Join our Newsletter — 33% off our NHI Course

Why does dormant access in OT still create security risk?

Dormant access is risky because pre-positioned adversaries can wait until a strategic moment to activate it, often after defenders have lost context or attention. In OT, that means access can remain useful long after it first enters the environment, especially when visibility and segmentation are weak.

Why dormant access matters more in OT than it first appears

dormant access creates a long tail of exposure because the permission, remote path, or account may still be valid even after the original business need has faded. In OT environments, that matters because environments change slowly, access reviews lag, and defenders may assume that old access is harmless when it is still technically usable.

OT is also a trust-bound environment: once access exists, it can survive equipment changes, shift handoffs, vendor relationships, and organisational drift. That means the risk is not only that someone could log in today, but that the access can remain ready for a future intrusion path when conditions are more favourable for an attacker.

For a practical baseline on OT security boundaries and segmentation assumptions, NIST SP 800-82 Rev 3 is a useful reference, and CISA’s Industrial Control Systems resources remain a strong operational reference point.

How dormant access turns into an active attack path

Dormant access becomes dangerous when an attacker can wait, observe, and then activate it at a moment that reduces detection or response quality. That is especially effective where visibility is weak, remote access is loosely governed, or shared operational accounts blur attribution and owner responsibility.

The usual failure is not the initial creation of access, but the absence of a hard stop later in the lifecycle. If credentials, VPN paths, or vendor sessions are not aggressively reviewed and retired, they can persist across maintenance cycles and become a ready-made route for lateral movement or privilege escalation once an attacker gains them.

This is why identity-aware remote access controls matter even in industrial settings, and why OT access should be evaluated with the same seriousness as any other privileged pathway. NHIMG’s OT and ICS Identity and Access Guide and Remote Access Identity Guide both address the access patterns that tend to stay hidden until they are abused.

What defenders should treat as the real signal

The signal is not simply whether an account exists, but whether it still has a live path to meaningful OT assets. A dormant account with segmented, time-bound, monitored access is far less concerning than a dormant account that can still reach engineering workstations, remote support tools, or control-adjacent systems without strong verification.

Practitioners should also distinguish between nominal inactivity and real revocation. An account can look unused while still carrying standing privilege, approved exceptions, or unattended vendor access that will reappear the moment a session is re-opened or a credential is replayed.

For access governance and privileged control patterns, the most useful lens is whether the access is still operationally capable of reaching an asset that matters. NHIMG’s Schneider Electric Jira breach 2024 is a reminder that stolen or lingering credentials can remain valuable long after first exposure, while the OWASP Non-Human Identity Top 10 and MITRE ATT&CK Enterprise Matrix help map how access is abused once it is no longer being watched.

Risk and Threat Considerations

Dormant access is attractive to attackers because it offers persistence without immediate noise. In OT, that can let an intruder wait for maintenance windows, incident distraction, or a period of weaker monitoring before reusing access that defenders have mentally retired.

Failure mechanism: stale credentials, remote accounts, or vendor pathways remain technically valid after the original need has passed, while segmentation and logging are too weak to make later activation obvious.

Impact: the access can be reactivated for unauthorized entry, lateral movement, disruption, or covert reconnaissance against systems whose availability and safety matter more than in typical IT environments.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA-05 — Identity Management, Authentication, and Access Control Dormant OT access is an access-control and lifecycle problem.
Recommendation — Enforce access review and revocation for inactive OT accounts and remote paths.
NIST SP 800-53 Rev 5 AC-2 — Account Management Dormant access persists when accounts are not recertified or removed.
Recommendation — Disable or remove accounts that no longer have an approved OT business need.
CIS Controls v8 CIS-5 — Account Management OT dormant access is reduced by disciplined account inventory and removal.
Recommendation — Inventory and eliminate inactive accounts that still reach OT environments.
ISO/IEC 27001:2022 A.5.16 — Identity management OT dormant access depends on whether identities remain governed after use changes.
Recommendation — Maintain identity ownership and periodic review for OT access paths.
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Dormant access often remains because non-human access is not fully retired.
Recommendation — Retire unused OT service and remote-access identities before they can be reused.

Practitioner Guidance

What to prioritise: Focus first on any dormant path that still reaches OT-adjacent remote access, engineering, or privileged administration functions. If the access can still reach a consequential system, treat it as an active exposure, not a housekeeping item.

What to verify: Confirm who owns the access, whether it is still required, whether it is time-bound, and whether monitoring would actually detect re-use. If you cannot prove recent business need and a current control owner, assume the access deserves retirement or re-approval.

Common mistake: teams often review account lists but not effective reach. The important question is not whether the account exists, but whether it can still authenticate into a path that matters and whether anyone would notice if it did.

Practitioner takeaway: In OT, dormant access is risky because it preserves future attacker optionality; your control objective is to make old access either non-functional, tightly bounded, or unmistakably observable before it becomes a convenient entry point.