Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What happens when organisations have an ICS security…
Cyber Security

What happens when organisations have an ICS security plan but not enough staff to implement it properly?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Cyber Security

A plan without sufficient staff usually becomes partial, delayed, or inconsistent in execution. Controls may exist on paper, but monitoring, response, and hardening tasks are not carried through across all critical assets. In ICS environments, that gap is especially risky because availability matters, and incomplete implementation can leave engineering systems exposed while teams assume they are covered.

Why the plan breaks down in ICS operations

An ICS security plan is only as effective as the people available to run it. In operational technology, implementation is not a paperwork exercise: it requires asset coverage, rule tuning, maintenance windows, vendor coordination, and fast follow-through when something changes. When staffing is thin, the plan often becomes selective, with the highest-risk systems receiving attention first and everything else drifting.

That gap matters because ICS environments are built around availability and controlled change. If hardening, review, and monitoring tasks are repeatedly deferred, the organisation may still believe the plan is “in place” while the actual protection level remains uneven. In practice, under-resourcing turns a security plan into a prioritisation list, not an operating model.

For operational technology baseline guidance, see NIST SP 800-82 Rev 3 and CISA Industrial Control Systems.

Where the implementation gap shows up first

The first failure point is usually coverage. A small team can often document controls, but not verify them across PLCs, HMIs, engineering workstations, remote access paths, and field-connected assets at the same cadence. That creates uneven protection, with some systems patched, segmented, or logged, while others remain on legacy settings because no one had time to complete the work.

The second failure point is operational consistency. Monitoring rules, exception handling, backup checks, and access reviews require repeated attention, especially after maintenance, vendor support, or process changes. Without sufficient staff, those recurring tasks are the ones most likely to be skipped, which means the environment can slowly diverge from the approved plan without a clear control failure alert.

Staffing limits are especially important in OT identity and access work, where remote vendor access, shared accounts, and privileged credentials often need manual governance. NHIMG’s OT and ICS Identity and Access Guide is useful where a security plan depends on practical control of access paths rather than policy language alone.

What organisations should expect when the plan is under-resourced

Understaffing usually produces three predictable outcomes: delayed execution, partial execution, and inconsistent evidence. Delayed execution means critical actions, such as segmentation changes or review cycles, are pushed into the next maintenance window. Partial execution means the same control is applied to a few high-value assets but not to the broader estate. Inconsistent evidence means leadership cannot confidently show that the plan was carried through everywhere it needed to be applied.

That combination creates a false sense of maturity. The organisation can point to a plan, a risk register, or a project tracker, but the practical question is whether the team has enough capacity to keep protections current as assets, vendors, and process conditions change. In ICS, the answer to that question often determines whether the control is real or only aspirational.

The most useful comparison point is whether the team can sustain the control after rollout, not whether it can produce the original plan. Availability-sensitive systems need recurring operations, not one-time security work, and that distinction is what under-staffed programs often miss.

Risk and Threat Considerations

When staffing is insufficient, the main risk is control decay: protections exist in policy but are not consistently applied, verified, or maintained across the live environment. In ICS, that can leave exposed remote access, stale privileges, weak segmentation, or unmonitored systems in place long enough for operational disruption or attacker footholds to develop.

Failure mechanism: Limited staff forces security work into exception handling and best-effort coverage, so monitoring, hardening, and review cycles lag behind operational change. The result is control drift between the documented plan and the actual state of critical assets.

Impact: The organisation inherits uneven protection, slower response, and higher exposure to outage or compromise, especially where legacy systems, vendor access, or safety-linked processes depend on timely maintenance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5CA-7 — Continuous MonitoringUnderstaffed ICS plans often fail at sustained monitoring and follow-through.
CM-2 — Baseline ConfigurationIncomplete implementation leaves OT assets drifting from intended secure baselines.
IR-4 — Incident HandlingThin staffing slows detection, escalation and response in availability-sensitive ICS environments.
Recommendation — Establish a continuous monitoring cadence that matches staff capacity and critical asset coverage. Define and maintain approved baselines for critical ICS assets and verify they stay current. Assign incident handling roles that can be executed within the operational constraints of the site.
CIS Controls v8CIS-8 — Audit Log ManagementUnder-resourcing often leaves monitoring and review work incomplete across critical systems.
Recommendation — Ensure logging and review coverage can be sustained for the assets that matter most.

Practitioner Guidance

What to prioritise: Start with the controls that fail badly when they are only partly done, especially monitoring, remote access governance, segmentation, and asset-specific hardening. If the team cannot sustain broad coverage, narrow the scope deliberately and make the coverage boundary explicit.

What to verify: Confirm that the people assigned to the plan can actually perform the recurring work, not just approve it. A useful test is whether the team can show recent evidence of completed reviews, configuration changes, and follow-up on exceptions across all critical assets, not only the best-managed ones.

Practitioner takeaway: In ICS, staffing is part of the control design, not an administrative detail. If the organisation cannot resource the recurring work, the right response is to reduce scope, formalise prioritisation, and be honest about which protections are not yet real.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org