Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

DORA compliance and infrastructure access: are static controls enough?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15984
Topic starter  

TL;DR: DORA’s full effect on January 17, 2025 puts infrastructure access, incident reporting, and third-party risk back under regulatory scrutiny, according to Teleport. The compliance problem is not a lack of controls in theory, but the mismatch between static credentials, sprawling infrastructure, and audit demands that assume access can be cleanly bounded.

NHIMG editorial — based on content published by Teleport: The 2025 DORA Deadline is Here: Simplify Compliance with Teleport

Questions worth separating out

Q: How should security teams reduce DORA risk in infrastructure access paths?

A: Security teams should reduce DORA risk by removing persistent credentials from privileged workflows and replacing them with session-scoped access that can be logged, revoked, and audited.

Q: Why do static credentials create problems for DORA compliance?

A: Static credentials create problems because they extend access beyond the task, obscure who used them, and make revocation and audit evidence harder to prove.

Q: What breaks when standing privileges are left in place for cloud infrastructure changes?

A: Standing privileges increase the chance that a routine change can affect shared systems far beyond the intended task.

Practitioner guidance

  • Inventory every static infrastructure credential Map passwords, SSH keys, and long-lived tokens across on-prem, cloud, and Kubernetes estates, then classify which ones support regulated or privileged access.
  • Replace standing privilege with session-scoped access Use short-lived certificates or equivalent ephemeral access mechanisms for administrative and operational tasks.

What's in the full article

Teleport's full blog post covers the operational detail this post intentionally leaves for the source:

  • A control-by-control walkthrough of how its infrastructure access model maps to DORA requirements.
  • Examples of how ephemeral certificates replace passwords, SSH keys, and static tokens in privileged workflows.
  • A compliance-oriented view of logging, monitoring, and audit evidence for regulated infrastructure estates.
  • The vendor's framing of how its platform is positioned for financial institutions and ICT providers under DORA.

👉 Read Teleport's blog post on simplifying DORA compliance for infrastructure access →

DORA compliance and infrastructure access: are static controls enough?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15569
 

Static infrastructure credentials are a DORA liability, not just a hygiene issue. DORA expects organisations to evidence controlled access, incident response, and resilience across operational environments. Static passwords, SSH keys, and tokens make those requirements harder to prove because they outlive the session, the operator, and sometimes the system they were meant to protect. The practitioner conclusion is simple: if access cannot be bounded and evidenced, compliance becomes fragile.

A few things that frame the scale:

  • Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems, according to The 2026 Infrastructure Identity Survey.
  • That same survey found that 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.

A question worth separating out:

Q: Who is accountable for ICT risk management under DORA?

A: Senior management is accountable, with regulated entities expected to assign clear responsibilities for ICT risk oversight, reporting, and resilience testing. In practice, that accountability extends to access governance because identity failures can trigger incidents, supplier exposure, and recovery problems. The board cannot delegate away the evidence requirement.

👉 Read our full editorial: DORA compliance exposes the limits of static infrastructure access



   
ReplyQuote
Share: