Warning signs include weak visibility into who accessed what, limited audit trails, inconsistent approval of privileged sessions, and no reliable way to show compliance through reports or live monitoring. If third-party access is handled informally, or if identities are not mapped cleanly to roles, the organisation will struggle to demonstrate control. That is usually where NIS2 programmes start to fail in practice.
What weak OT access controls look like under NIS2
NIS2 does not ask whether access exists in theory, it asks whether access is controlled, reviewable, and proportionate in practice. In OT, the warning signs usually appear as gaps between policy and reality: shared or informal access paths, weak segregation between operators and vendors, and controls that cannot prove who did what, when, and under whose approval.
When those gaps show up, the problem is often not a single broken setting. It is a control design that has never been made auditable for operational use, which is exactly where access governance, privileged session handling, and third-party oversight start to fail.
Which control failures are the clearest signals?
The clearest signals are operational, not cosmetic. If access logs are incomplete, session approvals are inconsistent, or remote maintenance is handled through ad hoc exceptions, the organisation is already struggling to demonstrate that access is bounded and reviewable. That matters because NIS2 expectations align with demonstrable control, not informal assurance.
Another strong indicator is role mapping that does not match how the plant is actually run. If people or suppliers inherit broad access because the environment is old, urgent, or difficult to segment, then least-privilege intent has not been translated into enforceable OT access control. The same issue appears when reports exist but cannot be reconciled to live privileges or active sessions.
For practical control design, it helps to compare the OT environment with a mature authorisation model, where roles, entitlements, and exceptions are explicit rather than implied. NHIMG’s Authorisation Models Guide is useful here because it shows how access decisions become harder to defend when policies are too coarse or too loosely enforced.
Why third-party and privileged access expose the biggest NIS2 gaps
Third-party access is often where OT programmes become weakest, because it introduces another trust boundary without always introducing the same level of evidence. If vendor access is not time-bound, not tied to a named identity, or not reviewed after use, the organisation may be unable to show that privileged access stayed within the approved purpose.
Privileged sessions are a similar test. If you cannot see whether a session was approved, recorded, or terminated correctly, then the control is effectively unproven even if the login succeeded. In OT, that lack of proof is especially important because operational urgency can hide excessive access for long periods.
NHIMG’s OT and ICS Identity and Access Guide and Privileged Access Management Guide both reflect this reality: vendor remote access, shared accounts, and standing privilege are not just administration issues, they are control failures when they cannot be reviewed and attributed cleanly.
Risk and Threat Considerations
Weak OT access controls create two forms of exposure at once, compliance exposure under NIS2 and operational exposure inside the plant. The same gap that prevents auditability also gives an attacker or careless insider a wider and less visible path into sensitive systems, especially where remote access, shared credentials, or excessive privilege have been normalised.
Failure mechanism: Access is granted through informal exceptions, shared accounts, or poorly governed privileged sessions, so the organisation loses reliable attribution, monitoring, and timely revocation.
Impact: Attackers can blend into legitimate maintenance activity, third parties can retain access longer than intended, and the organisation may be unable to evidence control effectiveness during an incident or regulatory review.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | OT access gaps often stem from weak user attribution and shared access paths. |
| IA-5 — Authenticator Management | OT programmes fail when credentials, shared secrets, and rotation are not governed. | |
| AU-2 — Event Logging | The question centres on weak visibility and audit trails for OT access control. | |
| Recommendation — Enforce named-user authentication for OT operators and administrators. Rotate and govern OT credentials so access remains attributable and revocable. Log OT access events and privilege changes to create reviewable evidence. | ||
Practitioner Guidance
What to verify: Confirm that every privileged OT path can be tied to a named identity, an approved reason, and a revocation point. If you cannot reconstruct those three elements from logs and reports, the control is not ready for NIS2 scrutiny.
What good looks like: The strongest signal is not perfect documentation, it is consistent proof that access is limited, session activity is visible, and exceptions are short-lived and reviewable. If live access and periodic reporting do not tell the same story, the environment still has control drift.
Practitioner takeaway: Treat NIS2 readiness in OT as an evidence problem as much as an access problem, because controls that cannot explain themselves under scrutiny are usually the ones most likely to fail in practice.
Related resources from NHI Mgmt Group
- When should organizations review access controls?
- Why do organisations struggle to keep identity and access controls aligned with NIS2 and ISO 27001 expectations?
- How should security teams run access reviews for non-human identities?
- How should security teams govern non-human identities that have persistent access?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org