Technology

NIS2 Enforcement Puts Access Control in Business Applications Under the Spotlight

European organisations are navigating a regulatory shift that reaches deeper into their IT environments than many anticipated.

The NIS2 Directive, formally adopted as Directive (EU) 2022/2555, required EU member states to transpose its provisions into national law by 17 October 2024.

With enforcement actively underway across the bloc in 2026, the directive’s requirements around access management are forcing companies to scrutinise areas they previously treated as internal housekeeping, including the permissions structure inside their own ERP systems.

The conversation is no longer limited to firewalls and endpoint protection. NIS2 explicitly calls for policies on access control and asset management, which means the internal configuration of business-critical software is now a compliance matter.

For organisations running Microsoft Dynamics 365 Business Central or similar platforms, this raises pointed questions about who holds which permissions, and whether those permissions are properly documented and reviewed.

Ensuring proper security for your Dynamics environment goes beyond perimeter defences. It demands a structured approach to authorisation design, segregation of duties, and continuous monitoring of user permissions.

These are precisely the areas where many organisations discover significant gaps once they begin mapping their access controls to the directive’s requirements.

What the directive demands on access management

Article 21 of the NIS2 Directive lists access control policies as one of the minimum cybersecurity risk-management measures that essential and important entities must implement.

This is not a best-practice suggestion; it is a legal obligation backed by potential administrative fines that can reach into the millions for essential entities.

The scope covers sectors ranging from energy and transport to digital infrastructure and ICT service management.

What makes this requirement significant is its breadth. Access control does not only mean managing Active Directory accounts or VPN credentials.

It extends to every system that processes sensitive business data, including financial applications, supply chain tools, and ERP platforms where purchasing, payments and reporting converge.

Regulators are increasingly aware that poorly configured application-level permissions can be as dangerous as an unpatched server.

A user with excessive rights in an ERP system could approve their own purchase orders, manipulate financial records, or export customer data without triggering a single alert.

ERP permissions as a blind spot in cybersecurity strategy

Most cybersecurity strategies focus heavily on network security, endpoint detection and identity management at the infrastructure level.

Application-level authorisation, the specific set of permissions a user holds within a system like Business Central, tends to fall between the responsibilities of IT security and application management.

Neither team fully owns it, and the result is often a permission structure that has grown organically over years without proper review.

The risk is tangible. When an employee changes roles, their old permissions frequently remain active alongside the new ones.

Over time, this permission creep creates accounts with far more access than any single role requires, and in environments subject to SOx or GDPR obligations, this has long been a known audit finding.

Breda-based software company 2-Controlware has been building authorisation tooling for Microsoft Dynamics environments for over 17 years, specifically to address this kind of challenge.

Their Authorization Box product provides conflict detection and continuous monitoring of user permissions within Business Central, capabilities that align directly with what NIS2 now expects of covered organisations.

Segregation of duties under growing regulatory pressure

Segregation of duties, the principle that no single user should be able to execute a complete critical process from start to finish, has long been a cornerstone of financial auditing.

NIS2 does not use the term explicitly, but its requirement for policies and procedures to assess the effectiveness of cybersecurity risk-management measures implicitly demands this level of control.

The Digital Operational Resilience Act (DORA), in effect since January 2025, reinforces similar expectations for financial entities.

Implementing segregation of duties at the ERP level is notoriously difficult without dedicated tooling.

Business Central’s native permission system comprises hundreds of permission sets that interact in ways hard to trace manually.

Identifying where a conflict exists, for instance between a user who can both create vendors and approve payments, requires a matrix approach that checks every combination systematically.

Guidance published by the European Union Agency for Cybersecurity (ENISA) emphasises that access control measures should be proportionate and risk-based.

For organisations processing significant financial data through their ERP system, proportionate increasingly means automated and auditable rather than manual and ad hoc.

Preparing for audits in a changed landscape

As national authorities ramp up enforcement of their NIS2 transposition laws, organisations should expect auditors to ask specific questions about application-level access controls.

Can you demonstrate who has access to what in your financial systems? Can you prove that segregation of duties is maintained across critical processes? Can you produce a log of permission changes over the past twelve months?

Answering these questions confidently requires more than spreadsheets and occasional screenshots.

Security for your Dynamics environment, viewed through the lens of NIS2, means maintaining a continuous, documented and reviewable process for managing authorisations.

Configuring roles once during implementation and never revisiting them no longer passes muster.

Organisations that have not yet mapped their ERP access structures against the directive’s requirements should treat this review as urgent rather than aspirational.

The regulatory perimeter around cybersecurity has expanded, and the permissions inside business applications now sit squarely within it.

Kavichselvan

Kavichselvan is a Cybersecurity Enthusiast and Journalist covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago