Blog - swIDch

Access Control Limits in NIS2 OT Audits

Written by Admin | Aug 11 2026

 

As the European Union enforces the NIS2 Directive, industrial organisations across global supply chains are overhauling cybersecurity architectures to satisfy regulatory demands. Most enterprises deploy VPNs, multi-factor authentication (MFA), and privileged access management (PAM) solutions at the IT and OT boundary, assuming these measures fulfil NIS2 access control requirements.

 

However, detailed NIS2 field audits and technical inspections regularly reveal a critical structural gap. Traditional controls fail to answer a fundamental question: once a session is established, who actually accesses the endpoint, and how is non-repudiation achieved?

 

NIS2 Article 21 Requirements for Access Control

Under Article 21 of the NIS2 Directive and guidance from ENISA (European Union Agency for Cybersecurity), organisations must implement robust asset management, access control, and comprehensive logging for incident investigation. Regulatory audits applying Zero Trust principles scrutinise whether network users possess legitimate authority for every accessed endpoint and action.

A central friction point during technical audits is whether session authorisation guarantees the legitimacy of control access. Even if third-party contractors or internal engineers access the OT network through a PAM gateway, downstream connections to engineering workstations (EWS) or programmable logic controllers (PLCs) often strip the user's distinct identity. From an audit perspective, leaving endpoints unprotected by individual identity verification leaves access control incomplete.

 

Operational Gaps Exposed by SANS and CISA

Control systems expert Joe Weiss highlighted this vulnerability, noting that IT access controls fail to identify who accesses endpoints at the control layer, leading endpoints to execute received packets indiscriminately. Data from SANS Institute ICS surveys confirms that over half of global OT environments still depend on shared accounts or static long-standing sessions.

This structural limitation directly causes real-world incidents. Recent infrastructure advisories from CISA demonstrate how attackers leverage stolen remote maintenance accounts to enter authenticated sessions and alter control parameters. Because control systems register these actions as legitimate operator activity, real-time blocking fails. Furthermore, post-incident forensics frequently fail to link specific endpoint access to individual human operators, directly violating the accountability and non-repudiation mandates of NIS2 Article 21.

 

 

Extending Accountability to Endpoint Access Control 

Modern OT security demands extending access controls from network perimeters down to the endpoint layer before any execution occurs.

True access control must explicitly verify user identity and authority at the endpoint level before session or control privilege is granted. Generating undeniable audit trails for individual access events enables organisations to prove access legitimacy and demonstrate genuine accountability without interrupting operational continuity.

For CISOs, regulatory readiness requires more than checklist compliance. Meeting ENISA guidelines and global standards necessitates authenticating individual identities at the endpoint access layer prior to execution, securing regulatory compliance while safeguarding operational integrity. 

 

 

--------------------

 

swIDch will continue its quest to innovate and pioneer next-generation authentication solutions. To stay up-to-date with the latest trends sign up to our newsletter and check out our latest solutions.