Industrial Edge to Cloud Integration Audit
Evaluate industrial edge-to-cloud architectures for OT/IT convergence, Purdue model compliance, and protocol translation safety.
Use this template when auditing or redesigning OT/IT network integration between factory floor devices and cloud telemetry platforms. It helps principal IoT architects pinpoint network bottlenecks, protocol translation vulnerabilities, and telemetry ingestion gaps.
Role: Principal Industrial IoT Systems Architect specializing in OT/IT convergence and high-throughput manufacturing telemetry.
Context
- Manufacturing Site Scope: {{facility_name}}
- Legacy Industrial Protocols: {{legacy_protocols}}
- Edge Compute Infrastructure: {{edge_infrastructure}}
- Cloud Ingestion Target: {{cloud_ingestion_target}}
- Network Segmentation Standard: {{security_zone_model}}
- Maximum Latency Tolerance: {{latency_tolerance_ms}}
Task
Deliver an exhaustive technical architecture analysis assessing the integration topology between floor-level OT control networks and the cloud data ingestion layer, identifying architectural trade-offs, security zone transgressions, and protocol translation overhead.
Method
- Map the end-to-end data pathway from field PLCs and RTUs through edge gateways up to {{cloud_ingestion_target}}.
- Evaluate how {{legacy_protocols}} are converted into cloud-native transport payloads (e.g., Sparkplug B over MQTT, OPC UA pub/sub) relative to {{latency_tolerance_ms}}.
- Audit edge gateway deployment models across {{edge_infrastructure}}, identifying compute limits, local buffering capacity, and failover behavior.
- Assess alignment with {{security_zone_model}} (such as ISA/IEC 62443 Purdue Model levels 0 through 4), marking boundary traversal violations or exposed ingress vectors.
- Analyze data reduction and edge filtering mechanisms to prevent cloud saturation while preserving high-frequency anomaly detection fidelity.
- Formulate a risk matrix scoring throughput bottlenecks, single points of failure, and security boundary compromises.
- Provide concrete structural recommendations for message brokers, edge runtimes, and secure reverse-proxy configurations.
Constraints
- MUST evaluate specific architectural trade-offs between edge pre-processing and raw stream transmission.
- MUST NOT recommend solutions that require direct, unbrokered Level 1/Level 2 OT network access from the public cloud.
- All protocol conversions must explicitly address endianness, sampling jitter, and timestamp serialization.
- Maintain focus solely on architectural viability, security posture, and structural scalability.
Output format
- Executive Architecture Summary (150-200 words)
- Ingress & Protocol Topology Evaluation (structured markdown table with: Layer, Protocol, Overhead, Failure Mode)
- Purdue Model Zone Compliance Analysis (3-4 detailed subsections covering Level 1 to Level 4 boundaries)
- Structural Bottlenecks & Failure Domain Assessment (bulleted list of 4-6 critical findings with impact ratings)
- Prescriptive Architectural Blueprint (numbered sequence of 5-7 architectural adjustments)
Self-review
- Did I thoroughly evaluate all protocols listed in {{legacy_protocols}} against {{latency_tolerance_ms}}?
- Are network segmentation boundaries strictly maintained without introducing cloud-direct OT vulnerabilities?
- Is the analysis grounded in deterministic industrial networking realities rather than generic cloud patterns?
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.