Privileged access workstations: introducing our new set of principles
Principles-based guidance for organisations setting up a PAW solution.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

The NCSC has today published a new set of principles on privileged access workstations, or PAWs. When designed and implemented in the right way, PAWs are an indispensable tool for organisations to help defend against real-world cyber threats.
Any organisation, no matter the size, will benefit from reviewing their use of privileged access against these principles.
At its core, a privileged access workstation is a highly restricted and audited physical device that helps an organisation minimise the attack surface for its high-risk systems. Having a PAW in place makes these accesses significantly more difficult to compromise.
In practice, this means eliminating common methods that attackers might use to gain access to your system. For example, if your PAW device isn’t allowed to use email services, a threat actor can't use phishing to gain access to your devices or network.
The principles provide best-practice guidance to put in place a PAW solution. It is for your organisation to choose how to implement the principles for your own context. The principles explain this in more detail.
It’s also worth saying something more about why the principles have been written. Our secure system administration guidance recommends using PAWs, but it may not always be clear what a PAW is or when one is required. At a time when organisations face a range of different threats, there is a need to better protect paths to avoid privilege escalation to minimise the impact if an attack happens.
There are two excellent reasons why you should put a PAW solution in place.
Firstly, highly privileged administration interfaces are prime targets for attackers. Threat actors will attempt to compromise the devices used to access these interfaces, so it's crucial to ensure they aren’t easy targets. By utilising a PAW to access these interfaces, you significantly enhance security, making it considerably more challenging for threat actors to infiltrate high-privilege environments. Without a PAW, these highly privileged interfaces could be vulnerable, which could significantly impact your business's ability to operate.
Secondly, a well-implemented PAW supports the users who are managing your critical systems. It should be an enabling technology, balancing usability and security. It should also be designed to meet the specific needs of these users. When used with effective change management, this offers visibility of its users' needs and makes the use of shadow IT less likely.
It's common to view a PAW as a standalone device which is configured to a locked-down state, and then distributed. But this approach isn’t enough to ensure trust in the device, either when it's first set up, or throughout its lifecycle.
These principles highlight the importance of understanding your needs, integrating PAWs as part of broader controls, and building trust in these devices. Trust must be established through systems that enforce auditable and validated controls from a single source of truth, so that systems are designed and maintained to a unified standard.
It’s worth remembering that while PAWs are a critical control, they are just one component of the broader set of controls an organisation should use to defend against cyber threats.


