Operational technology has different rules.
These systems control physical things, run for years without a restart, and were often specified before the network they now sit on existed. Availability outranks almost everything, a patch window may be annual, and an outage has consequences that are not measured in tickets. IT practice applied without translation causes the incident it was meant to prevent.
The pressure is to connect it, and that is the risk.
Everyone wants the data: utilisation, condition, energy, output. The quickest way to get it is a flat connection between the plant network and the business network, which is also the fastest route for a problem on one to reach the other. The convenient answer and the safe answer are not the same answer.
We separate properly, then move data one way.
Establish what is actually on the operational network, because the inventory is usually incomplete. Segregate it with a controlled boundary rather than a firewall rule added later. Move data outward along a defined path instead of opening access inward. Agree change windows and vendor access on the plant's terms. Then build the reporting on the far side of the boundary.
What you are left with.
An accurate picture of what is connected, a boundary you can describe to an auditor, operational data available for reporting without exposing the systems producing it, and a change process the plant will actually accept.

