What happened
October brings a new wave of legally binding NIS2 deadlines across the European Union, as member states move from transposition into enforcement. In Austria the national implementation law enters into force once adopted, and in Poland a mandatory self-registration closes on a fixed date set by the national authority. The directive places direct obligations on organizations covering supply chain risk management, incident reporting and board-level accountability.
The penalty regime gives those obligations teeth. Essential entities face fines up to 10 million euros or 2 percent of global turnover, important entities up to 7 million euros or 1.4 percent, and management bodies face personal liability, including temporary bans from executive roles.
The 2026 Verizon Data Breach Investigations Report adds a data point on where the risk concentrates. Vulnerability exploitation has overtaken stolen credentials as the top initial access vector, at 31 percent of breaches. But credential abuse still appears in 39 percent of breaches measured across the full attack chain, and Verizon identifies it as a legitimate mitigation target chokepoint. Credentials do not just open the front door; they are how attackers move through the building once inside.
Why this is a GRC story
The practical argument for starting with identity and access management is that it is the fastest path to auditable evidence. The article compares two NIS2 Article 21 requirements: supply chain risk management runs 6 to 12 months of implementation work, while access control enforcement can be done in 2 to 4 weeks. Enforcing a fine-grained password policy, moving shared credentials into a managed vault and enabling phishing-resistant MFA for privileged accounts is a small project with immediate, examinable output.
The blind spot is non-human identity. Most IAM programs track human users, but auditors increasingly focus on service accounts, API keys and database connections. Unmanaged service accounts and API keys are a named pre-audit failure. If your access inventory stops at people, the audit will not.
The personal liability provision changes the conversation for executives. When board members can be banned from executive roles, compliance stops being an IT cost center and becomes a governance obligation. That is the shift NIS2 is designed to force, and IAM is the control where most organizations can demonstrate it fastest.
What to watch
Watch the national enforcement deadlines through October, especially Austria and Poland, and how the first wave of NIS2 audits actually tests access controls. Do not read the DBIR shift toward vulnerability exploitation as permission to deprioritize credentials. The data still says credential abuse runs through nearly 4 in 10 breaches, and access control is the control you can fix before the auditor arrives.
Attribution: Analysis based on Help Net Security's reporting and related public reporting. This article is original commentary, not a repost of the source material.
