During a routine audit we found something mundane and dangerous: the account of an employee who had left six months earlier was still active — email, VPN, access to company files. Nobody had disabled it, because nobody was explicitly responsible for it.
This is not about malice, but about a missing offboarding procedure. Every active account that nobody needs anymore is a door left unlocked: it can be used by the former employee, but also by an attacker who compromises a password they reused elsewhere.
Account hygiene — who has access, to what, and immediate deactivation on departure — is one of the cheapest security measures and one of the most often ignored. We check it for every client; an initial audit shows you exactly which doors are still unlocked.
This article was generated with AI assistance.