OT Security • Access Management

User Access Reviews for SCADA: Joiner, Mover, Leaver

Merobix Engineering • • 11 min read

Ask any operation for its SCADA user list and watch the pause. There is the operator who left in March and still has an active login, the integrator's account from a 2023 commissioning job, the manager carrying engineer rights from two roles ago, and the shared "field" password everyone swears they were going to retire. None of these are exotic failures - they are what happens by default when nobody reviews access. This guide gives you the joiner-mover-leaver discipline, a quarterly review process that actually finishes, fixes for role sprawl and contractor accounts, and the evidence trail that satisfies auditors and insurers.

Back to Blog

From the Merobix industrial security hub - every security, compliance & certification guide in one place.

4Reviews Per Year for Control-Capable Accounts
0Shared Logins Is the Only Acceptable Number
Day 1When a Leaver's Access Must End

Why Access Reviews Fail in OT - and Why That's Dangerous

In IT, a stale account leaks data. In OT, a stale account can open a valve. That asymmetry should make access reviews more disciplined in industrial operations, but in practice they are usually weaker - because OT access grows out of urgency. A unit is down at 2 AM, so someone gets admin "for now." An integrator needs access for commissioning, so an account appears with no end date. A retiring supervisor's login keeps working because the historian reports run under it and nobody knows what breaks if it dies.

Every one of those accounts is attack surface. Departed-employee credentials are a recurring feature in industrial incidents - CISA's joint advisory on threats to US water and wastewater systems specifically calls out former employees whose credentials remain improperly active - and in the insider threat picture generally - not because ex-employees are villains, but because their credentials outlive their loyalty, their laptops, and their password hygiene. A phished credential belonging to someone who left last year is the perfect intrusion: valid, privileged, and watched by no one. The access review is the control that finds these accounts before someone else does - and it is also, not incidentally, the control that auditors, cyber-insurance questionnaires, and frameworks from IEC 62443 to NERC CIP keep asking about by name.

Joiner, Mover, Leaver: The Lifecycle Behind the Review

Access reviews are the audit; joiner-mover-leaver (JML) is the process being audited. Get the process right and reviews become fast confirmations. Get it wrong and every review is an archaeology dig.

Stage What Should Happen The Common Failure
JoinerNamed account created from a documented request; least-privilege role for the actual job; site scope limited to assigned facilities; MFA enrolled before first login"Copy Dave's permissions" - inheriting years of Dave's accumulated access on day one
MoverAccess re-baselined to the new role: new permissions granted, old ones removed, sign-off from the new supervisorAddition without subtraction - the mover keeps everything and gains more; this is where role sprawl is born
LeaverSame-day revocation of platform accounts, active sessions, API keys, VPN, and any shared secrets they knew; access removal on the offboarding checklist next to the truck keysThe account that "we'll get to next week" and still works at the next audit - or the departure nobody told the SCADA admin about at all

Two details make the leaver step real rather than aspirational. First, revocation must kill live sessions, not just future logins - a platform with session revocation and a logout-everywhere control ends access now, while a platform that only disables the password ends it whenever the current session happens to expire. Second, revocation must cover non-human access: API keys, report credentials, and integrations created under the leaver's identity. Scoped API keys with a managed lifecycle and explicit revocation make this a checklist item instead of a scavenger hunt.

Role Sprawl: How Permissions Accumulate

Role sprawl is entropy applied to authorization. Granting access has a deadline and a requester; removing it has neither. Run that asymmetry for five years and you get accounts whose permissions describe their careers instead of their jobs.

The structural fixes:

Running a Quarterly Review That Actually Finishes

Access reviews die of scope. The fix is a tight, repeatable procedure - the discipline that the account-management controls in NIST SP 800-53 formalize - and for a typical operation this is a half-day, quarterly:

  1. Export the full account list from the SCADA platform: humans, contractors, service accounts, and API keys, with role, site scope, and last-login timestamp.
  2. Flag the mechanical findings first. No login in 90 days; accounts for people not on the current employee or contractor roster; expired engagements; API keys with no known owner. This is half your findings in ten minutes.
  3. Have supervisors certify their own people. The control-room lead reviews operators; engineering reviews engineers. The reviewer must be someone who knows what the person actually does - a security admin cannot certify need-to-know alone.
  4. Challenge privilege, not just existence. For every admin, engineer, and control-capable account: does the current job require it? "Has not used it in six months" is a strong argument for removal.
  5. Revoke immediately, in the meeting. Findings queued for later have a way of surviving until the next review. Disable first; anyone who genuinely needs access back will tell you within a day, loudly.
  6. Record everything: who reviewed, what was found, what changed, dated and signed. This artifact is your audit evidence and next quarter's baseline.

Event-driven reviews sit on top of the calendar: same-day for leavers, at role change for movers, and a full sweep after incidents, acquisitions, or vendor transitions. If this quarterly rhythm feels heavy, note that it is one line item in the broader 30-point OT security self-audit - and the one with the best findings-per-hour ratio.

Contractors, Integrators, and Vendor Accounts

Third-party access breaks every assumption the JML process makes: there is no HR record to trigger offboarding, engagements end fuzzily, and the temptation to share one "integrator" login across a firm is strong. The rules that keep it controlled:

Competency Checks: Authorization Is More Than Security

In OT, "should this account be able to write this setpoint" has two components: permission (their role allows it) and competency (they are trained and current on that equipment). Most platforms only model the first. The gap matters: an authorized-but-unqualified write is how a well-meaning new hire trips a unit. Merobix models both - control actions can require role and competency checks, high-risk workflows such as permit signing can demand step-up re-authentication at the moment of action, and management-of-change and pre-startup safety review gates can stand between a command and the process where configured. For the full command-path picture - writable-tag allowlists, setpoint bounds, read-back verification - see our remote control security guide. At review time, this adds one question per control-capable account: is the training current? A lapsed competency should suspend control rights as surely as a lapsed engagement suspends a contractor.

What the Platform Must Give You

A quarterly review is only as good as the tooling underneath it. The platform capabilities that turn this article from theory into a half-day task:

Merobix ships each of these as platform behavior, which is the difference between an access review that takes an afternoon and one that takes a maintenance window. The details live on the security architecture page.

Evidence: What Auditors Actually Want to See

Whether the request comes from a customer audit, an insurer, or a regulator, the ask is the same: prove the reviews happen and prove they bite. That means the dated review artifact - account list, reviewers, findings, actions - plus the platform audit trail showing the revocations landing at specific timestamps, plus the ability to answer "when did this specific person's access end?" with a record instead of a shrug. One practical warning: a review log showing zero findings quarter after quarter reads as a rubber stamp, because healthy reviews almost always catch something. Findings are not embarrassing; they are the review working.

Key takeaway: access reviews are not bureaucracy - they are the scheduled destruction of the accounts an attacker would love most. Run joiner-mover-leaver with same-day leaver revocation, re-baseline movers instead of stacking them, expire contractors at creation, review control-capable accounts quarterly, and keep the evidence. On a platform with graded roles, site scoping, session revocation, and immutable audit records, the whole discipline costs a half-day per quarter. See it working in a live demo.

Frequently Asked Questions

How often should SCADA user access be reviewed?

Quarterly for accounts that can execute control actions or administer the platform, and at least semi-annually for view-only accounts - plus event-driven reviews that do not wait for the calendar: same-day revocation when someone leaves, a role re-baseline when someone changes jobs, and a full review after any incident or vendor transition. Quarterly is the cadence most security frameworks and auditors treat as standard for privileged access, and in OT nearly every operator or engineer account qualifies as privileged.

What is the joiner-mover-leaver process?

Joiner-mover-leaver (JML) is the lifecycle discipline behind access control. Joiners get named accounts with the least privilege their documented job requires, granted through a request that records who approved what. Movers - people changing roles - have access re-baselined to the new role rather than accumulating the old one on top. Leavers have every access revoked the same day: platform accounts, sessions, API keys, VPN, and shared credentials they knew. Access reviews exist to catch what this process missed, and the mover step is where most organizations fail.

How should contractor access to SCADA systems be handled?

Named individual accounts (never a shared integrator login), scoped to the specific sites and roles the engagement requires, with an expiry date set at creation and an internal sponsor accountable for the account. Review contractor accounts on every quarterly cycle with a bias toward disabling anything not actively used, and revoke access the day the engagement ends. In a platform with site-level authorization, scope contractors to only their sites - a commissioning contractor for one facility has no business seeing the rest of the fleet.

What is role sprawl and how do I fix it?

Role sprawl is the slow accumulation of permissions that outlive their reason: the operator who kept admin rights from a project three years ago, the manager with engineer access from a previous role, the temporary grant that became permanent because nobody removed it. It happens because granting access is urgent and removing it never is. The fix is structural: define a small set of standard roles, re-baseline access on every job change instead of adding to it, time-limit exceptional grants, and use quarterly reviews to strip anything the account's current job does not require.

What evidence do auditors want from access reviews?

A dated record for each review cycle showing the account list that was reviewed, who reviewed it, what was found, and what changed - with revocations traceable in the platform's audit trail at specific timestamps. Auditors distrust reviews with zero findings, since healthy reviews almost always catch something. Keep the review artifact (spreadsheet or export, sign-offs, remediation list) alongside the platform's immutable audit records, and be able to demonstrate that a specific leaver's access ended on a specific date.

Sources & Further Reading

Access Control You Can Actually Review

Graded roles, site-level scoping, same-day session revocation, scoped API keys, and immutable audit records - the tooling that turns quarterly reviews into a half-day habit.

Request a Demo → See Our Security Architecture
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →