Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should utilities prioritise zero trust access or internal…
Governance, Ownership & Risk

Should utilities prioritise zero trust access or internal network monitoring first?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

For OT, they should be treated as complementary, but access scope usually deserves priority because it reduces the number of paths monitoring must police. INSM can improve detection and evidence, yet it cannot compensate for a design that still assumes trusted network presence. Start with the access model, then strengthen observation around it.

Why utilities should treat access and monitoring as a sequence, not a choice

For operational technology, zero trust access changes the blast radius by controlling who and what can connect in the first place. Internal network monitoring remains important, but it is inherently reactive: it detects, corroborates, and investigates activity after a path already exists. That is why the access model usually comes first, with monitoring layered to validate and watch the paths that remain.

The practical difference is leverage. A tighter access model reduces the number of assets, sessions, and protocol paths that need continuous scrutiny. Monitoring without access reform can still be useful, but it is forced to observe a larger, noisier attack surface and will miss weak assumptions that still allow trusted lateral movement.

In utilities, that sequence matters because OT environments often contain legacy trust paths, shared administration patterns, and remote access exceptions. A zero trust approach narrows those entry points by making access explicit and policy-driven, while monitoring helps prove whether the control is behaving as intended and whether unexpected connections are still appearing.

What internal network monitoring can do, and where it stops

Internal network monitoring is strongest when the question is visibility: what is talking to what, at what time, and under what baseline. It can uncover drift, identify unusual east-west movement, surface policy violations, and give incident responders evidence for containment decisions. It is also useful for OT because many systems cannot host heavy agents, making network-based observation a pragmatic control.

Its limit is that observation does not equal enforcement. If the environment still assumes that anything inside the network is trusted, monitoring may detect abuse too late, especially when credentials are valid or remote access is already established. That means monitoring should be treated as an assurance and detection layer, not the first line of control design.

Utilities should therefore use monitoring to answer whether access decisions are being followed, whether segmentation is effective, and whether privileged sessions are behaving normally. Those are meaningful questions, but they depend on an access model that already defines who may enter, from where, and under what conditions.

What zero trust access changes in practice for OT

Zero trust access is not just a policy phrase. It shifts the environment from implicit trust based on location to explicit verification based on identity, device state, and policy per request. In OT, that usually means segmenting operator, vendor, and engineering access so the smallest practical set of paths exists, and then applying stronger verification at those choke points.

The operational benefit is that fewer inbound and lateral paths remain available for misuse, which also simplifies monitoring. A well-designed access layer can enforce least privilege, reduce standing access, and make exceptions visible enough to review instead of hiding them in a broadly trusted internal network.

This is why the right question is rarely whether to “do access or monitoring.” The more accurate question is how to make access strict enough that monitoring has a manageable job. That sequence aligns with NIST SP 800-207 Zero Trust Architecture, which treats continuous verification and policy enforcement as the foundation for reducing implicit trust.

Risk and Threat Considerations

Utilities face two compounded risks when they delay access reform. First, internal monitoring can become overloaded by legitimate but overly broad connectivity, making abnormal traffic harder to distinguish. Second, an attacker who gains valid credentials or a trusted foothold can blend into the same network pathways that monitoring is trying to observe.

Failure mechanism: A trusted-network design leaves too many paths available, so detection has to compensate for an access model that still permits broad reach. In OT, that increases the chance that valid remote access, vendor connectivity, or lateral movement will appear ordinary until damage or disruption is already underway.

Impact: The result is larger blast radius, slower containment, and weaker evidence quality because alerts describe movement rather than prevent it. Access-first design lowers exposure before monitoring is asked to validate it, which is why a zero trust control model is generally the better first investment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication and Access ControlZero trust access and internal monitoring both depend on controlling who can reach OT assets.
Recommendation — Enforce PR.AA-05 to narrow OT access paths before relying on detection.
NIST SP 800-53 Rev 5AC-4 — Information Flow EnforcementOT segmentation and policy enforcement directly govern which network paths remain open.
Recommendation — Apply AC-4 to limit east-west OT traffic to approved flows.
NIST Zero Trust (SP 800-207)Zero Trust ArchitectureThe question compares explicit verification and continuous monitoring in a zero trust design.
Recommendation — Adopt zero trust policy enforcement before expanding reliance on monitoring.
CIS Controls v8CIS-12 — Network Infrastructure ManagementUtilities need controlled network pathways and visibility to support segmentation and monitoring.
Recommendation — Segment OT networks and continuously inventory permitted communications.
ISO/IEC 27001:2022A.8.22 — Segregation of networksNetwork segregation is central to reducing OT blast radius before monitoring is layered on.
Recommendation — Implement network segregation to reduce trusted OT reach.

Practitioner Guidance

What to prioritise: Start by identifying the highest-value OT entry paths, especially remote access, vendor connections, and admin sessions. Those are the points where access scope can be reduced fastest and where monitoring gains the most value once the paths are constrained.

What to verify: Confirm that every exception path has an owner, a purpose, and an expiry condition. If you cannot explain why a connection must remain broad, it is usually a candidate for tighter policy before it becomes a monitoring problem.

Common mistake: Treating network monitoring as a substitute for access control. That approach improves visibility but leaves the underlying trust assumption intact, which means the same abuse paths remain available.

Practitioner takeaway: In utilities, monitoring should prove and refine the access model, not replace it; the strongest operational posture comes from shrinking trusted reach first and then watching the remaining paths closely.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org