In industry, privileged access builds up over years and is almost never a matter of bad intent. Someone once gave a machine service provider an account so they could check a fault remotely. Someone else set up a shared administrator account because it was quicker. A decade later it turns out nobody can answer a simple question: who holds the keys to the most important systems today.

The starting point

The group runs several production plants, each with its own history of systems and its own vendors. Administrative accounts were shared between members of the maintenance team, and passwords lived in a spreadsheet and in a few people’s heads. External companies had access granted years ago, with no expiry. There was no privileged session history, so after an incident there would be no way to establish who did what.

Why it was urgent

Two things came together. First, operational risk: with shared accounts, one stolen password opens the way to systems that control production, and in a plant that means a stoppage, not just an IT problem. Second, regulation. The NIS2 requirements directly touch access control and accountability, and responsibility rests with management. The board needed not declarations but evidence.

How we ran the rollout

We did not start by installing a tool. We started with an audit and an inventory: who really has privileged access, to what and on what basis. That list was the hardest part of the project and at the same time the most valuable, because it revealed the scale of previously invisible risk, including accounts left by people who had long since left the company.

Only then did we deploy Segura as the only way into critical systems. Admin passwords went into a vault and are rotated automatically, so they stopped being something anyone knows by heart. Access is granted by name and for the time of a specific task, and privileged sessions are recorded. The shared admin account stopped being a way of working.

We handled external company access separately, because it was the biggest unknown. Machine service providers and system vendors got access limited to the scope and time of a task, instead of an open-ended VPN account. From the plant’s point of view nothing got worse: the service provider still comes in when it must, only now it is clear who, when and what they did.

We rolled the whole thing out in stages, plant by plant and system by system, from the most critical. We ended each stage with a test that, for keeping operations running, mattered more than any report: at three in the morning, when a line stops, can the on-call person still get in where they need to. Security that cuts people off from work becomes a workaround within a week.

Finally we tied the project to the NIS2 requirements on access control and accountability, so that what was built technically could be shown to an auditor as a process.

What changed

Privileged access across the whole group now passes through one controlled point. There are no shared administrator passwords and no spreadsheet that was the company’s biggest secret. Every entry into a critical system is by name, time-limited and reconstructable after the fact, including for external companies.

A project worth over half a million zloty did not, however, buy a tool. It bought an answer to the question everyone had been afraid of: who holds the keys, and what did they do with them.