When identity governance lags behind regulatory expectations, organisations can face fines, insurance problems, reputational damage, and operational instability. In critical infrastructure, weak identity controls also undermine incident response and resilience because teams cannot reliably prove who has access, why they have it, or whether access is still appropriate.
Regulatory Failure Is an Access-Control Problem, Not Just a Compliance Problem
When critical infrastructure organisations fail to align identity governance with regulatory obligations, the issue is usually not paperwork alone. Regulators expect access to be bounded, reviewed, revocable, and traceable, because those properties support safety, resilience, and incident response. If access reviews are stale or ownership is unclear, the organisation may be unable to demonstrate who can change operational systems, approve exceptions, or recover from an incident in a controlled way. The Ultimate Guide to NHIs — Regulatory and Audit Perspectives is useful here because it connects governance failure to auditability and lifecycle control, not merely account hygiene.
In practice, the regulatory gap becomes material when identity data, privilege evidence, and operational ownership do not line up, and teams discover that their control narrative is weaker than their environment.
How the Gap Shows Up in Operations
Critical infrastructure environments tend to accumulate exceptions: emergency access, shared administrative paths, vendor connections, service accounts, and long-lived credentials that were never fully retired. Good identity governance should keep those paths visible and justified, but regulatory obligations usually require more than visibility. They require evidence that access is proportionate to function, reviewed at defined intervals, and removed when no longer needed. This is where governance and operations meet. If the organisation cannot prove that a maintenance contractor, control-system engineer, or automation account still has a valid business basis, the regulator sees unmanaged privilege, even if no incident has occurred.
The operational problem is that identity governance data often sits apart from asset inventories, OT change records, and incident processes. That separation makes it hard to answer basic questions during an audit or outage: who approved the access, what system depends on it, when it was last reviewed, and what breaks if it is revoked. The NHIMG Ultimate Guide to NHIs is relevant because it shows how lifecycle failures, excessive privilege, and missing visibility compound over time rather than appearing as isolated control gaps. NIST CSF 2.0 also remains relevant as a governance frame for identifying, protecting, detecting, responding, and recovering across the broader operational picture.
- Map every privileged identity to a named owner and an operational purpose.
- Align review cycles to the real change cadence of plant, grid, or transport systems.
- Separate break-glass access from standing administrative access so exceptions remain auditable.
- Retire access paths that cannot be justified with current business or safety need.
These controls tend to break down in legacy and mixed IT-OT estates because identity records, system ownership, and change control are often maintained in different tools and by different teams.
What Regulators and Operators Commonly Underestimate
Tighter identity governance often increases operational overhead, requiring organisations to balance assurance against the speed needed in critical operations. The hardest trade-off is that highly available environments still need fast restoration, vendor support, and emergency intervention, but those needs do not remove the requirement for accountability. The result is not that every access path must be eliminated; it is that each one must be defensible, time-bound, and reviewable. Where organisations struggle is assuming that if access was once justified, it remains justified indefinitely. That assumption fails most often after role changes, contract changes, equipment modernisation, or incident-driven privilege expansion.
Regulators and internal auditors also tend to underestimate how much risk is created by weak evidence rather than weak intent. A team may believe it has good governance because approvals exist somewhere, yet cannot produce timely proof of current access scope or revocation history. That evidence gap matters because it undermines trust in the control environment and can delay recovery decisions during outages. For infrastructure operators, the practical question is not whether identity governance exists in policy, but whether it can withstand scrutiny when a high-impact change or incident forces immediate inspection.
Organisations that treat identity governance as a periodic compliance exercise usually discover that the weakest point is not the policy text but the inability to prove control at the moment it matters.
Risk and Threat Considerations
Failure to align identity governance with regulatory obligations creates both compliance exposure and operational security exposure. In critical infrastructure, excessive or unreviewed access can become a resilience issue because privileged identities can alter configurations, disable safeguards, or slow incident containment.
Failure mechanism: Misaligned governance leaves standing privilege, orphaned access, and weak revocation paths in place; attackers and insiders can then abuse legitimate identities, while auditors and responders lack reliable evidence to distinguish approved access from unsafe access.
Impact: The organisation can face enforcement action, delayed recovery, broader blast radius during incidents, and loss of confidence in operational controls that underpin safety and continuity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while NIS2, DORA and EU Cyber Resilience Act define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIS2 | Art. 21 — Cybersecurity Risk-Management Measures | Critical infrastructure identity governance supports required risk-management and access control measures. |
| Recommendation — Align identity reviews and revocation evidence to Art. 21 risk-management obligations. | ||
| DORA | Art. 9 — Protection and Prevention | Operational resilience depends on controlled privileged access and timely removal of stale access. |
| Recommendation — Tie privileged access governance to protection and prevention controls for resilience. | ||
| EU Cyber Resilience Act | Art. 13 — Vulnerability Handling and Security by Design | Identity control gaps can undermine secure operation and lifecycle handling in connected products. |
| Recommendation — Build identity governance into secure-by-design and vulnerability handling processes. | ||
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication, and Access Control | The question centers on access control alignment, review, and revocation evidence. |
| Recommendation — Apply PR.AC controls to bound, review, and revoke privileged access. | ||
| CIS Controls v8 | 6 — Access Control Management | Prescriptive access control safeguards directly address stale privilege and ownership gaps. |
| Recommendation — Implement CIS Control 6 to inventory, approve, and remove unnecessary access. | ||
Practitioner Guidance
What to prioritise: Start with identities that can change production operations, safety settings, incident tooling, or vendor connectivity. If those accounts lack clear ownership, review dates, and revocation evidence, treat them as a governance and resilience issue rather than a documentation task.
What to verify: Confirm that each privileged identity has a current business justification, an accountable owner, an expiry or review trigger, and a traceable approval path. If any of those elements are missing, the control is not yet audit-ready, regardless of whether the account is rarely used.
Practitioner takeaway: The real test is whether identity governance can prove, in near real time, that access is both necessary and reversible without disrupting critical operations.
Related resources from NHI Mgmt Group
- What happens when organisations try to meet cyber insurance or regulatory identity requirements without unified enforcement?
- What is the relationship between identity governance and regulatory compliance in practice?
- How should organisations approach identity governance when they want both open source control and digital sovereignty?
- What happens when organisations try to reduce identity security spend without fixing control gaps?