NIS2 Turns a Blind Eye No More: Why Maintenance Access Is Now a Board-Level Risk
Published on 10/10/2026 at 04:01 | Editorial boerse-global.de
Roughly half of all security incidents in operational technology trace back to external access. For years, industrial operators treated that exposure as a cost of doing business. Under Europe's revised cybersecurity rules, that calculation no longer holds.
The problem is rarely a sophisticated intrusion. More often, it is an outside technician moving through a production network with little oversight, while a sprawling mix of tools makes locking things down even harder.
Where access control quietly fails
Industry analyses point to a common root cause: remote access gets treated as an IT convenience rather than a resilience control that matters. Sessions run by external service providers, scheduled maintenance windows and short-notice emergency support routinely slip past normal approval and logging procedures. The result is a documentation gap — no reliable record of who changed what, or when.
Shared contractor accounts handed out informally, emergency access that nobody watches closely, and inconsistent logging round out the familiar weak points. Then there is the slow creep of temporary permissions that never get closed. Maintenance exceptions stay open long after the job is done, lingering as permanent entry points.
For remote connections to machines and plant equipment, companies typically choose between classic VPN links, screen sharing over VNC, or browser-based visualisation. In mechanical engineering, VPN setups lean on protocols such as OpenVPN, WireGuard and IPsec.
Each carries its own hazards: weak authentication, permissions that reach too far, outdated software versions. And as user numbers, distributed sites and mobile devices multiply, the approach runs into functional limits.
What NIS2 demands — and what non-compliance costs
Under the European NIS2 Directive, operational exceptions must be classified as first-class risk events. That means named responsible parties, fixed time limits, and full logging of every action taken.
For industrial companies, serious incidents trigger strict reporting deadlines under Article 23: an early warning within 24 hours, a detailed notification after 72 hours, and a final report after one month.
Penalties are steep. Essential entities face sanctions of at least €10 million or 2% of worldwide annual turnover; important entities face at least €7 million or 1.4% of worldwide turnover.
In Germany, Section 30(2) of the BSI Act sets out ten minimum measures for operators, covering access control, supply chain security and continuity of operations.
The frameworks pointing the way
International standards offer established reference points for implementing secure access and segmentation, notably NIST SP 800-53 Revision 5 and NIST SP 800-82 Revision 3. Spain's cybersecurity agency INCIBE, drawing on IEC 62443, goes further: it recommends blocking inbound direct connections into operational technology altogether.
Access instead should flow only through gateways in decoupled zones, VPN connections protected by multi-factor authentication, and least-privilege permissions granted for tightly bounded periods.

