Skip to main content

Privileged access workstations: introducing our new set of principles

Principles-based guidance for organisations setting up a PAW solution.
, ,
Natthaphon Wanason via Getty Images

The NCSC has today published a new set of principles on privileged access workstations, or PAWs. When designed and implemented in the right way, PAWs are an indispensable tool for organisations to help defend against real-world cyber threats. 

Any organisation, no matter the size, will benefit from reviewing their use of privileged access against these principles.

What is a PAW ?

At its core, a privileged access workstation is a highly restricted and audited physical device that helps an organisation minimise the attack surface for its high-risk systems. Having a PAW in place makes these accesses significantly more difficult to compromise.

In practice, this means eliminating common methods that attackers might use to gain access to your system. For example, if your PAW device isn’t allowed to use email services, a threat actor can't use phishing to gain access to your devices or network.

How should I use the principles?

The principles provide best-practice guidance to put in place a PAW solution. It is for your organisation to choose how to implement the principles for your own context. The principles explain this in more detail.

It’s also worth saying something more about why the principles have been written. Our secure system administration guidance recommends using PAWs, but it may not always be clear what a PAW is or when one is required. At a time when organisations face a range of different threats, there is a need to better protect paths to avoid privilege escalation to minimise the impact if an attack happens.

Why do I need a PAW – what’s in it for me?

There are two excellent reasons why you should put a PAW solution in place.

Firstly, highly privileged administration interfaces are prime targets for attackers. Threat actors will attempt to compromise the devices used to access these interfaces, so it's crucial to ensure they aren’t easy targets. By utilising a PAW to access these interfaces, you significantly enhance security, making it considerably more challenging for threat actors to infiltrate high-privilege environments. Without a PAW, these highly privileged interfaces could be vulnerable, which could significantly impact your business's ability to operate.

Secondly, a well-implemented PAW supports the users who are managing your critical systems. It should be an enabling technology, balancing usability and security. It should also be designed to meet the specific needs of these users. When used with effective change management, this offers visibility of its users' needs and makes the use of shadow IT less likely.

Isn’t a PAW just a locked-down device?

It's common to view a PAW as a standalone device which is configured to a locked-down state, and then distributed. But this approach isn’t enough to ensure trust in the device, either when it's first set up, or throughout its lifecycle.

These principles highlight the importance of understanding your needs, integrating PAWs as part of broader controls, and building trust in these devices. Trust must be established through systems that enforce auditable and validated controls from a single source of truth, so that systems are designed and maintained to a unified standard.

It’s worth remembering that while PAWs are a critical control, they are just one component of the broader set of controls an organisation should use to defend against cyber threats.

David G, Senior Cyber Physical Security Architect

Tom B, Senior Telecoms Security Consultant

Tim D, Senior Security Architect

Written by

David G Security Architect NCSC
Tom B Senior Telecoms Security Consultant, NCSC
Tim D Senior Security Architect, NCSC