Skip to main content

Access

Identity & Privileged Access

Ensure every action in OT is attributable to a person and privileges are minimal and time-bound.

Defensive guide

Why should I care?

Credential abuse features repeatedly in documented OT intrusions.

How to implement it

  • Named accounts for engineers and administrators; role accounts for operators only where the console model requires it
  • Separate OT identity from enterprise identity where the operating model allows
  • Tiered administration and privileged access management for OT servers

What good looks like

  • No shared administrative credentials
  • MFA on all human remote access
  • Joiner/mover/leaver process covers OT

Common failure modes

  • One 'engineer' account shared by a team
  • Enterprise domain admins implicitly administering OT

How to verify it

  • Review privileged group membership
  • Test that a departed contractor's access is gone