TL;DR: Water utilities face elevated cyber risk because remote vendor access, default credentials, shared accounts, and limited centralised control still create easy paths into operational technology, according to StrongDM’s discussion of the NIST NCCoE water and wastewater reference design. The governance problem is not connectivity itself but whether access can be bounded, monitored, and revoked without weakening operations.
At a glance
What this is: This is an analysis of water utility OT cybersecurity that finds vendor access, default credentials and ad hoc remote entry remain the main governance gaps.
Why it matters: It matters because OT environments still rely on access patterns that are hard to constrain, which makes IAM, PAM and lifecycle control central to protecting critical infrastructure.
Context
Water utility cybersecurity is an access-governance problem as much as a perimeter problem. The article focuses on how remote vendor entry, shared credentials and weak central oversight create control gaps inside operational technology environments, where uptime pressures often override standard identity discipline.
For IAM and PAM teams, the key issue is whether access can be issued, monitored and removed with enough precision to avoid standing privilege and unmanaged vendor pathways. In a water utility context, those identity decisions affect not only remote support but also the reliability of critical services.
Key questions
Q: What breaks when water utilities rely on vendor access without OT identity governance?
A: The control gap is that external support becomes a standing access path instead of a task-specific exception. That breaks accountability, makes revocation slow and leaves utilities unable to prove who touched which OT asset during routine maintenance or incident response.
Q: Why do shared OT accounts increase risk in critical infrastructure environments?
A: Shared accounts erase attribution and let several people act through the same credential, which means no one can tell which operator, contractor or attacker performed a sensitive action. In OT, that creates both security risk and forensic ambiguity.
Q: How should utilities phase out default credentials in OT systems?
A: Start by inventorying devices that still ship with vendor or inherited defaults, then replace them with uniquely owned credentials and a recovery process that does not depend on the original shared secret. The goal is to remove known footholds before broader access redesign.
Q: What should security teams do when remote vendor access is already embedded in OT operations?
A: They should bring that access into one policy layer, define which actions are allowed on which systems and ensure every session is logged and revocable. If vendor access remains ad hoc, OT risk will stay permanently elevated.
Technical breakdown
Why remote vendor access becomes an OT control gap
Operational technology environments often depend on outside vendors for maintenance, patching and troubleshooting, but that support path is usually built around long-lived remote entry. When access is provided through VPNs or jump hosts without strict governance, the identity path itself becomes a standing exposure surface. The problem is not simply that remote access exists. It is that OT access often outlives the task, lacks granular session control and becomes difficult to distinguish from legitimate operator activity. In water utilities, that mismatch between operational dependency and access governance is what creates durable risk.
Practical implication: replace broad vendor entry paths with task-bounded access that is logged, scoped and revoked at the end of the maintenance need.
Default and shared credentials in OT devices
Default credentials are dangerous in OT because they convert device access into a known and repeatable control failure. Shared accounts make the problem worse by removing accountability, so one credential can be reused across people, vendors or service functions without a meaningful audit trail. In critical infrastructure, that means an attacker does not need to defeat a sophisticated identity system if the baseline credential state is already weak. The article points to this as a core scenario in the NCCoE work because device-level authentication weakness quickly becomes infrastructure-level exposure.
Practical implication: eliminate default and shared OT credentials first, then tie each remaining account to a named owner, device scope and review cadence.
Why centralised access control matters more than convenience
Centralised access control is not just an administrative preference. It is what allows utilities to decide who can connect, what they can reach and how their actions are monitored across a distributed OT estate. Without it, individual credentials and ad hoc approvals proliferate, making revocation slow and forensics incomplete. In identity terms, the control failure is fragmented authority: no single policy plane can enforce least privilege across vendor, operator and emergency access paths. That is why the article treats central policy, monitoring and logging as part of the defensive model rather than as optional visibility features.
Practical implication: consolidate OT access decisions into one policy layer so vendor, operator and emergency pathways share the same enforcement and audit model.
Threat narrative
Attacker objective: The attacker aims to gain durable access to OT systems in a way that enables disruption, manipulation or persistence inside critical water infrastructure.
- Entry occurs through remote vendor access paths, especially when those paths depend on VPNs, jump hosts or unmanaged shared credentials.
- Credential abuse follows when default or individual accounts are reused without strong central oversight, creating a foothold that is difficult to attribute or contain.
- Impact comes from unauthorized or over-broad access to OT systems, which can threaten service reliability, incident response quality and the integrity of critical water operations.
Breaches seen in the wild
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
- CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Vendor access is the governance boundary that OT security often fails to treat as identity infrastructure. Water utilities do not just have a connectivity problem. They have a lifecycle problem, because outside support paths frequently remain active longer than the work they are meant to enable. That makes vendor access a standing identity issue, not a temporary operational convenience. The practitioner conclusion is simple: if the access path cannot be bounded, it is already an exposure path.
Default credentials and shared OT accounts are not legacy nuisances, they are attack assumptions. In a water utility, these accounts erase accountability and flatten the difference between a legitimate operator, a contractor and an intruder. Once multiple parties can act through the same credential, incident reconstruction becomes guesswork. The practitioner conclusion is that identity ownership must be explicit even in environments that were historically engineered for availability first.
Centralised policy enforcement is the only way to make OT access governable at scale. The article’s core pattern is fragmented access, where vendor entry, emergency support and routine administration are managed differently and often inconsistently. That fragmentation prevents least privilege from being applied consistently across assets, sessions and actors. The practitioner conclusion is to treat OT access policy as a single control plane rather than a collection of exceptions.
Water utility cybersecurity exposes the limits of access models built around static trust. The White House warning and the NCCoE reference design both point to the same reality: critical infrastructure cannot rely on broad, manually managed access paths and still claim mature identity governance. The implication is broader than one sector. Any programme that still treats vendor connectivity as separate from IAM and PAM is carrying avoidable governance debt. The practitioner conclusion is to close that gap before it becomes an operational incident.
Task-scoped access is the named concept this article reinforces for critical infrastructure. Water utilities need support paths that exist only for the work being performed, not as semi-permanent administrative lanes. That is what turns vendor access from a hidden trust extension into a controlled operational control. The practitioner conclusion is to design OT access around discrete tasks, not open-ended support relationships.
What this signals
Task-scoped access is the control shift that matters most here: OT programmes cannot keep treating vendor support as a durable trust relationship. When the maintenance need ends, the access path should end with it, otherwise the utility inherits standing exposure that is hard to audit or contain.
Water utilities should expect identity and access governance to move closer to operational reliability conversations. In practice, that means PAM, session logging and credential ownership are no longer back-office controls, they are part of how critical service continuity is defended.
For practitioners
- Tighten vendor support pathways Map every external maintenance path into a single inventory that shows who can reach which OT assets, through what mechanism and under what approval condition.
- Eliminate default OT credentials Remove manufacturer and inherited defaults from devices and controllers, then verify that replacement credentials have named owners and documented recovery steps.
- Remove shared accounts from OT access Assign one identity per person or service role so access reviews, incident reconstruction and emergency revocation are all possible.
- Use task-bounded privileged access Constrain remote vendor sessions to a specific maintenance window, specific target system and specific set of commands, then revoke access when the task closes.
- Centralise logging for vendor activity Collect authentication events, session actions and privilege changes into one reviewable log stream so forensic analysis does not depend on local device history.
Key takeaways
- Water utility OT risk is being amplified by access patterns that are hard to govern, not by connectivity alone.
- Default credentials, shared accounts and fragmented remote access create the conditions for attribution loss and persistent exposure.
- Utilities need task-bounded access, explicit ownership and central enforcement to make vendor support compatible with critical infrastructure security.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 — Vulnerable Third-Party NHI | Vendor support paths in OT are the article's central exposure surface. |
| NHI-04 — Insecure Authentication | Default and reused credentials are called out as key OT weaknesses. | |
| NHI-05 — Overprivileged NHI | The article warns that vendor access can become broader than the maintenance task requires. | |
| Recommendation — Inventory and constrain third-party OT access under NHI-03 before it becomes a persistent trust path. Replace insecure OT authentication patterns with unique, verified credentials and controlled session access. Reduce vendor privileges to the minimum OT scope needed for each maintenance activity. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article describes credential harvesting and remote-access abuse as likely attack paths. |
| Recommendation — Map OT vendor-access weaknesses to credential access and lateral movement techniques in detection plans. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Centralised access control and granular authorization are core themes in the article. |
| DE.CM-01 — Network Monitoring | The article emphasises logging and monitoring vendor sessions for detection and forensics. | |
| Recommendation — Apply PR.AA-05 to govern who can reach OT systems and what they can do once connected. Use DE.CM-01 to ensure OT vendor sessions are continuously monitored and reviewable. | ||
Key terms
- Vendor access governance: Vendor access governance is the set of policies and controls that define, limit, review, and revoke external user or system access. It focuses on lifecycle, scope, evidence, and accountability, so third-party identities do not become permanent or overly broad trust paths.
- Task-bounded Access: Task-bounded access is a control pattern where permissions exist only for the duration of a specific job and are removed automatically when the job ends. It is especially relevant for AI agents because autonomous systems can otherwise retain or recreate access long after the original need has passed.
- Shared Account Risk: The security and accountability problem created when multiple people use the same login or credential. Shared accounts weaken traceability, complicate offboarding, and make it difficult to prove who performed an action inside a SaaS application.
- Operational Technology Identity: An identity used in environments where digital access can affect physical processes, equipment, or uptime. These identities often carry higher operational risk because access mistakes can move beyond data exposure into safety, availability, and process integrity concerns.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org