TL;DR: DORA’s full effect on January 17, 2025 puts infrastructure access, incident reporting, and third-party risk back under regulatory scrutiny, according to Teleport. The compliance problem is not a lack of controls in theory, but the mismatch between static credentials, sprawling infrastructure, and audit demands that assume access can be cleanly bounded.
At a glance
What this is: This is a Teleport blog post arguing that DORA compliance depends heavily on reducing static credentials, improving access visibility, and proving operational resilience across complex infrastructure.
Why it matters: It matters because IAM, PAM, and NHI teams must show that access controls, logging, and third-party oversight work across on-prem, cloud, and ephemeral environments under regulatory pressure.
👉 Read Teleport's blog post on simplifying DORA compliance for infrastructure access
Context
DORA is a resilience and governance problem, not just a compliance deadline. For identity teams, the hard part is proving that infrastructure access is controlled, observable, and recoverable across mixed environments where static credentials and standing privilege are still common.
Teleport frames the issue around financial institutions and the ICT providers that support them: both must demonstrate access control, monitoring, incident response, and third-party oversight. That places NHI governance, privileged access, and audit evidence squarely inside the DORA control surface.
The article’s core claim is that traditional access patterns do not scale cleanly to the audit and reporting expectations DORA imposes. The result is a gap between what teams can operate and what regulators may expect them to prove.
Key questions
Q: How should security teams reduce DORA risk in infrastructure access paths?
A: Security teams should reduce DORA risk by removing persistent credentials from privileged workflows and replacing them with session-scoped access that can be logged, revoked, and audited. The goal is not only stronger security, but evidence that access was proportionate, time-bound, and governed across the full infrastructure estate.
Q: Why do static credentials create problems for DORA compliance?
A: Static credentials create problems because they extend access beyond the task, obscure who used them, and make revocation and audit evidence harder to prove. Under DORA, that creates a mismatch between operational reality and the regulatory expectation for resilient, controlled, and reportable access.
Q: What breaks when standing privileges are left in place for cloud infrastructure changes?
A: Standing privileges increase the chance that a routine change can affect shared systems far beyond the intended task. In cloud environments, that can turn one valid administrative action into a production outage, a security incident, or both. The problem is not just misuse by attackers. Persistent access expands the blast radius of legitimate work.
Q: Who is accountable for ICT risk management under DORA?
A: Senior management is accountable, with regulated entities expected to assign clear responsibilities for ICT risk oversight, reporting, and resilience testing. In practice, that accountability extends to access governance because identity failures can trigger incidents, supplier exposure, and recovery problems. The board cannot delegate away the evidence requirement.
Technical breakdown
Why static credentials create DORA exposure
DORA assumes organisations can control and evidence access to critical systems with enough precision to support resilience, incident handling, and auditability. Static passwords, SSH keys, and long-lived tokens make that difficult because they expand the credential lifecycle far beyond the session or task that needs access. In blended infrastructure, those credentials often span on-prem, cloud, and ephemeral components, which makes traceability and revocation uneven. The operational issue is not merely exposure, but the inability to prove who had access, for how long, and under what context.
Practical implication: replace persistent secrets with short-lived, traceable access patterns where audit evidence can be produced on demand.
How dynamic access controls map to resilience requirements
Dynamic access control changes the identity model from always-on privilege to session-scoped authorisation. That matters under DORA because access should be constrained to need, context, and duration, then expire automatically. This does not eliminate the need for policy. It shifts policy from static entitlement lists to governance over session issuance, logging, and revocation. For infrastructure teams, the technical challenge is proving that least privilege is enforced across heterogeneous systems without relying on manual exception handling.
Practical implication: align access governance with session expiry, policy enforcement, and central logging across all infrastructure estates.
Why monitoring and audit logs are part of the control, not an afterthought
DORA places reporting and incident response alongside prevention because resilience depends on detection, evidence, and action. Real-time monitoring and immutable access logs turn identity events into operational proof, especially when organisations must explain abnormal access, unusual locations, or revoked sessions. In NHI and PAM terms, logs are not just forensic artefacts. They are the control plane that shows whether access policy is actually being enforced across a changing infrastructure footprint.
Practical implication: treat access logs, anomaly detection, and revocation records as compliance evidence that must be continuously available.
Threat narrative
Attacker objective: The attacker aims to exploit long-lived infrastructure access to cause operational disruption, preserve access, or evade accountability in a regulated environment.
- Entry begins with static credentials, such as passwords, SSH keys, or tokens, that give access to infrastructure components without strong session boundaries.
- Escalation follows when standing privilege and fragmented controls let an attacker move through cloud-native and on-prem systems with insufficient revocation visibility.
- Impact is achieved when the attacker disrupts operations, extracts data, or weakens resilience in ways that are difficult to prove or contain quickly under regulatory scrutiny.
Breaches seen in the wild
- MongoBleed breach — MongoBleed exposed secrets across 87K MongoDB servers.
- IOS app secrets leakage report — iOS apps leaking hardcoded secrets and credentials endangering user privacy.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Static infrastructure credentials are a DORA liability, not just a hygiene issue. DORA expects organisations to evidence controlled access, incident response, and resilience across operational environments. Static passwords, SSH keys, and tokens make those requirements harder to prove because they outlive the session, the operator, and sometimes the system they were meant to protect. The practitioner conclusion is simple: if access cannot be bounded and evidenced, compliance becomes fragile.
Standing privilege is the control gap DORA exposes most clearly. The article’s focus on eliminating standing access aligns with a deeper governance problem: persistent privilege makes it impossible to demonstrate that access is proportionate to task, context, and time. Under DORA, that gap affects both the financial institution and the ICT provider because third-party access can become a compliance failure path. Teams should treat privilege persistence as an audit finding, not a configuration detail.
Centralised access visibility is now part of resilience architecture. DORA links monitoring, incident reporting, and operational continuity, which means logs are not secondary evidence but a core control surface. If organisations cannot reconstruct who accessed what, when, and from where, they cannot credibly show resilience under disruption. Practitioners should view access telemetry as part of the control chain, not just the detective layer.
Identity governance for DORA is increasingly a third-party discipline. The regulation does not stop at the institution boundary. It reaches the ICT suppliers, software vendors, and service providers whose access patterns can affect regulated operations. That means contract lifecycle, access offboarding, and proof of secure access become governance obligations, not optional vendor management tasks. The practical conclusion is to align NHI and PAM controls across the full service chain.
From our research:
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems, according to The 2026 Infrastructure Identity Survey.
- That same survey found that 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
- For a deeper governance lens, see Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs for lifecycle control patterns that also apply to privileged infrastructure access.
What this signals
Standing access will become harder to justify as resilience and audit expectations converge. DORA-style scrutiny pushes teams toward evidence-rich access models where every privileged session can be explained after the fact. That changes programme design from entitlement management to proof management, which is a materially different operating model for IAM and PAM teams.
Identity evidence must become portable across teams and suppliers. When regulated firms depend on third-party infrastructure providers, access records, offboarding proof, and session logs need to survive organisational boundaries. The practical signal is that access governance will increasingly be judged by how well it travels across the service chain, not by how neatly it sits inside one tool.
Least privilege is moving from principle to measurable operating requirement. With 70% of organisations already granting AI systems more access than human employees in our research, access excess is not an edge case. For security programmes, that makes privilege scope, expiry, and logging the controls most likely to influence both resilience and regulatory defensibility.
For practitioners
- Inventory every static infrastructure credential Map passwords, SSH keys, and long-lived tokens across on-prem, cloud, and Kubernetes estates, then classify which ones support regulated or privileged access. Prioritise any credential that cannot be tied to a named owner, a session, or a clear expiry path.
- Replace standing privilege with session-scoped access Use short-lived certificates or equivalent ephemeral access mechanisms for administrative and operational tasks. Enforce automatic expiry after each session and require re-issuance for the next task so that access can be explained and revoked cleanly.
Key takeaways
- DORA turns infrastructure access into a resilience and evidence problem, not just a compliance checkbox.
- Static credentials and standing privilege create the clearest gap between what organisations operate and what they must prove.
- Teams that cannot produce session-level access evidence will struggle to show both operational resilience and audit readiness.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the technical controls, while DORA and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | DORA access control and least privilege map directly to identity and access management outcomes. |
| NIST SP 800-53 Rev 5 | IA-5 | Static credential replacement and certificate-based access align with authenticator management. |
| NIST Zero Trust (SP 800-207) | The article’s session-based access model aligns with zero trust, continuous verification, and least privilege. | |
| DORA | ICT risk management | The article is explicitly about DORA compliance, resilience, reporting, and third-party risk. |
| ISO/IEC 27001:2022 | A.5.15 | Access control governance is central to the article’s compliance argument. |
Use zero-trust principles to make every privileged session explicit, time-bound, and continuously validated.
Key terms
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Ephemeral certificate: A short-lived digital credential issued for a current session rather than stored for long-term reuse. In connected OT environments, ephemeral certificates reduce the value of stolen credentials and provide a cleaner control point for remote authentication and revocation.
- ICT Risk Management Framework: A structured set of governance, technical, and operational controls used to identify, monitor, and reduce risk from information and communication technology. For DORA, it must cover internal systems, third-party dependencies, reporting, and recovery in a way regulators can assess.
What's in the full article
Teleport's full blog post covers the operational detail this post intentionally leaves for the source:
- A control-by-control walkthrough of how its infrastructure access model maps to DORA requirements.
- Examples of how ephemeral certificates replace passwords, SSH keys, and static tokens in privileged workflows.
- A compliance-oriented view of logging, monitoring, and audit evidence for regulated infrastructure estates.
- The vendor's framing of how its platform is positioned for financial institutions and ICT providers under DORA.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or PAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org