Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should critical infrastructure teams do when they…
Governance, Ownership & Risk

What should critical infrastructure teams do when they must preserve both access and isolation?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

They should use governed, identity-based access that is tightly scoped to the required OT asset and supported by segmentation that can survive degraded connectivity. The operational goal is not to pretend no route exists, but to make any route deliberate, observable and reversible. That approach supports both continuity and containment.

Access Control Is Only Half the Problem in Critical Infrastructure

For critical infrastructure, the hard part is not choosing between access and isolation. It is designing access so operators can still perform required actions without collapsing the containment boundary. That usually means tightly scoped, governed access paths, with segmentation that limits spread if a remote path, jump host, vendor connection, or engineering account is compromised.

The access path should be treated as a controlled operational dependency, not a convenience layer. If it is broad, persistent, or difficult to audit, it becomes a shared failure point across reliability and security.

Why Deliberate, Observable Access Beats Broad Connectivity

Critical infrastructure environments often need remote support, maintenance, and exception handling, but every added route changes the blast radius. The better design choice is to make each route explicit, constrained to the required OT asset, and revocable without rebuilding the whole network. That is how teams preserve continuity while keeping the environment contained.

In practice, this means access should be tied to a specific business or operational need, not to a generic subnet, site-wide trust zone, or standing remote session. When the route cannot be justified at asset level, it is usually too broad to be safe.

For identity-based access patterns in operational environments, the access decision is only trustworthy if the route and the authority behind it are both bounded. Guidance for governed machine and service access in broader identity programs makes the same point: scope the credential, scope the destination, and reduce unnecessary reuse of access paths. The Colonial Pipeline ransomware attack remains a useful reminder that an unused remote-access path can become a high-impact entry point when it is left outside normal governance.

Segmentation Must Still Work When Connectivity Degrades

The containment side of the design cannot assume ideal conditions. In critical infrastructure, networks fail, links degrade, and operational staff may need fallback paths to keep systems safe or stable. Segmentation therefore has to survive partial outages, not just normal-state policy checks. If isolation disappears the moment a control plane is unavailable, the architecture is not resilient enough.

That is why teams should prefer segmentation models that degrade safely, with predictable fail states, clear zone boundaries, and monitored exceptions. The goal is not perfect separation at all times, but separation that remains meaningful when infrastructure is under stress.

External guidance for critical sectors and industrial environments reinforces this operating model. CISA Industrial Control Systems resources emphasize that OT controls have to fit availability and safety realities, while still limiting exposure. CISA cyber threat advisories also show why exposed remote access and weak boundary control remain recurring operational risks. ENISA threat landscape reports likewise consistently place critical infrastructure among the environments where exposure, persistence, and disruption matter most.

What Good Looks Like When Operations Need Both Reach and Containment

The best pattern is governed access with narrow authority, a defined time window, and a clear target asset, combined with segmentation that limits what else can be reached if the session is abused. Access should be reversible, auditable, and attributable, while the network boundary should continue to enforce separation even if one control layer is impaired.

Teams should also avoid designing for permanent exceptions. Once a remote route, vendor tunnel, or bypass path becomes routine, it stops being an exception and starts becoming part of the attack surface. That is the point where containment and continuity begin to drift apart.

For practitioners, the most useful benchmark is not whether a connection exists, but whether it is specific, time-bounded, monitored, and removable without broad operational fallout. When those conditions are missing, the environment is already trading away containment to preserve convenience.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-4 — Information Flow EnforcementPreserves OT boundary enforcement while allowing necessary operational access.
AC-6 — Least PrivilegeLimits operator and support access to the minimum needed for the OT task.
IA-2 — Identification and Authentication (Organizational Users)Supports governed, attributable access for human operators in critical environments.
Recommendation — Enforce controlled information flows between zones and named assets. Constrain access paths and entitlements to the minimum operational need. Authenticate operators before allowing access to sensitive OT functions.
ISO/IEC 27001:2022A.8.20 — Network securityDirectly applies to segmentation and boundary protection in critical infrastructure.
Recommendation — Implement network segmentation and boundary controls for OT environments.
CIS Controls v8CIS-4 — Secure Configuration of Enterprise Assets and SoftwareSegmentation and constrained routes depend on hardened, controlled configurations.
Recommendation — Harden and standardize remote access and segmentation configurations.

Practitioner Guidance

What to prioritise: Start with the highest-consequence OT assets and the paths that can reach them, then verify whether each path is genuinely required for operations or only inherited from older support models.

What to verify: Confirm that every privileged route can be revoked independently, that segmentation still limits lateral movement during partial outages, and that access logs identify the exact asset and operator involved.

Decision rule: If a path cannot be scoped to a named operational need and a named asset, treat it as too broad for a critical environment, even if it is currently convenient.

Practitioner takeaway: The right balance is not “more access” or “more isolation”, it is access that is narrow enough to be defensible and isolation that remains real when the environment is under stress.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org