Because compromised identities often become the shortest path to escalation and disruption. If attackers can reuse credentials, escalate privileges, or move laterally, identity becomes the bridge between an initial foothold and service impact. That is why IAM and PAM controls must be tested as operational controls, not treated as policy artefacts.
Why This Matters for Security Teams
In critical infrastructure, identity is not just an IT control plane issue. It is often the operational control plane that protects remote access, privileged administration, vendor connectivity, machine-to-machine trust, and incident response access. When identity is compromised, attackers can frequently blend into authorised activity instead of forcing noisy malware behavior. That makes detection slower and containment more difficult. Current guidance from CISA cyber threat advisories repeatedly shows that valid credentials remain a common enabler of intrusion, persistence, and lateral movement.
The stakes are higher in sectors where availability and safety matter as much as confidentiality. A compromised operator account, privileged service account, or remote support identity can affect industrial processes, telemetry, safety tooling, or orchestration systems. This is why identity compromise should be treated as an operational resilience issue, not only a cyber hygiene issue. It also explains why attackers increasingly target password resets, help desk workflows, federated access, and shared administrative paths before they ever touch the core platform. In practice, many security teams encounter the impact of identity compromise only after privileged misuse or service disruption has already occurred, rather than through intentional detection of the attack path.
How It Works in Practice
Identity compromise in critical infrastructure usually follows a chain that is more about trust abuse than technical exploitation. An attacker may steal a password, phish a token, abuse session cookies, or hijack a privileged workflow, then use those legitimate access paths to escalate. In operational technology and hybrid environments, that access may extend into VPNs, jump hosts, SCADA support accounts, engineering workstations, or cloud control planes that support industrial systems.
Practical defense depends on reducing standing privilege, tightening authentication flows, and making privileged access observable. NIST’s identity guidance in NIST SP 800-63B supports phishing-resistant authenticators and strong session management, while the NIST Cybersecurity Framework helps teams connect identity controls to governance, detection, and recovery outcomes. For critical infrastructure, that usually means:
- Separate human, service, and emergency access paths so one compromise does not expose the entire estate.
- Require privileged actions to go through PAM, JIT access, and approval or ticket binding where appropriate.
- Monitor for abnormal identity behavior such as impossible travel, new device use, unusual command execution, and atypical privilege activation.
- Protect machine identities and secrets with the same rigor as human credentials, including rotation, inventory, and scope limitation.
- Test identity recovery procedures, not just login controls, because account takeover often becomes service takeover through reset and delegation paths.
AI-assisted intrusion has made this more urgent. The Anthropic first AI-orchestrated cyber espionage campaign report illustrates how automation can increase the speed and scale of reconnaissance, credential abuse, and post-compromise action. Identity controls must therefore assume faster adversary decision cycles and more adaptive attack chains. These controls tend to break down when legacy OT remote access, shared admin accounts, and emergency override procedures are combined in the same trust domain because accountability and segmentation become too weak to contain misuse.
Common Variations and Edge Cases
Tighter identity control often increases operational friction, requiring organisations to balance availability, maintenance speed, and safety against reduced attack surface. That tradeoff is real in critical infrastructure, where downtime windows are narrow and vendor support can be difficult to redesign. Best practice is evolving, and there is no universal standard for every plant, grid, or utility architecture.
One common edge case is emergency access. Break-glass accounts may be necessary, but they should be isolated, heavily monitored, and time-bound rather than treated as permanent exceptions. Another is service-to-service authentication across hybrid environments. Those identities are easy to overlook, yet they often have broad permissions and weak lifecycle control. A third case is outsourced operations, where third-party access can become indistinguishable from internal admin activity unless logs, approvals, and device trust are enforced. The ENISA Threat Landscape and the Anthropic Project Glasswing materials both reinforce the need to assume rapid adaptation by adversaries and to design controls that can still detect abuse when attackers operate within legitimate access channels.
For regulated operators in Europe, identity compromise also has governance implications under the EU NIS2 Directive, especially where incident reporting, access control, and resilience obligations converge. Current guidance suggests that identity telemetry, privileged session recording, and recovery testing should be treated as core resilience controls, not optional hardening. The hard part is not choosing between perfect lockdown and flexibility, but proving that exceptions remain bounded when real operators, vendors, and machines all need access at once.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA | Identity assurance and access control are central to preventing privileged misuse in critical infrastructure. |
| NIST SP 800-63 | SP 800-63B | Phishing-resistant authentication and session controls reduce takeover risk for high-value identities. |
| NIST AI RMF | AI-enabled intrusion increases the need for governance over identity-related security decisions. | |
| MITRE ATT&CK | T1078 | Valid Accounts is a common way attackers turn stolen identity into lateral movement and disruption. |
| OWASP Non-Human Identity Top 10 | Machine and service identities are often the overlooked bridge attackers use after initial compromise. |
Map human and machine access to PR.AA outcomes and verify who can authenticate, elevate, and recover access.
Related resources from NHI Mgmt Group
- Why do identity attributes matter so much in row-level security and column masking?
- Why do Active Directory controls matter so much for identity security?
- Why do identity and PAM findings matter so much in security scorecards?
- Why do service desk and onboarding processes matter so much in identity security?