Start with asset visibility, identity-based access, and least privilege around administrative paths, then phase controls by process criticality. In ICS and SCADA, safety and uptime come first, so teams should avoid broad enforcement that could interrupt control loops or legacy equipment. Use strong authentication, segmented access, and continuous verification where changes are safe to introduce.
Why This Matters for Security Teams
Applying zero trust to ICS and SCADA is not a simple policy rewrite. These environments are built around deterministic control, long equipment lifecycles, and safety requirements that can make aggressive enforcement risky. A zero trust program that ignores process criticality can disrupt control loops, strand legacy operators, or create fail-closed conditions that are worse than the threat being addressed. NIST’s NIST SP 800-207 Zero Trust Architecture is clear that trust should be continuously evaluated, but in OT that evaluation has to respect operational constraints.
That is why identity, segmentation, and verification need to be introduced selectively rather than uniformly. The practical goal is to reduce lateral movement and administrative sprawl without interfering with the timing and availability requirements of plant systems. NHIMG’s Ultimate Guide to NHIs notes that 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, which is especially relevant where service accounts, jump hosts, and remote vendor access often carry more reach than their owners realise. In practice, many security teams discover the weakest path only after a maintenance window or vendor session has already exposed it.
How It Works in Practice
Zero trust in ICS and SCADA works best when it is phased around the highest-risk administrative paths first. Start with asset visibility, then map who and what can reach engineering workstations, historians, remote access gateways, PLC programming interfaces, and safety-adjacent systems. From there, apply identity-based access so that operators, vendors, and automation tools are authenticated and authorised by context, not by implicit network location. This aligns with the practical direction of Guide to SPIFFE and SPIRE, where workload identity helps prove what an entity is before it is allowed to act.
Controls that usually fit OT environments include:
- strong MFA for remote and privileged access paths
- segmentation between enterprise IT, DMZ, and control zones
- just-in-time access for maintenance and vendor sessions
- session recording and command logging for admin actions
- short-lived credentials for tool access where systems support them
- policy checks tied to process criticality, not just user role
For OT, the safest implementation pattern is often allow-by-exception with continuous verification around the narrow set of actions that change state, rather than blanket blocking. That is why many teams use a control gate in front of sensitive paths instead of modifying the control network itself. Current guidance suggests using policy-as-code and device or workload identity where feasible, but there is no universal standard for replacing legacy PLC authentication models yet. These controls tend to break down when a plant depends on unsupported controllers or vendor-managed remote diagnostics because the equipment cannot enforce modern identity and authorization signals.
Common Variations and Edge Cases
Tighter zero trust enforcement often increases operational overhead, requiring organisations to balance risk reduction against uptime, maintenance access, and safety validation. In brownfield environments, this tradeoff is most visible where vendor laptops, serial gateways, and shared engineering accounts were never designed for per-session identity or continuous policy checks. The right answer is usually not to force every device into the same model, but to wrap compensating controls around the parts that can be changed safely.
Where legacy systems cannot support modern authentication, teams often rely on jump hosts, privileged access workflows, and network isolation while they modernise adjacent layers. Where systems can support stronger identity, ephemeral access and workload identity should replace long-lived shared credentials. NHIMG’s Ultimate Guide to NHIs — Standards is useful here because OT teams often need to align identity controls with broader governance rather than treating them as isolated access exceptions. Best practice is evolving, especially for remote operations, and the safest path is to prove controls on non-critical segments before extending them to production control paths. The approach becomes fragile when operators depend on shared credentials or emergency access outside change windows, because those patterns defeat continuous verification.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST Zero Trust (SP 800-207), NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST Zero Trust (SP 800-207) | Verify explicitly | Core zero trust principle for constrained OT access decisions. |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege and access control are central to OT segmentation and admin path protection. |
| OWASP Non-Human Identity Top 10 | NHI-01 | ICS and SCADA rely heavily on service accounts and machine identities. |
| CSA MAESTRO | IAM-2 | MAESTRO addresses identity and access patterns for autonomous and machine-driven operations. |
| NIST AI RMF | AI RMF helps manage operational risk when automation and analytics influence OT decisions. |
Place a policy gate in front of OT access and verify each request by identity, device, and session context.
Related resources from NHI Mgmt Group
- How should security teams apply zero trust to export controlled information in SAP environments without disrupting operations?
- How should security teams apply zero trust to OT without disrupting operations?
- How should security teams plan an SAP ECC to S/4HANA migration without disrupting business operations?
- How should security teams apply least privilege to Amazon S3 access without breaking day-to-day operations?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org