Learn how can smart cities unify operational data, improve visibility, detect anomalies, and secure connected infrastructure.

Every day, cities generate millions of data points — from water pressure readings to traffic signal state changes to air quality alerts. Too often, that data stays across separated IT and OT environments, trapped in systems that were never designed to share it, which slows response and hides problems until they become outages.
Operational technology (OT) is the hardware and software that monitors and controls physical infrastructure (pumps, valves, signals, building systems).
Informational technology (IT) is the hardware and software supporting agencies in investigating incidents, coordinating response, and measuring performance (identity, endpoint security, network security, analytics platforms).
When OT and IT data remain separated, agencies lose the context needed to act quickly and safely.
This article explains a practical way to bridge OT and IT data with Elastic, so you can move from isolated sensor readings to a unified operational view with searchable, governed, real-time operational insight.
IT and OT convergence is the shift away from treating operational technology and information technology as separate domains with separate ownership and toward a model where data, tools, and processes flow between them as one system.
For decades, agencies ran OT and IT as parallel worlds with different teams, different budgets, and different vendors. That separation made sense when OT systems were closed and physically isolated. It makes far less sense today, when a traffic signal controller, a water treatment sensor, and a city laptop can all sit on the same network path.
IT and OT data convergence becomes even more important as organizations adopt AI. The value AI delivers is greater when it has context from unified data and can support teams with a unified operational picture and a better understanding of what is happening across the systems that run the city.
Elastic reduces protocol sprawl by using a single ingestion architecture, the Elastic Agent managed by Fleet, to normalize data from legacy industrial protocols and modern IoT sources into Elastic Cloud.
| Architecture component | What it does | Why it matters for agencies |
| Sensors and devices | Physical infrastructure: pumps, traffic lights, meters, HVAC, air monitors | Source of operational truth |
| Elastic Agent (edge) | Runs on gateways/servers to collect logs/metrics and ship securely | Reduces tool sprawl; consistent policy and upgrades |
| Fleet | Central management for thousands of Elastic Agents | One control plane for rollout, config, and compliance |
| Elastic Cloud | Central datastore and search/analytics platform | One place to correlate OT and IT data |
| Kibana dashboards | Visualizations and workflows for operators and analysts | Faster triage and clearer situational awareness |
As a result, with Elastic, data from a decades-old valve controller can be indexed and explored with the same consistency as telemetry from a modern IoT sensor, so teams spend less time translating formats and more time resolving issues.
It also improves interoperability by giving legacy and modern systems a common data layer, making it easier to connect systems across different protocols, vendors, and generations of infrastructure.
While many OT protocols are manufacturer-specific, the true challenge for municipalities is long-term interoperability, ensuring that data remains accessible regardless of which hardware vendor provided the sensor.
Standards like Modbus, PROFINET, and DNP3 typically operate within closed ecosystems. This siloed approach creates significant friction when agencies attempt to integrate new hardware, rotate vendors, or consolidate telemetry into a single operational view.
To counter this, the industry is shifting toward vendor-neutral frameworks. For instance, OPC UA provides a common interface for cross-manufacturer communication. Agencies should apply this same logic to their analytics platforms: adopting a vendor-agnostic, open architectural layer that resides above device-specific protocols to maintain flexibility.
In this environment, open standards, Elastic Agent, and Fleet serve as the interoperability plane. Whether data originates from an MQTT broker or a legacy gateway, it is normalized into a unified schema in Elastic Cloud. This ensures that swapping hardware providers doesn't force a total rebuild of your Kibana dashboards or ML jobs, providing a practical defense against vendor lock-in.
Agencies can quantify impact through faster troubleshooting, fewer blind spots, and earlier detection of operational anomalies (like leaks), especially when OT and IT signals are searchable together. Although use cases may vary depending on organizational needs, these outcomes are already being realized by organizations using Elastic in different operational contexts.
Kibana dashboards unify OT telemetry (pressure/flow/valve state) with IT health signals so operators can triage incidents faster.
Real-time service health and incident response views help transit teams correlate delays with infrastructure and network events.
Revenue and enforcement teams can track transactions, device uptime, and anomalies in one shared view.Almost every smart city data point already has a location attached to it. Elasticsearch stores that location natively as geo_point or geo_shape data, and Kibana Maps turns it into a layer agencies can search, filter, and correlate in real time.
A water pressure reading, a traffic signal fault, and a security alert on a substation network all mean more when you know where they happened relative to each other. Treating location as a first-class field, not an afterthought bolted on in a separate GIS tool, is part of what makes an OT/IT unification strategy actually usable day to day.
Layering OT sensor locations, utility service boundaries, and security events on one map helps operators see the physical scope of an issue, not just a list of alerts.While strict air-gapping remains a requirement for highly sensitive federal and defense infrastructure, many municipal agencies are intentionally connecting everyday operational systems to power modern smart city services. However, when OT becomes reachable from IT networks, the attack surface expands, and the blast radius can move beyond data loss into physical service disruption.
This is why guidance from organizations such as CISA and NIST emphasizes securing OT environments while accounting for their unique operational and safety requirements.
Whether you maintain strictly isolated environments or are embracing IT/OT convergence, Elastic Security supports an OT-aware approach. You can secure connected city infrastructure by applying Zero Trust, correlating IT and OT events to detect lateral movement, and using protocol-aware detections mapped to MITRE ATT&CK® for ICS.
Attackers often start in IT (phishing, stolen credentials) and pivot toward OT. When OT and IT telemetry land in one platform, analysts can:
Investigate a phishing-driven endpoint event
Track identity and authentication activity
Correlate network behaviors and OT-side command anomalies
Build a single timeline that reduces handoffs between tools
Use AI-driven capabilities to automatically summarize complex IT/OT attack chains
Instead of treating OT traffic as opaque, agencies can enrich and analyze it:
Decode and analyze industrial protocols (e.g., Modbus, DNP3, and CIP) to identify suspicious commands
Alert on behavior that’s unusual for a device, time, or segment (e.g., administrative writes at abnormal hours)
Reduce false positives by pairing network detections with asset and identity context
Mapping detections to MITRE ATT&CK for ICS helps teams:
Align detection coverage to known tactics and techniques
Communicate risk in a common language across leadership and technical teams
Prioritize gaps based on real adversary behaviors
As smart cities bring more OT, IT, and IoT data together, Elastic can help agencies build a more connected operational view, detect anomalies, strengthen security across their infrastructure, and reduce tool sprawl. You can start by setting up the MQTT integration to bring OT data into Elastic, use machine learning for anomaly detection to identify unusual patterns in city sensor data, and explore Elastic Security to help protect industrial and OT environments.
The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | When AI agents swarm, can banks keep up? | 0 | 10.38 | 30-09-2026 |
| 2 | The security attack that hid inside your observability data | 0 | 5.62 | 03-09-2026 |
| 3 | Federal Leader’s Guide to CAIO & CDO: Qlik’s Andrew Churchill on growing your confidence in agentic tools | 0 | 8.14 | 28-09-2026 |
| 4 | Are Smart Cities ‘Sustainable?’ Revisiting the ‘Helix Model’ of the ASEAN Smart Cities Network [version 3; peer review: 1 approved, 2 approved with reservations, 1 not approved] | 0 | 7.84 | 08-09-2026 |
| 5 | How cities can secure EU mobility funding | 0 | 10.96 | 12-09-2026 |
| 6 | How SEO agencies are adapting to agentic search | 0 | 8.4 | 28-07-2026 |
| 7 | Autonomous AI Agents: Architecture and Risk Mitigation | 0 | 6.94 | 10-09-2026 |
| 8 | What Merkle Tree Certificates (MTCs) mean for your certificate operations | 0 | 11.6 | 25-09-2026 |
| 9 | An SEO guide for service businesses | 0 | 6.55 | 31-03-2026 |