TL;DR: Critical infrastructure resilience is increasingly tied to how organisations govern OT access, vendor sessions, and incident response under NIS2, according to SSH Communications Security. The practical issue is not eliminating risk but proving that privileged access, auditability, and continuity controls still hold when essential services are under stress.
Editorial analysis by NHI Mgmt Group, based on content published by SSH Communications Security: “Why Cyber Resilience Can't Wait”.
Key questions
Q: Where does OT access governance fail under NIS2 resilience pressure?
A: It fails when organisations treat access as an IT convenience layer instead of a resilience control.
Q: Why does vendor access increase OT resilience risk?
A: Vendor access often combines elevated privilege, time pressure, and cross-system reach, which makes it easy to overextend a session beyond its original purpose.
Q: How can organisations tell whether OT access controls are actually working?
A: Look for evidence that access is issued only on demand, expires automatically, and can be tied to a named user, task, and session record.
Practitioner guidance
- Map OT vendor access paths Inventory every third-party and maintenance route into OT systems, including emergency support, remote operations, and cross-domain administrative access.
- Enforce session-level controls Require just-in-time approval, session recording, and protocol-aware monitoring for every privileged OT connection so access is attributable and reviewable.
- Separate emergency and routine access Create distinct processes for time-critical support and standard maintenance so temporary urgency does not become standing operational privilege.
Bottom line: The article frames OT access as a resilience issue because essential services can fail when privileged sessions are uncontrolled or unauditable.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
OT access governance is now a resilience discipline, not a narrow PAM problem. NIS2 pushes essential sectors to prove that access remains controlled under stress, which means the old boundary between access management and continuity planning is collapsing. The practical implication is that OT access paths must be governed as part of service survivability, not as a separate administrative control.
A question worth separating out:
Q: What should organisations do when OT support must continue during an incident?
A: They should use a tightly scoped emergency access process with explicit approval, continuous monitoring, and immediate session attribution. The point is to preserve continuity without creating persistent privilege or unverifiable access. That keeps incident response aligned with governance, which is exactly what NIS2 resilience expects.
👉 Read our full editorial: NIS2 resilience is exposing gaps in OT access governance