Security1 distinct publisher3 min readPublished
Essential entities face up to EUR 10 million or 2 percent of global turnover, and management bodies can be barred from executive roles, which makes access control the one Article 21 requirement a team can finish and evidence inside a month.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
An auditor and an intruder open with the same request: list every account that can reach a production system. Article 21(2)(i) requires access control policies to cover all accounts with access to network and information systems, and Help Net Security reports that auditors increasingly read that to include non-human identities [13]. Service accounts, API keys, database connection strings and deployment tokens sit in .env files, CI/CD pipeline configuration and shared drives, which is where attackers look once they are inside [14]. The same publication says a typical mid-size organisation holds more service accounts than human ones, most of them sharing passwords, never rotated, with no documented owner [15].
The penalty arithmetic is worth doing once. Divide each flat ceiling by its percentage: 10 over 0.02 is 500, and 7 over 0.014 is also 500 [19]. Both tiers hinge on the same point, EUR 500 million of global turnover. Below it the flat cap is the bigger number in your risk register; above it the percentage is, and it tracks revenue.
Converted into weeks, the supply chain programme runs between 6.5 and 26 times the calendar of the access control work [20]. The short project has a defined scope: a fine-grained password policy across Active Directory, shared credentials moved into a managed vault, and phishing-resistant MFA on privileged accounts [12].
The Verizon figures need care before anyone quotes them at a steering committee. The initial-access ranking and the full-chain measurement use different frames, one counting how breaches begin and the other counting where credential abuse turns up anywhere in the sequence [8][9]. The eight-point gap between the two is not a like-for-like result [21]. What survives the reframing is Verizon's own label for credential abuse, a legitimate mitigation target chokepoint [9].
What the article does not supply is a date. Austria's national implementation law enters into force once adopted, and Poland's mandatory self-registration closes on a fixed date set by the national authority, with neither date named [3][4]. The fine tiers and the executive ban attach to those national instruments, so the operative deadline comes from the member-state authority rather than from the directive text.
Dormant accounts fail the same article, which requires lifecycle management [16]. The mechanism is procedural rather than malicious: HR closes the ticket, IT disables the Active Directory account, and nobody checks the direct database access, the VPN certificate, the AWS IAM user or the SSH keys on three production servers, because no single system tracks them [17]. Access reviews have to be documented and exportable [18], which is the useful part of the whole exercise: the review that revokes those credentials is the same file you hand the auditor.
Ranked by verification strength, evidence, and original report placement.
Article 21(2)(i) requires access control policies to cover all accounts with access to network and information systems, and auditors increasingly include non-human identities such as service accounts in that scope.
Dormant accounts are a direct audit failure point under Article 21(2)(i), which requires access control policies to include lifecycle management.
The NIS2 Directive places direct obligations on organisations across supply chain risk management, incident reporting, and board-level accountability.
NIS2 non-compliance exposes essential entities to fines of up to EUR 10 million or 2 percent of global turnover, and important entities to up to EUR 7 million or 1.4 percent.
NIS2 exposes management bodies to personal liability, including temporary bans from executive roles.
The 2026 Verizon Data Breach Investigations Report found vulnerability exploitation overtook stolen credentials as the top single initial access vector, accounting for 31 percent of breaches.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
Exploited software flaws now open more breaches than stolen credentials do1 distinct publisher
security
43 days, 26 percent, and a pitch that saves you 29 minutes1 distinct publisher
security
Ransomware's victim list barely moves: 73% of disclosed hits landed on mid-market firms1 distinct publisher
security
Benchmarking AI On Bug Hunting Scores 31% Of The Breach Problem1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Solid statute, borrowed statistics, invented clock
The material splits three ways. Penalty tiers, management liability and the wording of Article 21 are law and stand on their own. The 31 percent and 39 percent breach figures are relayed from a Verizon report that Help Net Security names but never links or paginates. The '6 to 12 months' and '2 to 4 weeks' ranges have no survey, sample or estate size behind them — they are the author's judgement presented in the same typography as the statute.
Nobody counted anything
There is no measurable uptake to report: no registration tally from the Polish authority, no enforcement action, no count of entities that have completed the access-control work or deployed the vault Help Net Security recommends. This is advice about a deadline, not a record of what organisations have done about it.
A countdown with no dates on it
October is the reason to read this, yet the Austrian law arrives 'once adopted' and the Polish window closes on 'a fixed date set by the national authority'. Meanwhile the two numbers used to reinstate credentials as the top priority are measured on different frames — full attack chain against initial access — and the eight-point margin is treated as though it settles the comparison. The urgency is real in outline and unevidenced in specifics.
Three gaps, one vendor, in order
Read the ending first and the argument reorganises itself. The three failures — unmanaged service accounts, broken offboarding, MFA exceptions — map one-to-one onto Passwork's per-secret ownership and rotation, AD/LDAP lifecycle integration, and WebAuthn support, with 'the quarterly access review becomes a report export' as the closing line. That does not make the law wrong. It does mean the two-week estimate, the 'auditors increasingly' claim and the decision to rank credentials above patching are all coming from an interested party.
Trust the law, verify the clock
We are confident about what NIS2 says and confident about who is telling us; we are not confident about the dates, the effort, or the second-hand breach percentages. A single trade outlet with a product at the end of the page is enough to raise the question and not enough to close it — a compliance team should reproduce the national deadlines from its own authority before scheduling anything against them.