had the safety systems been successfully disabled and process equipment manipulated, the potential consequence was toxic gas release and explosion.

SIS targeted · 90+ day dwell · H₂S / explosion risk · nation-state
Absent TGB functions Traffic mediation Governance translation Semantic translation
June 2017 · Shipping & Logistics · Denmark

A.P. Møller-Maersk – NotPetya

Flat network cascade – undifferentiated IT/OT architecture

NotPetya entered via a single MeDoc-infected machine in Odessa. Flat enterprise IT networks with no segmentation allowed it to reach all nine business units within hours. Port operations globally – including the loading systems used to balance container ships – were halted, stranding vessels for weeks. Maersk reinstalled 45,000 PCs and 4,000 servers. The defining case study of what undifferentiated IT/OT network architecture costs at scale.

$250–300M loss · 76 ports · 45,000 PCs reinstalled · 2 weeks
Absent TGB functions Traffic mediation Governance translation Semantic translation

The same NotPetya wiper struck Merck, Mondelēz, and Saint-Gobain in June 2017 – a single enterprise blast radius across four otherwise unrelated industries, with combined acknowledged losses above $1.5 billion. Each case maps to the three functions the governed boundary would have exercised: traffic mediation, governance translation, and semantic translation.

A Three-Book Series

The diagnosis, the mandate, and the architecture.

This three-book series diagnoses the structural condition in depth, derives the governance mandate it demands, and specifies – in architectural detail – the architecture that makes governance operational at the place where it has to act.

Go Deeper

Read the argument before the books.

The Introduction to the Series sets out the central argument, the three governance mandates, the TGB as the architectural mechanism, and the structure of the three-book series. Concise, complete, and designed to stand alone.

The Introduction opens
Industrial organisations have spent two decades connecting operational technology to enterprise networks. The connectivity is real, the consequences are physical, and the governance – overwhelmingly – is absent.

From there, the Introduction traces the central argument, names the three actors and their governance logics, sets out the three mandates – fidelity of representation, safety of action, integrity of their interaction – and introduces the TGB as the architectural mechanism through which the void is structurally resolved. Request the full document below.

Publication

The series is in its final stages.

The Structural Diagnosis, The Governance Mandate, and The Governed Boundary are in final editing before publication. Register to be notified when each volume becomes available.

Author

Martin van der Linden

Martin van der Linden is the author of the three-book series Governance and Architecture for the Cyber-Physical Enterprise. He works with industrial enterprises on the governance and architecture of IT/OT convergence – the territory on which enterprise systems, operational technology, and vendor platforms meet, and where the governance void this work addresses has its practical consequences.

LinkedIn