Critical infrastructure owners and operators struggle to deploy cloud technologies across operational technology environments, understand shared responsibility models, and decide what data to keep on-premises vs. in cloud configurations. Security teams, engineers, and technicians responsible for Operational Technology (OT) network management and maintenance need help informing executive leadership on cyber risk conversations and decisions to support continuous improvement. With Zero Trust principles in focus, this paper is meant to aid owners and operators evaluate current and future cloud adoption across OT environments. There is a concern for end users of operational technology and industrial control systems that control system vendors and integrators are pursuing cloud configurations for computing, storage, and security needs. However, some vendors and suppliers only allow integration within their partner ecosystem. In an effort to simplify the vendor ecosystem, asset owners risk being limited to solutions preselected by original equipment manufacturers and/or systems integrators. It is essential to evaluate the enterprise utility, security impacts, and applicability across heterogeneous systems for each cloud deployment under consideration. This paper covers the considerations, trade-offs, and cybersecurity elements of cloud adoption across OT environments, applicable to a range of sectors. The content breaks down service models for cloud deployments, discusses trade-offs between vendor consolidation and single points of failure (or overreliance on a single technology or provider), and examines the security implications of cloud solutions. It includes sector and vendor-agnostic drivers and cost/benefit considerations for implementing cloud-connected enterprise resource planning (ERP) tools in OT environments, deployment of cloud-enabled security tools in OT environments, and applications and services associated with supervisory control and data acquisition (SCADA) systems in the cloud. Finally, this paper identifies how Cloud adoption in OT must start from clear design principles that prioritize safety, reliability, and resilience. Migrating OT security and operational capabilities to cloud environments fundamentally alters how Zero Trust strategies are implemented in critical infrastructure. The traditional five-step Zero Trust implementation methodology, while remaining conceptually valid, requires significant adaptation to address the unique challenges introduced by cloud adoption in OT contexts. Purpose: This document gives critical infrastructure owners and operators guidance for evaluating cloud adoption in OT environments, including inputs for implementation plans and procurement requirements.
Key Takeaways
- Critical infrastructure owners and operators struggle with deploying cloud technologies across operational technology environments, understanding shared responsibility models, and deciding what data to keep on premises vs. in cloud configurations. Security teams, engineers and technicians responsible for Operational Technology (OT) network management and maintenance need help educating executive leadership on cyber risk conversations and decisions, in support of continuous improvement. With Zero Trust principles in focus, this paper is meant to aid owners and operators in evaluating current and future cloud adoption across OT environments.
- There is a concern for end users of operational technology and industrial control systems that control system vendors and integrators are pursuing cloud configurations for computing, storage, and security needs, however, some vendors and suppliers only allow integration within their partner ecosystem. In an effort to simplify the vendor ecosystem, asset owners risk being limited to solutions preselected by original equipment manufacturers and/or systems integrators. It is essential to evaluate the enterprise utility, security impacts, and applicability across heterogeneous systems for each cloud deployment in consideration.
- This paper uncovers the considerations, trade-offs, and cybersecurity elements related to cloud adoption across OT environments. The content breaks down the service models for cloud deployments, discusses the tradeoffs between vendor consolidation and single points of failure (or an overreliance on a single technology or provider) and security implications of cloud solutions. It includes sector and vendor agnostic drivers and trade-offs for consideration of implementing cloud-connected enterprise resource planning (ERP) tools in OT environments, deployment of cloud-enabled security tools in OT environments, and applications and services associated with SCADA in the cloud.
- Finally this paper identifies how Cloud adoption in OT must start from clear design principles that prioritize safety, reliability, and resilience. The migration of OT security and operational capabilities to cloud environments fundamentally alters the implementation of Zero Trust strategies in critical infrastructure. The traditional five-step Zero Trust implementation methodology, while remaining conceptually valid, requires significant adaptation to address the unique challenges introduced by cloud adoption in OT contexts.



