Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why does relying on the same security model…
Threats, Abuse & Incident Response

Why does relying on the same security model during a crisis increase exposure for organisations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Threats, Abuse & Incident Response

Because crisis conditions change both attacker behavior and defender capacity. Budgets shrink, staff are stretched, and remote access expands the attack surface at the same time. If teams keep using the same assumptions, they miss weaknesses in endpoints, VPNs, email access, and web platforms. Adapting controls to current operating conditions reduces the gap between policy and reality.

Why Crisis Conditions Expose the Weakness in Static Security Models

A crisis changes the operating environment faster than many security models can absorb. The key problem is not only more risk, but different risk: wider remote access, compressed decision time, and less tolerance for manual checks. A model built for normal operations often assumes stable staffing, stable networks, and stable user behavior, so it underestimates the new attack paths that appear when those assumptions break.

Security controls are only as strong as the conditions they were designed for. When those conditions shift, controls that once looked adequate can become too slow, too narrow, or too dependent on human review. Crisis periods therefore expose where policy, detection, and access decisions were tuned for routine work instead of degraded, high-pressure operations.

What Changes in the Attack Surface During a Crisis?

Several things change at once. Remote work expands the number of endpoints and home networks in play, email and collaboration tools become even more central, and VPNs or remote access gateways become higher-value targets. At the same time, defenders may relax normal friction to keep operations running, which can create openings in authentication, device trust, and review discipline. The result is not just more exposure, but more concentrated exposure around a few critical entry points.

That concentration matters because attackers follow where the organisation becomes least resilient. If a crisis drives everyone to the same remote access pattern, the same mailbox workflow, or the same exception process, a weakness in one of those paths can affect many users at once. The same security model may still “work” on paper, but it no longer matches how people actually get work done under pressure.

Why Adapting Controls Matters More Than Perfect Policy

Crisis response is not a choice between control and no control. It is a choice between controls that reflect current conditions and controls that pretend normal conditions still exist. The practical difference is whether the organisation can still verify who is accessing what, from where, and under what constraints when the environment is stretched. Static rules often fail because they assume the same assurance level is appropriate even when identity, endpoint, and network trust have all changed.

For example, current guidance on risk management is most useful here when it is translated into operating decisions: tighten the controls that protect the highest-consequence systems, shorten approval paths only where the business can tolerate the trade-off, and treat temporary exceptions as time-bound and reviewable. Crisis does not eliminate the need for security judgment, it increases the need to apply it to the live conditions in front of you.

Risk and Threat Considerations

Static assumptions become dangerous in a crisis because they let exposure grow invisibly. The most common failure is not a dramatic collapse, but a slow mismatch between policy and reality, where more users, more devices, and more urgent access paths are allowed without equivalent monitoring or verification.

Failure mechanism: Staff shortages, remote access expansion, and rushed exceptions weaken endpoint assurance, gateway scrutiny, and review consistency, while attackers concentrate on the newly overused access paths and the least monitored recovery workflows.

Impact: Organisations can lose visibility into compromised endpoints, overlook suspicious email or VPN activity, and create a larger blast radius for credential theft, lateral movement, or unauthorised access during the exact period when response capacity is lowest.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyCrisis-driven exposure changes require risk decisions tied to current operating conditions.
PR.AA-05 — Identities Are Proofed and Bound to CredentialsRemote access and crisis exceptions depend on trustworthy identity verification.
DE.CM-01 — Networks and Network Services Are MonitoredCrisis periods increase the need to monitor remote gateways and email-heavy access paths.
Recommendation — Update risk decisions to match the changed crisis operating environment and resulting exposure. Reassess identity assurance for expanded remote access paths during crisis conditions. Increase monitoring on the access paths that become most active during the crisis.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeStatic crisis access models often overgrant access to keep work moving.
IA-2 — Identification and Authentication (Organizational Users)Remote work and urgent access make user authentication a central control.
Recommendation — Limit crisis-era access to the minimum permissions needed for the task. Revalidate user authentication strength for high-volume remote access.

Practitioner Guidance

What to prioritise: Start with the controls that gate broad access, not the ones that only protect isolated systems. In a crisis, the safest first move is usually to identify which remote access, endpoint, and email paths now carry the most operational load and verify they still meet minimum trust requirements.

What to verify: Confirm that temporary access changes have expiry dates, that high-risk exceptions are visible to security owners, and that logging still covers the paths people are actually using. If a control cannot be observed during the crisis, it is not giving you the assurance you think it is.

Practitioner takeaway: The objective is not to preserve the old security model under stress, it is to keep the control set aligned with current exposure, because crisis conditions punish assumptions that were only valid before operations changed.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org