Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

NIS2 access governance: what changes for IAM and PAM teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: NIS2 shifts cybersecurity from an IT concern to a board-accountable business risk, and Wallix’s interview argues that access governance now sits at the centre of resilience because excessive privileges, shared accounts, and poor traceability undermine both prevention and investigation. The pressure point is not just compliance, but accountable control over who can access what, when, and under what oversight.

NHIMG editorial — based on content published by Wallix: Expert interview, NIS2 and the new accountability model for access governance

Questions worth separating out

Q: How should organisations govern privileged access under NIS2?

A: They should treat privileged access as a resilience and accountability control, not just a technical permission set.

Q: Why do shared administrative accounts create NIS2 risk?

A: Shared accounts weaken attribution, which makes it hard to prove accountability or investigate misuse.

Q: What breaks when third-party access is not time-bound and traceable?

A: The organisation loses control over offboarding, incident reconstruction, and privilege review.

Practitioner guidance

  • Map accountability to every privileged access path Create an inventory of who can reach critical systems, how access is granted, and which approvals or logs prove that access was legitimate.
  • Convert shared administrative access into named or brokered access Replace shared credentials where systems allow it, and where they do not, place privileged access behind session brokering, recording, and time limits so activity can be attributed during review or incident response.
  • Apply the same controls to third-party access as to internal privilege Require time-bound access, auditable sessions, and offboarding checks for suppliers and integrators.

What's in the full article

Wallix's full interview covers the operational detail this post intentionally leaves for the source:

  • How access governance maps to NIS2 accountability expectations for leadership and boards
  • The practical limits of legacy applications that force shared accounts and excessive privileges
  • Where PAM, stronger authentication, and audit trails fit when systems cannot be redesigned
  • How third-party access should be controlled, monitored, and traced under resilience-focused governance

👉 Read Wallix's interview on NIS2 and the new accountability model for access governance →

NIS2 access governance: what changes for IAM and PAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Access governance becomes a resilience control, not just an IAM hygiene task. NIS2 pushes accountability up the organisation, so privilege decisions now need to survive executive scrutiny and audit review. That changes the measure of maturity from policy existence to proof of oversight, traceability, and exception handling. The practitioner conclusion is simple: if you cannot evidence access decisions, you do not control them.

A few things that frame the scale:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • That confidence gap matters because unmanaged access often persists longer in machine and service identities than in human workflows, which expands audit and incident-response risk.

A question worth separating out:

Q: Who is accountable for NIS2 access decisions and incident reporting?

A: Top-level management remains accountable for risk governance, but identity, data, and security teams must supply the evidence and control operations that make accountability real. Practically, that means clear ownership for access policy, review outcomes, incident scope, and reporting artefacts. Without named stewardship, the organisation cannot demonstrate control.

👉 Read our full editorial: NIS2 makes access governance a board-level accountability issue



   
ReplyQuote
Share: