09/01/2026
Quick question: if someone left your company three months ago, could they still log into anything today?
We ask this in almost every security review and the answer is usually "probably." Not because anyone is careless, it's just that access cleanup falls to the bottom of the list. Someone changes roles and keeps their old permissions. A contractor wraps up a project and their login never gets pulled. A shared password from an old vendor relationship is still floating around.
None of this shows up until an audit, or worse, until it's the reason something goes wrong. The NIS2 compliance push happening right now is a good reminder that regulators are starting to expect proof of clean access, not just a promise of it.
Here's a simple self-check you can run this week:
Pull a list of everyone with access to your core systems, email, file storage, accounting software, admin panels. For each name, ask two questions: does this person still work here, and does their current role actually need this level of access. Anything that gets a "no" or a "not sure" goes on a cleanup list.
Takes maybe 20 minutes. Usually finds more than people expect.
If you want a second set of eyes on it, that's what we're here for. We can run a full access inventory and tell you exactly where the gaps are.