Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What happens when organisations keep relying on high-touch…
Cyber Security

What happens when organisations keep relying on high-touch access methods after reopening?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Cyber Security

When organisations keep relying on high-touch access methods, they preserve avoidable friction and increase exposure to shared-surface risk. That can slow secure reopening, weaken user experience, and leave physical access processes out of step with current expectations. Teams should evaluate whether those methods still match today’s operational and health-related requirements before treating them as acceptable defaults.

Why High-Touch Access Becomes a Drag After Reopening

High-touch access methods, such as staffed checkpoints, manual approvals, and repeated human intervention, tend to persist because they feel controlled and familiar. After reopening, that same familiarity becomes a liability if the process still assumes pandemic-era caution, added handling, or slower throughput. The result is not just inconvenience, it is a process that no longer matches day-to-day operational demand.

At the practical level, these methods create friction at every entry point. They slow movement, increase queueing, and make access decisions harder to scale when attendance rises. They also make it more likely that staff will bypass the intended process to keep operations moving, which turns a control into a routine exception.

Where reopening changes expectations, the control question is whether the access method still serves a current purpose or whether it is simply an inherited workaround. The more a process depends on manual handling, the more its effectiveness depends on human consistency, staffing, and patience under load.

How Shared-Surface and Handling Risk Stays in the Process

High-touch access methods often preserve shared-surface risk because multiple people continue to handle the same objects, interfaces, or checkpoints. That can matter even when the original health concern has eased, because the exposure is created by the process design itself, not only by the external environment. If the method remains in place without reassessment, the organisation keeps the same contact pattern and the same opportunity for inconsistent hygiene or handling controls.

There is also a broader operational side to that risk. When access is mediated through shared items or repeated staff intervention, the organisation may need more cleaning cycles, more supervision, and more exception handling than it expected. That increases the cost of maintaining the process and can make compliance with internal standards uneven over time.

For that reason, the key issue is not whether a high-touch method was once justified, but whether its current risk profile still matches the way people actually use the space. A method that requires constant exception management is usually signalling that it no longer fits the operating model.

What Good Access Design Looks Like After the Return to Normal Operations

Better post-reopening access design reduces touch points without losing control. In practice, that usually means shifting toward cleaner checkpoints, clearer rules, and fewer manual handoffs so access can scale with normal traffic. Where possible, the process should make entry predictable for users and easy to administer for staff.

The strongest test is whether the access method still aligns with present operational requirements, not just historical assumptions. Teams should look for signs that the process is causing avoidable delay, encouraging workarounds, or requiring more human effort than the underlying risk warrants. If those signs are present, the method should be redesigned rather than defended by habit.

Reopening is also the right time to reset expectations with users. If the access flow has stayed in a temporary mode for too long, people may accept inconvenience as normal even when it is no longer necessary. A current design should be easier to explain, easier to operate, and easier to keep consistent across sites or shifts.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyAccess friction and shared-surface exposure require a current risk strategy.
Recommendation — Reassess whether the access method still fits the organisation’s current risk appetite.
ISO/IEC 27001:2022A.5.15 — Access controlThe question concerns whether the access method remains appropriate as an access control.
A.5.18 — Access rightsReopening changes whether access processes and approvals remain justified.
Recommendation — Review access control design to remove outdated high-touch steps that no longer add value. Validate that access permissions and handoffs still match present operational needs.
NIST SP 800-53 Rev 5AC-2 — Account ManagementManual access methods often rely on admin-controlled approvals and maintenance.
AC-6 — Least PrivilegeHigh-touch methods often persist because of overbroad, manual access patterns.
Recommendation — Reduce manual access handling where it no longer supports timely, controlled operation. Limit access steps and privileges to the minimum needed for current operations.
CIS Controls v8CIS-6 — Access Control ManagementHigh-touch access methods are fundamentally an access control management issue.
Recommendation — Streamline access controls that now create avoidable delay or handling risk.

Practitioner Guidance

What to prioritise: Start with the access points that create the most repeated handling or the longest delays, because those are usually where friction and shared-surface exposure are most visible. If a control depends on staff memory or informal exceptions to function, treat it as a redesign candidate rather than a stable operating method.

What to verify: Confirm whether the method still has a clear security or operational purpose, whether it can handle current volume, and whether users are bypassing it under pressure. A process that only works on paper is not a useful post-reopening default.

Practitioner takeaway: The decision is not whether the old method once made sense, it is whether it still earns its place now that reopening has changed traffic, expectations, and tolerance for friction.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org