How IT-Style MFA Adopted for Compliance Unwittingly Drives Factory Operators to Bypass Security

Recently, the biggest topic for global manufacturing and infrastructure organisations is complying with global security regulations, most notably the European NIS2 Directive. To satisfy these requirements, many enterprises are hastily transplanting IT-style Multi-Factor Authentication (MFA)—a proven weapon in corporate environments—straight into Operational Technology (OT) domains.
Forcing users to receive smartphone push notifications or enter OTP codes just to log into control systems might make security teams relax over a fully ticked compliance checklist. However, whilst they celebrate, field operators are secretly deploying highly dangerous workarounds that completely dismantle the security framework. Overlooking the physical characteristics and technical limitations of OT environments carries a heavier price than anticipated.
The Technical Contradiction of Air-Gapped Networks and Smartphone Bans
The fundamental flaw of conventional IT-style MFA is its absolute reliance on 'real-time, bidirectional communication'. Whether it is a push notification, an SMS, or a cloud-synced OTP, the smartphone must establish a live session with an authentication server via the external internet, cellular networks, or corporate Wi-Fi.
Yet, critical infrastructure and core OT control networks operate under a strict air-gapped network environment, entirely severed from the outside world. In power dispatch centres, water treatment facilities, or gas supply stations where cellular signals cannot penetrate, an authentication method demanding external connectivity is fundamentally unviable. To make matters worse, high-security zones or advanced manufacturing floors legally prohibit the introduction of all external electronic devices, including smartphones, to prevent espionage and data leakage. An IT-style solution that cannot authenticate without a smartphone hits an insurmountable technical and physical wall right at the factory gate.
Physical Friction: Thick Protective Gloves and Shift Rotations

Even in areas where device entry or communication is permitted, IT-style authentication faces a formidable barrier: the uncompromising demand for operational availability, where a single minute of downtime translates into catastrophic financial losses.
When a plant engineer wrapped in cleanroom suits and wearing thick protective gloves rushes to an HMI screen to address an urgent equipment alarm, a prompt demanding they pull out a smartphone and perform secondary authentication is not a mere inconvenience—it represents a direct threat to production continuity. Furthermore, factories naturally operate on continuous shift rotations where multiple operators share a single master workstation. An IT-bound MFA tied to an individual's specific account or personal device shatters this collaborative operational structure.
'MFA Fatigue' Forcing Operators to Unlock Their Own Gates
Faced with the imperative to keep the plant running, field operators pushed by the friction of regulatory compliance inevitably begin searching for workarounds.
- Shared Authentication Assets: To accommodate shift changes, authentication smartphones or hardware tokens are left permanently plugged into a factory workstation or left abandoned in a corner for the entire shift crew to share.
- Unauthorised Programme Installations: To eliminate delays during critical incidents, engineers install unauthorised cracks or bypass tools directly onto control PCs to skip the MFA step entirely.
Security measures intended to fortify the facility end up triggering severe 'MFA Fatigue', perversely justifying security evasion in the eyes of the operators and creating a massive security vacuum. The ultimate Achilles' heel that hackers exploit is precisely this: the vulnerability created when field staff intentionally open a loophole because the security process makes their job impossible.
The Imperative for Non-Intrusive, Offline Dynamic Verification

Security that disrupts operator workflows and compromises availability is fundamentally unsustainable. Blaming human error or negligence will not solve the problem. The success of OT security hinges on securing an alternative architecture that delivers robust identity verification entirely in the background, without harming the user experience (UX) or relying on external networks.
The solution leading global enterprises are turning to is 'One-Way Offline Dynamic Authentication', which requires zero communication with external servers. This architecture generates time-synchronised, one-time dynamic security codes via mathematical algorithms, even when a device is completely offline—such as in aeroplane mode.
Crucially, to accommodate zones where smartphones are prohibited, this technology must not be confined to mobile applications. It must be flexible enough to be embedded directly within the software of the operator's work PC, or integrated into the form factor of a smart card (E-Paper) badge that engineers already carry. By validating these ephemeral codes in the background at the exact millisecond a login is attempted, operators can log in seamlessly as they always have without any extra steps. An OT-native authentication strategy that preserves both operational flow and physical isolation is the only definitive way to achieve compliance without sacrificing the survival of the plant.
--------------------

swIDch will continue its quest to innovate and pioneer next-generation authentication solutions. To stay up-to-date with the latest trends sign up to our newsletter and check out our latest solutions.

No matter how precisely you segment your internal factory network or how heavily you fortify your firewalls, true

Throughout the first half of 2026, industrial control systems (ICS) security teams globally have been stretched to

Countless enterprises invest massive budgets in visibility and vulnerability management solutions. But we must judge
Looking to stay up-to-date with our latest news?