Because crisis conditions change both attacker behavior and defender capacity. Budgets shrink, staff are stretched, and remote access expands the attack surface at the same time. If teams keep using the same assumptions, they miss weaknesses in endpoints, VPNs, email access, and web platforms. Adapting controls to current operating conditions reduces the gap between policy and reality.
Why Crisis Conditions Expose the Weakness in Static Security Models
A crisis changes the operating environment faster than many security models can absorb. The key problem is not only more risk, but different risk: wider remote access, compressed decision time, and less tolerance for manual checks. A model built for normal operations often assumes stable staffing, stable networks, and stable user behavior, so it underestimates the new attack paths that appear when those assumptions break.
Security controls are only as strong as the conditions they were designed for. When those conditions shift, controls that once looked adequate can become too slow, too narrow, or too dependent on human review. Crisis periods therefore expose where policy, detection, and access decisions were tuned for routine work instead of degraded, high-pressure operations.
What Changes in the Attack Surface During a Crisis?
Several things change at once. Remote work expands the number of endpoints and home networks in play, email and collaboration tools become even more central, and VPNs or remote access gateways become higher-value targets. At the same time, defenders may relax normal friction to keep operations running, which can create openings in authentication, device trust, and review discipline. The result is not just more exposure, but more concentrated exposure around a few critical entry points.
That concentration matters because attackers follow where the organisation becomes least resilient. If a crisis drives everyone to the same remote access pattern, the same mailbox workflow, or the same exception process, a weakness in one of those paths can affect many users at once. The same security model may still “work” on paper, but it no longer matches how people actually get work done under pressure.
Why Adapting Controls Matters More Than Perfect Policy
Crisis response is not a choice between control and no control. It is a choice between controls that reflect current conditions and controls that pretend normal conditions still exist. The practical difference is whether the organisation can still verify who is accessing what, from where, and under what constraints when the environment is stretched. Static rules often fail because they assume the same assurance level is appropriate even when identity, endpoint, and network trust have all changed.
For example, current guidance on risk management is most useful here when it is translated into operating decisions: tighten the controls that protect the highest-consequence systems, shorten approval paths only where the business can tolerate the trade-off, and treat temporary exceptions as time-bound and reviewable. Crisis does not eliminate the need for security judgment, it increases the need to apply it to the live conditions in front of you.
Risk and Threat Considerations
Static assumptions become dangerous in a crisis because they let exposure grow invisibly. The most common failure is not a dramatic collapse, but a slow mismatch between policy and reality, where more users, more devices, and more urgent access paths are allowed without equivalent monitoring or verification.
Failure mechanism: Staff shortages, remote access expansion, and rushed exceptions weaken endpoint assurance, gateway scrutiny, and review consistency, while attackers concentrate on the newly overused access paths and the least monitored recovery workflows.
Impact: Organisations can lose visibility into compromised endpoints, overlook suspicious email or VPN activity, and create a larger blast radius for credential theft, lateral movement, or unauthorised access during the exact period when response capacity is lowest.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Crisis-driven exposure changes require risk decisions tied to current operating conditions. |
| PR.AA-05 — Identities Are Proofed and Bound to Credentials | Remote access and crisis exceptions depend on trustworthy identity verification. | |
| DE.CM-01 — Networks and Network Services Are Monitored | Crisis periods increase the need to monitor remote gateways and email-heavy access paths. | |
| Recommendation — Update risk decisions to match the changed crisis operating environment and resulting exposure. Reassess identity assurance for expanded remote access paths during crisis conditions. Increase monitoring on the access paths that become most active during the crisis. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Static crisis access models often overgrant access to keep work moving. |
| IA-2 — Identification and Authentication (Organizational Users) | Remote work and urgent access make user authentication a central control. | |
| Recommendation — Limit crisis-era access to the minimum permissions needed for the task. Revalidate user authentication strength for high-volume remote access. | ||
Practitioner Guidance
What to prioritise: Start with the controls that gate broad access, not the ones that only protect isolated systems. In a crisis, the safest first move is usually to identify which remote access, endpoint, and email paths now carry the most operational load and verify they still meet minimum trust requirements.
What to verify: Confirm that temporary access changes have expiry dates, that high-risk exceptions are visible to security owners, and that logging still covers the paths people are actually using. If a control cannot be observed during the crisis, it is not giving you the assurance you think it is.
Practitioner takeaway: The objective is not to preserve the old security model under stress, it is to keep the control set aligned with current exposure, because crisis conditions punish assumptions that were only valid before operations changed.
Related resources from NHI Mgmt Group
- What is secrets exposure in NHI security?
- How do security teams reduce exposure during the patch gap without relying on patching alone?
- Why do organisations need an identity-centric security model when a single compromised identity can create broad exposure?
- Why do AI and large language model deployments increase the chance of secret exposure in organisations?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org