The departed employee's account, active for 6 months: account hygiene

During a routine audit we found something mundane and dangerous: the account of an employee who had left six months earlier was still active — email, VPN, access to company files. Nobody had disabled it, because nobody was explicitly responsible for it.

This is not about malice, but about a missing offboarding procedure. Every active account that nobody needs anymore is a door left unlocked: it can be used by the former employee, but also by an attacker who compromises a password they reused elsewhere.

Account hygiene — who has access, to what, and immediate deactivation on departure — is one of the cheapest security measures and one of the most often ignored. We check it for every client; an initial audit shows you exactly which doors are still unlocked.

Sources

This article was generated with AI assistance.

I want an access audit Cybersecurity

← All news