Access doesn't disappear in the cloud - It just gets harder to see
What happened
SecurityBrief explains that third-party access does not disappear when systems move to the cloud — it becomes harder to see across hybrid on‑prem, OT and cloud estates. It points to the reformed Critical Infrastructure Risk Management Program (CIRMP) rules (in force since June 2026) that now list third‑party access as a named hazard, making live, accurate access evidence an operational requirement. Watch whether suppliers can deliver automated revocation and live access logs when asked during renewals
Why the category manager should care
This is an operational requirement, not a policy footnote: buyers must demand live evidence of who can access systems
Key facts
- CIRMP lists third-party access as a named hazard category
- Hybrid estates (on-prem, cloud, OT) hide contractor and standing-access gaps
- Regulatory expectation: ability to demonstrate current access status