NIS2 and DORA compliance starts at the service desk
Both regimes require that identity is verified before privileged actions are performed, and that you can prove it afterwards. Most organisations still leave that decision to an agent on a phone call.
01 · THE GAP
The control your framework probably does not cover
You have MFA. You have conditional access. You have a privileged access management tool.
Then a user calls the service desk and says they have lost their phone. In that moment every one of those controls is suspended, and the decision to restore access rests on an agent's judgement about a voice on a line. Social engineering attacks on IT help desks cost MGM Resorts and Clorox more than $480 million between them, and both started with a single phone call.
Under NIS2 and DORA this is no longer only an operational weakness. It is a control gap a supervisor can ask you to evidence.
FastPass Identity Verification Manager(opens in new tab) (IVM) closes it. IVM enforces a policy-driven verification workflow(opens in new tab) inside your existing ITSM platform, decides the outcome by rule rather than by agent discretion, and writes the evidence straight back to the ticket.
02 · THE REQUIREMENT
What the regulations actually say
» EU · NIS2 DIRECTIVE
Directive (EU) 2022/2555
Applies to essential and important entities across energy, transport, banking, health, water, digital infrastructure, public administration and manufacturing.
| Requirement | Reference | At the service desk |
|---|---|---|
| Access control policies and human resources security | Art. 21(2)(i) | Access restoration must follow a defined policy, not agent habit |
| Multi-factor or continuous authentication | Art. 21(2)(i) | The factor must still hold when the user calls to bypass it |
| Incident handling | Art. 21(2)(b) | A social engineering attempt must be detectable and reportable |
| Supply chain security | Art. 21(2)(d) | An outsourced service desk sits inside your risk management |
| Management body accountability | Art. 20 | Boards approve the measures and can be held personally liable |
| Reporting deadlines | Art. 23 | Early warning within 24 hours, notification within 72 hours |
Supervisory fines reach EUR 10 million or 2% of global annual turnover for essential entities, and EUR 7 million or 1.4% for important entities.
» EU · DORA
Regulation (EU) 2022/2554
Directly applicable to financial entities across the EU since 17 January 2025. The operational detail sits in the RTS on ICT risk management, Commission Delegated Regulation (EU) 2024/1774.
| Requirement | Reference | At the service desk |
|---|---|---|
| Strong authentication mechanisms | DORA Art. 9(4)(d) | Credential restoration is an authentication event and needs the same rigour |
| Least privilege and access rights administration | DORA Art. 9(4)(c) | Agents should not hold standing rights over the identities they support |
| Identity management | RTS Art. 20 | Unique identity, accountable actions, controlled lifecycle |
| Access control policy | RTS Art. 21 | Need-to-know, account lifecycle, authentication proportionate to risk |
| Logging | RTS Art. 12 | Access events recorded, retained and available for reconstruction |
| ICT third-party risk | DORA Art. 28 to 30 | Contracted service desk providers must meet the same standard |
DORA has no fixed fine schedule. Supervisors can require remediation, restrict arrangements with providers, and hold named senior managers responsible.
Neither regime asks whether you have a verification procedure written down. Both ask whether it was applied, every time, and whether you can produce the record.
03 · THE MAPPING
Where FastPass IVM meets the requirement
The security team defines the policy. IVM runs it. The agent sees a workflow with a pass or fail outcome and cannot skip a mandatory proofing step or improvise an alternative. Verification is scored, so weak factors alone do not clear the threshold, and the required score differs by user group, request type and risk signal. Factors include Microsoft Entra ID, Okta, Duo, RSA, TOTP, smartcard, SMS, email, manager approval, device confirmation from an enrolled workstation, and encrypted HR keyword data where the agent sees only match or no-match.
Every attempt is logged, including the ones that failed or were abandoned. The record captures the factors presented, the score reached, the outcome, the timestamp, the agent identity and the ticket reference, and it is written back into the ITSM ticket. Audit data sits in SQL Server and can feed Microsoft Sentinel, Splunk or any SIEM through database access or ETL. Two practical consequences. An auditor sampling tickets sees system-generated evidence rather than an agent's free-text note. And a cluster of failed verifications against one identity becomes a signal you can act on inside the 24-hour NIS2 early warning window.
Agents run the full IVM workflow without elevated directory rights. The privileged action, whether an Entra ID password reset, an MFA re-enrolment or an account unlock, is executed by the system only once the verification policy has been satisfied. Between 50% and 60% of FastPass customers have removed agent directory privileges on this basis. That turns a permanent standing-privilege finding into a controlled, evidenced transaction.
A TAP bypasses MFA by design, which makes it the highest-value item a social engineer can ask for. IVM issues a TAP only after the policy for that user has been met, and logs the issuance against the verified session. As Microsoft moves Entra ID towards passwordless, TAP volume rises and this control moves from useful to load-bearing.
A warehouse worker without a smartphone and a domain administrator should not clear the same bar. IVM sets separate policies by group, so routine requests stay fast while privileged accounts, finance staff and executives are pushed through stricter combinations. Proportionality is a stated principle in both regimes, and this is what it looks like in practice.
Attackers also impersonate the service desk to harvest credentials from employees. IVM supports reverse verification, where the end user confirms the caller is a genuine agent through a desktop or browser flow that only functions while that agent has the user open in IVM, with the agent's name displayed for confirmation.
If a managed service provider runs your first line, DORA treats them as an ICT third-party service provider and NIS2 treats them as supply chain risk. Contractual language alone does not evidence enforcement. FastPass IVM is deployed multi-tenant by MSPs, so the policy you define is the policy their agents execute, and the audit trail lands in your ticket rather than in theirs.
04 · COMPARISON
Legacy service desk against verified service desk
| Typical service desk | With FastPass IVM | |
|---|---|---|
| Verification method | Knowledge questions, caller ID, voice recognition | Scored combination of MFA, device, HR data and approval |
| Who decides | The agent, under time pressure | The policy, enforced by the system |
| Deepfake and vishing exposure | High, the control is human perception | Low, no factor depends on how the caller sounds |
| Agent privilege | Standing rights over directory objects | No standing rights required to run verification |
| Audit evidence | Free-text note reading "ID verified" | System record of factors, score, outcome, timestamp, agent, ticket |
| Failed attempts | Usually not recorded at all | Logged and available to SIEM |
| Policy change | Retraining, memos, hope | Configuration change, effective on the next call |
| "Prove it" | Sampling tickets and interviewing agents | Export the log |
05 · AUDIT READINESS
What an auditor or supervisor will ask for
Bring these five things to the review. IVM produces all of them.
1. The written verification policy, per user population, with the risk rationale.
2. Proof that the policy was technically enforced rather than communicated.
3. A complete record of verification events, successful and failed, for the sample period.
4. Evidence that privileged actions followed successful verification and not the reverse.
5. Evidence that the same standard applied to outsourced and after-hours support.
06 · DEPLOYMENT
Where FastPass IVM already runs
Police forces, defence ministries, the nuclear industry, healthcare, financial services and universities. The product is penetration tested by third-party firms and by security-sensitive customers, uses FIPS 140-2 compliant cryptography, and has been deployed inside a ServiceNow Government Community Cloud instance carrying FedRAMP High and DoD IL-4 authorisation without code changes.(opens in new tab)
ITSM: ServiceNow (certified)(opens in new tab), TOPdesk (certified), Zendesk(opens in new tab), Jira Service Management, ManageEngine(opens in new tab), HaloITSM, Ivanti, BMC Remedy.
Identity and MFA: Entra ID(opens in new tab), Active Directory(opens in new tab), Okta(opens in new tab), Duo, RSA, TOTP, SMS, email, smartcard.
Deployment: FastPass Cloud(opens in new tab), or fully on-premises with all data inside your own infrastructure.(opens in new tab)
07 · QUESTIONS
Questions from compliance and security teams
No product does. Compliance is an organisational obligation covering governance, risk management, continuity, reporting and supply chain, and no single tool discharges it.
What IVM does is close one specific control gap, help desk identity verification(opens in new tab), and produce the evidence that the control operated. We supply a mapping document referencing the relevant articles so your GRC team can drop it into the control framework alongside everything else.
FastPassCorp A/S · Frederiksborggade 15.3, 1360 Copenhagen · Listed on Nasdaq First North Copenhagen. This page is provided for information and is not legal advice. Regulatory obligations depend on your sector, size and national transposition.
Close the gap before your supervisor finds it
Most organisations discover this control gap in one of three ways. An auditor asks how a password reset was authorised. A penetration tester calls the service desk and gets in. Or an attacker does.