By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: RSA SecurityPublished September 2, 2026

TL;DR: Australia’s updated SOCI rules now require phishing-resistant authentication, least privilege, and access review capability that continues to work for up to 90 days in isolated critical infrastructure environments, according to RSA Security’s analysis. The governance shift is bigger than MFA selection: cloud-only identity assumptions no longer satisfy resilience, recovery, or audit expectations.


At a glance

What this is: This is RSA Security’s analysis of how SOCI 8B and 8C change authentication and access governance for critical infrastructure, with phishing-resistant MFA and isolation resilience as the core findings.

Why it matters: It matters because IAM teams now have to design authentication, privileged access, and review processes that survive cloud outages and isolation events in OT and critical infrastructure environments.

By the numbers:

👉 Read RSA Security’s analysis of SOCI 8B and 8C identity obligations for critical infrastructure


Context

SOCI 8B and 8C are reshaping how critical infrastructure teams think about identity security because the rules now tie authentication and access control directly to resilience under isolation. In practice, that means phishing-resistant MFA, least privilege, and access review are no longer separate governance themes; they are part of the same operational obligation for critical systems and remote access.

The primary problem is not whether a control exists in normal conditions. It is whether the control still works when the environment is disconnected, recovering, or constrained by OT realities. For IAM, PAM, and governance teams, the issue is continuity of identity assurance under isolation, not just access assurance during steady state.

This makes the article most relevant to organisations with critical infrastructure exposure, especially where cloud-dependent identity services have been assumed to be sufficient. That assumption is increasingly atypical for regulated CI environments.


Key questions

Q: What breaks when cloud-only MFA is used for isolated critical infrastructure?

A: Cloud-only MFA breaks the continuity of identity assurance when the environment is disconnected. Operators can be locked out of critical systems exactly when they need to restore service, which turns authentication into a recovery dependency instead of a control. In regulated critical infrastructure, that failure undermines both compliance and operational resilience.

Q: Why does SOCI 8C make least privilege a recovery issue?

A: Because lateral movement risk rises during isolation and rebuild, when privileged access can expand the blast radius of compromise. If access is not tightly scoped and reviewed, recovery teams may preserve the same paths attackers would abuse. The control objective is to keep critical systems usable without leaving standing privilege in place.

Q: How can security teams tell whether their phishing-resistant MFA model is actually compliant?

A: They need to test whether the authenticators, directories, and policy services remain available without external cloud access and still support the required user and admin flows. If the control only works in connected conditions, it is not resilient enough for SOCI-style isolation requirements. Compliance depends on operational continuity, not product labels.

Q: Which controls matter most when a critical infrastructure environment is being restored after compromise?

A: Authentication continuity, least privilege, and access review matter most because recovery is when identity weaknesses become operationally visible. Teams need controls that keep users authenticated, restrict lateral movement, and prove entitlement scope while rebuild work is underway. That is the governance model SOCI is pushing toward.


Technical breakdown

Phishing-resistant MFA in isolated critical infrastructure

Phishing-resistant MFA uses cryptographic authenticators rather than reusable secrets or push approvals that can be intercepted or socially engineered. In the SOCI context, the control is not only about strong login. It must also remain functional for internet-connected systems, privileged and unprivileged access, and remote access paths when connectivity to external identity services is unavailable. That changes the design problem from user verification to authentication continuity across constrained environments. Cloud-backed MFA services can satisfy a normal operating model but fail the isolation model if the identity dependency cannot survive a disconnected state.

Practical implication: treat authentication survivability in isolation as part of control design, not as a fallback scenario.

Least privilege and access review under section 8C

Section 8C ties lateral movement resistance to governance processes that identify who has access to what, how roles are assigned, and how those entitlements are reviewed. That matters because isolation and recovery periods are exactly when standing access becomes dangerous if it has never been rationalised. Least privilege is not just a policy label here. It is the operational boundary that limits which accounts can reach critical systems while recovery work is underway. Access review becomes the mechanism that proves the boundary is deliberate rather than inherited.

Practical implication: align privileged and non-privileged entitlements to a review cycle that can still be executed during recovery.

Hybrid failover as an identity control plane issue

The article highlights a common failure mode in critical infrastructure: identity services are often treated as external utilities rather than survivable control plane components. If the MFA provider depends entirely on the cloud, then isolation breaks authentication even when the local systems are otherwise functional. Hybrid failover shifts the question from availability of the identity vendor to availability of the authentication control itself. For OT and CI environments, that distinction is central because rebuilding systems after compromise requires the strongest controls to remain intact, not vanish at the point of recovery.

Practical implication: map every critical authentication dependency to its isolated-state behaviour before accepting it as compliant.


Threat narrative

Attacker objective: The attacker objective is to move laterally across critical infrastructure while identity controls are weakest during recovery or isolation.

  1. Entry occurs through identity-dependent access paths that remain reachable during normal operations but become fragile when cloud connectivity is removed.
  2. Escalation is enabled when standing access or weakly governed privileged paths allow lateral movement across critical systems during recovery.
  3. Impact is operational disruption, because teams cannot maintain or restore trustworthy authentication and access control while isolated.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity controls designed for connected environments fail when regulation assumes isolation. SOCI 8B and 8C make a simple point that many IAM programmes have avoided: authentication is not complete unless it survives the disconnected state. The governance assumption that cloud services are always available is no longer acceptable in high-risk critical infrastructure. Practitioners should treat survivable identity control as a design constraint, not an exception path.

Phishing-resistant MFA is only compliant if the control remains operational when the network does not. The article exposes a common mismatch between control intent and deployment reality. A method can be phishing-resistant on paper yet still fail the SOCI requirement if the authentication service itself is unavailable during isolation. The implication is that control assurance now includes environmental resilience, not just cryptographic strength.

8C turns least privilege into a recovery control, not just a governance principle. The requirement to keep critical systems operational while other systems are being restored changes the meaning of access review and role management. Excess privilege is not only a breach risk, it is a recovery risk because uncontrolled access increases the chance of lateral movement during rebuild. Practitioners should reassess entitlement design through recovery-time exposure, not steady-state convenience.

Cloud-only identity dependency is a structural weakness for critical infrastructure. When authentication, governance, and recovery all depend on an external cloud service, isolation becomes an access outage. That is not merely an availability issue. It is a governance failure because the organisation can no longer prove continuous control over critical systems. The practical conclusion is that CI identity architectures need local survivability, not just federation convenience.

Named concept: isolation-safe identity assurance. This article sharpens a useful concept for the field: identity assurance must remain valid while systems are isolated, recovered, and partially rebuilt. That is a different bar from normal MFA or normal PAM. Practitioners should use this lens when evaluating whether identity controls support regulated operational continuity, not just user login.

From our research:

What this signals

Isolation-safe identity assurance: SOCI 8B and 8C are a reminder that identity control is only real when it survives disconnected operations. That should push critical infrastructure teams to evaluate whether MFA, governance, and recovery workflows remain functional without external identity dependencies, not just whether they pass normal-state audits.

The governance signal is clear for IAM and PAM teams: recovery-time access scope now matters as much as steady-state access scope. If your reviews, role design, and admin paths are built only for connected environments, they are not yet aligned to the operational conditions regulators are now expecting.

The NIST Cybersecurity Framework 2.0 is still useful here because the issue spans protect, detect, respond, and recover. The practical challenge is translating those functions into identity controls that continue to operate when the environment is partially rebuilt, isolated, or otherwise constrained.


For practitioners

  • Map every authentication dependency to isolation behaviour Document whether MFA, directory, and governance services still operate when cloud connectivity is removed for up to 90 days. Separate controls that remain local from controls that silently fail over to an external provider.
  • Re-test phishing-resistant MFA against OT recovery conditions Validate that phishing-resistant authentication works for privileged, unprivileged, and remote access paths when critical infrastructure is segmented or air-gapped. Treat test results as a compliance input, not a lab exercise.
  • Rebuild access review for lateral movement resistance Tie access certification to the accounts that can reach critical systems during restoration. Focus on standing privilege, remote admin paths, and roles that would expand blast radius during rebuild.
  • Design hybrid failover for the authentication control plane Ensure identity services can continue in on-premises or semi air-gapped mode without depending on live cloud authentication. The control must remain available while other systems are in restoration or recovery.

Key takeaways

  • SOCI 8B and 8C turn identity controls into resilience controls for critical infrastructure, not just authentication policies.
  • Cloud-only identity dependencies are now a compliance problem when the regulated environment must keep operating while isolated.
  • Teams that can prove authentication continuity, least privilege, and access review during recovery will be closer to meeting the new obligation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1The article is about identity assurance and access control in critical infrastructure.
Map authentication and access governance to PR.AC-1 and verify it still works during isolation.
NIST SP 800-53 Rev 5IA-2Phishing-resistant authentication for critical systems aligns directly to identification and authentication.
Apply IA-2 to require resilient phishing-resistant authentication for critical access paths.
NIST Zero Trust (SP 800-207)The article’s isolation and continuous verification themes fit Zero Trust principles.
Treat identity and access decisions as continuous controls that must survive disconnected operation.
ISO/IEC 27001:2022A.5.15Access control governance is directly implicated by least-privilege and review obligations.
Align access governance with A.5.15 and test it under isolation and recovery scenarios.

Treat identity and access decisions as continuous controls that must survive disconnected operation.


Key terms

  • Phishing-Resistant MFA: Phishing-resistant MFA uses authentication factors that cannot be easily replayed, intercepted, or socially engineered. In regulated environments, this usually means device-bound or cryptographic methods rather than push prompts or SMS codes, because the control must hold up under realistic attack conditions.
  • Isolation-safe identity assurance: Isolation-safe identity assurance is the ability to keep authentication and access governance operating when systems are disconnected from external services. It extends beyond strong login to include continuity of directory, policy, and recovery functions so regulated environments can remain controlled while they are segmented or rebuilt.
  • Lateral movement hazard: A lateral movement hazard is any access path, entitlement, or recovery condition that allows an attacker or unauthorized operator to move across systems after initial compromise. In critical infrastructure, it is especially dangerous during restoration because standing privilege and over-broad roles can widen the blast radius of an incident.
  • Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.

What's in the full article

RSA Security's full post covers the operational detail this post intentionally leaves for the source:

  • The clause-by-clause mapping of SOCI 8B and 8C obligations to identity and governance controls.
  • The specific deployment model for phishing-resistant MFA in on-premises, air-gapped, and semi air-gapped environments.
  • The access review and least-privilege implications for critical systems during recovery and isolation.
  • The practical rationale behind hybrid failover for maintaining authentication during cloud outages.

👉 The full RSA Security post covers the clause mapping, hybrid failover model, and recovery-time access control detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 4, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org