Architecture guide · Critical infrastructure

IT/OT convergence in Africa: connect the business without weakening operations

The objective is controlled information flow, shared operational context and better decisions. The objective is not one flat network, cloud-dependent control or blurred accountability.

What IT/OT convergence means

Operational technology controls and observes physical processes. Information technology supports enterprise data, identity, collaboration, business applications and analytics. Convergence creates deliberate interfaces between those domains so that the right people and services can use operational information without removing the controls that protect availability, determinism and safety.

Examples include sending approved Historian data to energy or maintenance applications, presenting BMS and SCADA alarms in a Unified Control Centre, managing software versions across remote sites, or returning a reviewed work instruction to an operator. Each flow needs an owner, a purpose, a security boundary and a fallback when communications are unavailable.

A useful test: if a central service disappears, does the site continue to operate safely and predictably for the required period? If the answer is unclear, the architecture is not ready.

Five design principles for African operations

  1. Keep essential control local. WAN, cloud and enterprise-service failure must not automatically become process failure.
  2. Move only justified data and commands. Every cross-domain flow should have a business purpose, owner and minimum required privileges.
  3. Use zones and controlled conduits. Segment sites and services according to operational consequence, not organisational convenience.
  4. Design for disconnection. Buffer data, define stale-data behaviour and plan reconciliation after connectivity returns.
  5. Make lifecycle ownership explicit. Configuration, graphics, certificates, accounts, backups, patches and documentation need named owners.

The IEC describes the IEC 62443 series as cybersecurity standards for industrial automation and control systems. Its concepts provide a useful structure for programmes, systems, components and secure development, but implementation still needs a risk-based design for the specific operation.

A practical reference architecture

Level 1 · Process

Controllers and field assets

PLCs, RTUs, meters, protection systems and equipment interfaces. Local control logic remains authoritative for the process.

Level 2 · Operations

SCADA, HMI and local history

Operator supervision, alarms, engineering and the minimum local data services needed for autonomous operation.

Level 3 · Site services

Operational DMZ and brokers

Jump hosts, replication, patch staging, secure gateways, interfaces and monitoring that mediate cross-domain traffic.

Level 4 · Enterprise and group

Business and fleet services

Reporting, maintenance, energy, analytics, central administration and approved decision workflows.

Commands from central services deserve more scrutiny than outbound data. Define authorisation, validation, expiry, acknowledgement, local interlocks and behaviour after delayed delivery. “Technically possible” is not the same as operationally acceptable.

Governance: shared work, distinct accountabilities

Convergence programmes fail when IT owns the network but not the process consequence, or operations owns the process but not the cross-domain exposure. A workable model gives each group explicit decision rights:

  • Operations: process availability, operating modes, alarm response and acceptable fallback behaviour.
  • Engineering: control-system design, interfaces, configuration standards and lifecycle integrity.
  • Cybersecurity: risk assessment, zones, identities, monitoring, incident coordination and assurance evidence.
  • IT: enterprise platforms, identity services, infrastructure, data services and support processes outside the control boundary.
  • Management: priorities, risk acceptance, funding, partner model and performance measures.

A shared architecture review and change process should cover both technical changes and shifts in operating responsibility.

Multi-site convergence: local autonomy, central services

Distributed water, transport, building, energy and industrial estates need more than a central dashboard. They need predictable local operation, efficient engineering, store-and-forward data, secure remote support and a controlled way to distribute applications and updates.

CODRA's Edge-to-Service architecture describes autonomous local SCADA, central hypervision, central administration, an Edge Gateway in a DMZ and remote deployment of applications, versions and patches. It is a useful pattern when the business wants group-level services without turning the WAN into a control dependency.

The regional context changes the delivery plan

West Africa requires English- and French-speaking partner capacity across large territories. Central Africa can place greater emphasis on remote maintainability, knowledge transfer and communications resilience. East Africa includes rapidly expanding, distributed infrastructure where phased deployment is common. Southern Africa often combines mature industrial estates, legacy systems and demanding lifecycle requirements.

These are broad planning contexts, not substitutes for country and site discovery. The final design must reflect local regulation, skills, support routes, connectivity, installed assets and operational consequence.

Explore the delivery and partner context for each region:

Where Panorama Suite fits

Panorama Suite can provide the vendor-independent OT/IT Data Management Platform behind a Unified Control Centre. The foundation can support SCADA, GeoSCADA, BMS, EMS, Historian, PSIM and MES applications, alongside controlled interfaces, central supervision and selected Edge-to-Service capabilities. It is most valuable when the operator needs one consistent data and engineering model across mixed equipment, applications and sites.

The platform should be evaluated alongside the full system: controllers, networks, gateways, identity, backup, monitoring, integrator capability and support model. Read Panorama Suite for Africa: an OT/IT Data Management Platform for Unified Control Centres for the product evidence, cybersecurity status and evaluation checklist.

A practical phased delivery roadmap

  1. Choose one outcome. Examples: reduce alarm-response delay, unify energy reporting or centralise fleet status.
  2. Map the current path. Assets, protocols, data ownership, trust boundaries, dependencies and failure modes.
  3. Define the target interface. Data, commands, identities, latency, availability, retention and audit requirements.
  4. Build the security and fallback model. Segmentation, access, monitoring, backup, incident response and disconnection behaviour.
  5. Pilot on a focused scope. Prove operations, interoperability, support and handover, not only the dashboard.
  6. Scale by repeatable pattern. Standardise what worked while retaining justified site-specific differences.

Frequently asked questions

What does IT/OT convergence mean in practice?

It means creating governed interfaces between operational systems and enterprise services so that approved data and workflows can cross domains. It does not mean flattening IT and OT into one network or giving enterprise applications direct control access.

Should operational control move to the cloud?

Not by default. Essential control and operator supervision should remain at the level required for safe, deterministic and autonomous operation. Cloud or central services can add reporting, fleet analytics and selected workflows where the risk assessment supports them.

Who should own an IT/OT convergence programme?

Operations, engineering, cybersecurity and IT need defined joint governance. Operations should retain authority over process risk and availability; IT and security teams should own enterprise services and cross-domain controls within an agreed responsibility model.

Where should an organisation start?

Start with one operational decision or workflow, map the assets and data path, define the trust boundaries and owners, then prove the design on a focused site or asset group before scaling.

Discuss the initial scope

Turn convergence into an operational design

I work with African operators and integration partners to define the architecture, installed-base constraints, cybersecurity boundaries and delivery model before technology choices are locked in.