OT Cybersecurity: From Perimeter Security to Zero Trust: An AI-Governed OT Cybersecurity Architecture for Industrial Systems
Abstract
The progressive convergence of Information Technology (IT) and Operational Technology (OT) environments has introduced new cybersecurity challenges for industrial and critical infrastructure systems. This work presents a generalized OT cybersecurity architecture that combines the Purdue reference model with Zero Trust principles to enforce strict segmentation, continuous verification, and controlled information flows across IT/OT boundaries. The architecture incorporates Artificial Intelligence (AI)-driven monitoring to support anomaly detection, contextual risk assessment, and automated response mechanisms under operational constraints. Additionally, a governance and assurance layer is discussed, aligning AI-enabled security functions with recognized risk management frameworks and auditable controls to ensure trustworthiness, resilience, and operational sustainability in high-impact industrial deployments. The proposal is further contextualized with prior AI-RMFgoverned IoT-as-a-Service and OWASP ML05 middleware contributions that address AI-enabled IoT security, model protection, and governance requirements.