AI OT-IT Convergence Architecture for Refineries

By Johnson on August 26, 2026

ai-ot-it-convergence-architecture-refinery

Refineries piloting AI for process optimization or predictive maintenance keep hitting the same wall: the control network that keeps a distillation unit safe was never built to talk to a model, and the IT network hosting that model was never built to touch a live DCS. Bridging the two badly is how a promising pilot becomes an incident report. The real fix is not a faster firewall rule, it is a reference architecture that defines exactly where AI sits inside the Purdue Model, what enforces the one-way boundary at Level 3.5, and which IEC 62443 zone the inference engine is actually permitted to live in. See how iFactory is architected around that boundary at ifactory support.

AI OT-IT Convergence Architecture

Give AI a Seat Inside the Refinery Network Without Opening a Door Into It

A Purdue Model Level 3.5 reference architecture that lets AI read live process data through network segmentation, data diodes, and IEC 62443 zoning, so an inference engine never has a write path back into the control system.

7 Levels
Purdue Model layers, field device to enterprise cloud
One-Way
Data diode enforcement out of the control zone
SL2-SL3
Typical IEC 62443 target for refinery control zones

"Just Connect It to the Historian" Does Not Survive a Process Safety Review

Most refinery AI initiatives start the same way. A vendor asks for a route into the DCS historian, someone on the IT side opens a firewall rule, and within a week a model is pulling live tag data for a pilot. It works, right up until a process safety or cybersecurity review asks a simple question: what stops that same path from being used in the other direction. A firewall rule is a policy, not a physical boundary, and policies get changed, disabled during troubleshooting, or quietly widened six months later when someone needs "just one more" data point. None of that shows up as a problem until an audit, an incident, or an insurance renewal forces the question.

The deeper issue is that IT and OT networks were designed around opposite priorities. IT networks are built around confidentiality and are patched constantly. OT networks are built around availability and safety, and a control system that has run without a reboot for years is often treated as a feature, not a risk. An AI platform that needs continuous, high-frequency access to process data sits exactly on top of that fault line, and treating the connection as a routine IT integration project is where most convergence architectures go wrong before a single model is even trained.

Direct Link
The most common architecture mistake in early AI pilots
A model connected straight to the DCS or historian with only a firewall rule between it and the control zone, no enforced direction.
Level 3.5
Where AI platforms should actually live
The industrial DMZ between site operations and the enterprise network, purpose-built to broker data without a direct path either way.
Hardware
What actually enforces a one-way boundary
A data diode is a physical, hardware-enforced link with no return-path circuitry, unlike a firewall rule that exists only in software.
Zones + Conduits
The IEC 62443 model that replaces "just segment the network"
Every asset grouped into a security zone, every connection between zones treated as a conduit with its own defined security level.

The Purdue Model, Level by Level, and Where AI Is Allowed to Sit

The Purdue Enterprise Reference Architecture is the backbone most refineries already design their control networks around, whether or not anyone calls it by that name. It groups every system into a level based on what it does and how directly it touches the physical process, and each level carries a different tolerance for outside connectivity. An AI platform that respects these boundaries can still see everything it needs; it just never gets to sit where a single compromised model could reach a valve.

Level 0-1
Field Devices & Controllers
Sensors, actuators, and PLCs directly on the process. No AI platform should ever hold a direct connection here.
Level 2
Supervisory Control
DCS and SCADA HMI systems. Read access only ever flows out through a historian, never a live tap.
Level 3
Site Operations
Historians, batch management, and site-level manufacturing systems. This is where AI's source data originates.
Level 3.5
Industrial DMZ
The dedicated buffer zone. This is where the AI inference engine and its replicated data actually live.
Level 4
IT & Business Systems
ERP, CMMS, and business intelligence tools that consume AI outputs, never raw control data.
Level 5
Enterprise & Cloud
Corporate networks and cloud dashboards. Furthest from the process, and the only place external users log in.

Data Diode, Firewall, or Proxy: They Are Not Interchangeable

Nearly every OT-IT convergence conversation eventually circles back to which device actually enforces the boundary. The three options get discussed as if they solve the same problem, and they genuinely do not. A firewall filters traffic based on rules that can be reconfigured by anyone with the right credentials. A proxy or broker terminates the connection and re-originates it, which adds inspection but still runs in software. A data diode removes the return path physically, so there is no rule to misconfigure and no credential that can reopen it.

Boundary Enforcement Options Compared
Mechanism Enforcement Type Can Direction Be Reversed? Typical Refinery Use
Firewall Rule Software policy Yes, by any admin with access Perimeter filtering between IT zones, not control-to-IT
Proxy / Broker Software, connection re-origination Only if reconfigured at the application layer Level 3.5 data brokering with inspection and logging
Data Diode Hardware, one-way physical link No, no return-path circuitry exists Control zone to DMZ boundary for AI-fed data streams

IEC 62443 Zones, Conduits, and Security Levels

IEC 62443 replaces the vague instruction to "segment the network" with a defined model: every asset sits inside a zone grouped by function and risk, and every connection between zones is a conduit that carries its own required security level, from SL0 for no protection needed up to SL4 for resistance to a well-resourced, motivated attacker. A refinery control zone housing safety instrumented systems typically targets SL2 or SL3, while the conduit carrying AI-bound data out of that zone is engineered and documented as its own object, not an afterthought of whatever port happened to be open.

IEC 62443 Security Levels at a Glance
Level Protection Against Refinery Relevance
SL0 No specific protection required Non-critical, isolated test systems
SL1 Casual or coincidental violation Low-consequence business systems
SL2 Intentional violation, low resources Standard control zone assets and Level 3.5 DMZ
SL3 Sophisticated, moderately resourced attacker Safety instrumented systems, critical unit controllers
SL4 State-level, well-funded attacker Reserved for the highest-consequence national assets
Map Your Own Architecture

See Where an AI Platform Would Actually Sit on Your Network

Bring your current network diagram and DCS/historian setup to the call. We will walk through how a Level 3.5 architecture would be structured against your existing zones and conduits.

How Data Actually Moves Through a Diode-Mediated Architecture

A secure architecture is only useful if it still delivers data fast enough for the AI use case to matter. The flow below is how a Level 3.5 deployment typically moves process data from the control zone to an inference engine and back out to the business systems that act on the result, without ever opening a return path into the DCS.

1
Historian Mirrors to a Replica
The Level 3 historian continuously mirrors selected tags to a replica store, not the AI platform itself.
2
Data Diode Enforces the Crossing
The replica pushes across a hardware diode into the Level 3.5 DMZ, with no circuitry capable of sending anything back.
3
AI Reads Only the DMZ Copy
The inference engine runs entirely inside the DMZ against the replicated data, never touching a live DCS connection.
4
Outputs Are Reviewed in the DMZ
Recommendations, scores, or alerts are generated and logged inside the DMZ before anything leaves it.
5
Approved Results Reach Level 4/5
Only reviewed outputs are brokered onward to CMMS, ERP, or dashboards, keeping the control zone fully isolated.

What Each Zone Is Actually Responsible For

A convergence architecture stops being theoretical once every zone has a clearly assigned job and a clearly assigned owner. The breakdown below is what most refineries end up documenting once the architecture moves from whiteboard to implementation.

Control Zone (Levels 0-2)
Owned by OT/process control. No external write access under any circumstance, SL2-SL3 target, isolated from every AI component.
Site Operations Zone (Level 3)
Historian and batch systems, jointly owned by OT and site IT. Source of the replicated data feeding the DMZ.
Industrial DMZ (Level 3.5)
Where the AI platform physically runs. Jointly governed by OT and cybersecurity, with a formally defined conduit on each side.
Enterprise Zone (Levels 4-5)
Owned by corporate IT. Consumes only finished AI outputs through the same brokered conduit, never raw process data.

Direct Connection vs Diode-Mediated DMZ Architecture

The gap between these two approaches only becomes obvious once something goes wrong, whether that is an audit, a penetration test, or an actual incident. By then, retrofitting a proper boundary is far more disruptive than designing it in from the start.

Architecture Approaches Compared
Factor Direct DCS Connection VPN Bridge Diode-Mediated DMZ
Return Path Risk High, fully bidirectional Moderate, encrypted but reversible None, physically one-way
Audit Posture Difficult to defend Requires ongoing justification Matches IEC 62443 documentation directly
Data Latency for AI Lowest, but riskiest Low to moderate Near real-time via replica, minimal added delay
Typical Outcome Flagged in security or PSM review Tolerated short-term, rarely approved long-term Standard for sanctioned AI deployments

Four Mistakes That Undo a Well-Designed Architecture

Most convergence failures are not caused by a missing diagram, they are caused by shortcuts taken after the diagram was already approved. These four show up repeatedly across refinery AI deployments.

Skipping the Replica Layer
Pointing the AI platform straight at the live historian instead of a DMZ replica to save on infrastructure cost.
Treating a Firewall as a Diode
Assuming a strict firewall rule set delivers the same guarantee as hardware-enforced one-way data flow.
Undocumented Conduits
Building the connection first and writing the IEC 62443 zone and conduit documentation afterward, if at all.
No Joint OT-IT Ownership
Leaving the DMZ governed entirely by one side, so changes get made without the other team's sign-off.

What Changes Once the Architecture Is in Place

Security Review Outcome

Direct-connection pilots to documented Level 3.5 conduits
Data Freshness for AI

Near real-time replica feed versus stale batch exports
Ownership Clarity

Joint OT-IT sign-off on the DMZ replaces informal arrangements

Not sure whether your current historian setup can support a Level 3.5 replica feed? Talk to our team and we will walk through what your architecture would need.

A Common Starting Point: The Retrofit Scenario

Most refineries approaching this are not building a greenfield network, they are retrofitting an architecture around a DCS and historian that have been running for a decade or more. A typical starting point looks like this: a site operations historian already exists at Level 3, a business network sits at Level 4 with no formal DMZ between them, and someone has proposed an AI model for compressor or heat exchanger monitoring that needs continuous access to a specific tag set. The instinct is to open a single route between the two and call it done.

The retrofit path that actually holds up under review looks different. The existing historian is left untouched, and a lightweight replica instance is stood up specifically to mirror the tags the AI model needs, nothing more. A data diode is installed between that replica and a newly defined Level 3.5 segment, and the AI platform is deployed entirely inside that segment rather than on the business network. Outputs are logged and reviewed inside the DMZ before a broker service forwards only the finished recommendations to the CMMS or reliability dashboard the maintenance team already uses. The retrofit takes longer than opening a single firewall rule, but it produces an architecture that a security assessor, an insurer, or a process safety review can actually sign off on without conditions attached.

Frequently Asked Questions

What is Level 3.5 in the Purdue Model, and why does AI belong there specifically?
Level 3.5 is the industrial DMZ sitting between site operations and the enterprise network, purpose-built as a buffer rather than a pass-through. Placing AI here means the platform can read replicated process data without ever holding a direct connection into the control zone, and any output it produces is reviewed before it ever reaches business systems. Talk to our team about how this maps to your existing network.
Is a data diode really necessary, or can a strict firewall configuration achieve the same result?
A firewall enforces its boundary through software rules that can be changed by anyone with sufficient access, intentionally or by mistake during troubleshooting. A data diode removes the return-path circuitry entirely, so there is no rule to misconfigure and no credential that can reopen the connection. For AI feeds coming out of a control zone, that hardware guarantee is what most IEC 62443 assessments expect to see.
Does IEC 62443 certification apply to the AI platform itself, or to the whole architecture around it?
IEC 62443 is a system-level standard, so it evaluates the zones, conduits, and security levels of the entire architecture rather than certifying a single product in isolation. An AI platform can be well-built and still fail an assessment if it is deployed without a properly zoned DMZ around it. Book a scoping call to see how this applies to your specific deployment plan.
Can AI still deliver near real-time insights if it never touches the live DCS directly?
Yes, because the replica layer at Level 3 is updated continuously from the historian, and the diode crossing into the DMZ adds only marginal delay compared to a direct connection. For nearly every predictive maintenance or optimization use case, that small latency difference is far outweighed by removing the return-path risk entirely.
Who should actually own the decision to build this architecture, IT or OT?
Neither side should own it alone, since OT understands the control zone's safety consequences and IT understands the enterprise systems consuming the output, but only joint governance keeps the DMZ from drifting out of alignment with either side's changes. Most refineries formalize this as a shared sign-off requirement for anything touching the Level 3.5 conduit. Reach out to our team for a suggested ownership structure.
Stop Guessing Where AI Should Sit on Your Network.

Get a Level 3.5 Architecture Built Around Your Refinery

Bring your current network diagram and historian setup to the call. We will walk through exactly how a diode-mediated, IEC 62443-aligned architecture would be structured against what you already have running.

7
Levels mapped
One-Way
Diode enforcement
62443
Zone alignment
Joint
OT-IT governance

Share This Story, Choose Your Platform!