They should use governed, identity-based access that is tightly scoped to the required OT asset and supported by segmentation that can survive degraded connectivity. The operational goal is not to pretend no route exists, but to make any route deliberate, observable and reversible. That approach supports both continuity and containment.
Access Control Is Only Half the Problem in Critical Infrastructure
For critical infrastructure, the hard part is not choosing between access and isolation. It is designing access so operators can still perform required actions without collapsing the containment boundary. That usually means tightly scoped, governed access paths, with segmentation that limits spread if a remote path, jump host, vendor connection, or engineering account is compromised.
The access path should be treated as a controlled operational dependency, not a convenience layer. If it is broad, persistent, or difficult to audit, it becomes a shared failure point across reliability and security.
Why Deliberate, Observable Access Beats Broad Connectivity
Critical infrastructure environments often need remote support, maintenance, and exception handling, but every added route changes the blast radius. The better design choice is to make each route explicit, constrained to the required OT asset, and revocable without rebuilding the whole network. That is how teams preserve continuity while keeping the environment contained.
In practice, this means access should be tied to a specific business or operational need, not to a generic subnet, site-wide trust zone, or standing remote session. When the route cannot be justified at asset level, it is usually too broad to be safe.
For identity-based access patterns in operational environments, the access decision is only trustworthy if the route and the authority behind it are both bounded. Guidance for governed machine and service access in broader identity programs makes the same point: scope the credential, scope the destination, and reduce unnecessary reuse of access paths. The Colonial Pipeline ransomware attack remains a useful reminder that an unused remote-access path can become a high-impact entry point when it is left outside normal governance.
Segmentation Must Still Work When Connectivity Degrades
The containment side of the design cannot assume ideal conditions. In critical infrastructure, networks fail, links degrade, and operational staff may need fallback paths to keep systems safe or stable. Segmentation therefore has to survive partial outages, not just normal-state policy checks. If isolation disappears the moment a control plane is unavailable, the architecture is not resilient enough.
That is why teams should prefer segmentation models that degrade safely, with predictable fail states, clear zone boundaries, and monitored exceptions. The goal is not perfect separation at all times, but separation that remains meaningful when infrastructure is under stress.
External guidance for critical sectors and industrial environments reinforces this operating model. CISA Industrial Control Systems resources emphasize that OT controls have to fit availability and safety realities, while still limiting exposure. CISA cyber threat advisories also show why exposed remote access and weak boundary control remain recurring operational risks. ENISA threat landscape reports likewise consistently place critical infrastructure among the environments where exposure, persistence, and disruption matter most.
What Good Looks Like When Operations Need Both Reach and Containment
The best pattern is governed access with narrow authority, a defined time window, and a clear target asset, combined with segmentation that limits what else can be reached if the session is abused. Access should be reversible, auditable, and attributable, while the network boundary should continue to enforce separation even if one control layer is impaired.
Teams should also avoid designing for permanent exceptions. Once a remote route, vendor tunnel, or bypass path becomes routine, it stops being an exception and starts becoming part of the attack surface. That is the point where containment and continuity begin to drift apart.
For practitioners, the most useful benchmark is not whether a connection exists, but whether it is specific, time-bounded, monitored, and removable without broad operational fallout. When those conditions are missing, the environment is already trading away containment to preserve convenience.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-4 — Information Flow Enforcement | Preserves OT boundary enforcement while allowing necessary operational access. |
| AC-6 — Least Privilege | Limits operator and support access to the minimum needed for the OT task. | |
| IA-2 — Identification and Authentication (Organizational Users) | Supports governed, attributable access for human operators in critical environments. | |
| Recommendation — Enforce controlled information flows between zones and named assets. Constrain access paths and entitlements to the minimum operational need. Authenticate operators before allowing access to sensitive OT functions. | ||
| ISO/IEC 27001:2022 | A.8.20 — Network security | Directly applies to segmentation and boundary protection in critical infrastructure. |
| Recommendation — Implement network segmentation and boundary controls for OT environments. | ||
| CIS Controls v8 | CIS-4 — Secure Configuration of Enterprise Assets and Software | Segmentation and constrained routes depend on hardened, controlled configurations. |
| Recommendation — Harden and standardize remote access and segmentation configurations. | ||
Practitioner Guidance
What to prioritise: Start with the highest-consequence OT assets and the paths that can reach them, then verify whether each path is genuinely required for operations or only inherited from older support models.
What to verify: Confirm that every privileged route can be revoked independently, that segmentation still limits lateral movement during partial outages, and that access logs identify the exact asset and operator involved.
Decision rule: If a path cannot be scoped to a named operational need and a named asset, treat it as too broad for a critical environment, even if it is currently convenient.
Practitioner takeaway: The right balance is not “more access” or “more isolation”, it is access that is narrow enough to be defensible and isolation that remains real when the environment is under stress.
Related resources from NHI Mgmt Group
- How should security teams run access reviews for non-human identities?
- How should security teams govern non-human identities that have persistent access?
- How should security teams govern API keys used for generative AI access?
- How should critical infrastructure teams manage privileged access across human operators and non-human identities?