Bring access and permissions in order — before someone else does

"IT@company123" — one password, for years, for everyone. What began as a pragmatic solution eventually becomes the company's biggest open door.

Permissions grow historically: whoever once got access keeps it. Whoever leaves often stays registered. Whoever covers for a colleague quickly gets admin rights. And nobody can say who is actually allowed to do what.

The topic feels uncomfortably big — but with clear priorities it is very manageable: first an overview, then the critical accounts, then a process that keeps things in order.

When access becomes a risk

Typical signs that permissions are getting out of hand:

  • Shared accounts and shared passwords are everyday practice
  • Former employees or externals still have active access
  • Nobody can list who can access which systems and data
  • Admin rights are handed out generously — "to keep things moving"
  • Passwords live in Excel lists, notes or emails
  • In case of an incident, it would be impossible to trace who did what and when

Each of these points is uncomfortable on its own. Together they are exactly what attackers look for — and auditors find.

Typical access shadow processes

Shared accounts

One login for the whole team — nobody knows who did what, and the password is also known to whoever left last year.

Rights accumulation

With every role change, permissions are added — rarely is anything revoked.

Admin for everyone

Full rights out of convenience: every mistake and every hijacked account has maximum impact.

Externals with permanent access

Service provider accounts that simply keep running after the project ends.

No traceability

Without personal accounts and logs, every incident remains a mystery.

Why access chaos persists so long

It rarely comes from carelessness — but because:

  • It works in everyday business, at first
  • Revoking rights is more inconvenient than granting them
  • Nobody is explicitly responsible for permissions
  • On- and offboarding run without fixed checklists
  • The topic feels like a "big IT project" and therefore stays untouched

The right time to act is much earlier than most think — at the latest when customers, insurers or NIS2 ask for evidence.

Signs that it is time to act

It is worth taking a closer look when several of these points apply:

  • There are shared accounts for business-critical systems
  • Offboarding does not reliably remove access
  • Externals have permanent access to internal systems
  • More people have admin rights than there are admins
  • Passwords are stored unencrypted or shared
  • A cyber insurer or a customer asks about your permission concept
  • NIS2 or other requirements are approaching
  • An incident or near-incident has raised questions

What makes a good solution

Cleaning up permissions does not mean touching everything at once. What matters first:

  1. 1 Which systems and data are truly critical?
  2. 2 Who needs which access for their daily work?
  3. 3 Where is read access enough, where are write or admin rights needed?
  4. 4 How does access get in — and how reliably does it get out again?
  5. 5 What needs to be traceable if something happens?

Sensible building blocks include:

  • Personal accounts instead of shared logins
  • Role-based permissions: rights follow the task, not the history
  • A team password manager instead of Excel lists
  • Multi-factor authentication for critical access
  • Fixed on- and offboarding processes with checklists
  • Regular permission reviews — short but consistent

Modern systems support this well — from central login (SSO) and OAuth2 to policy-based authorization. The order matters: critical accounts first, refinements later.

How I approach cleaning up access

01

Create an overview

We map systems, access and accounts — including the forgotten ones: legacy accounts, externals, shared logins.

02

Assess criticality

Not everything is equally important. We prioritise by the damage a misused account could cause.

03

Implement quick wins

Close orphaned accounts, change critical passwords, enable MFA — the fast, big levers first.

04

Build structure

Role model, password manager, on-/offboarding process — so order is maintained without a permanent project.

05

Keep it up

A light rhythm of permission reviews ensures the chaos does not accumulate again.

Typical results from such projects

  • Clarity about who can access what
  • A significantly smaller attack surface
  • Traceability when it matters
  • Solid answers for insurers, customers and audits
  • On- and offboarding without loose ends
  • Less risk from legacy access and former employees

Practical context: typical starting points

In practice this is rarely a technology problem: the systems could usually do more than is being used. What is missing is the overview — and a process that keeps order when people join, leave and change roles.

That is why the work does not start with a new tool, but with an honest inventory. The technology — from password manager to policy-based authorization — follows after.

Which support can make sense

Access and permissions touch several areas — from security analysis to technical structure:

Häufige Fragen

Do we need an identity management system?
For most mid-sized companies, not right away. Personal accounts, MFA, a password manager and fixed processes solve most of the problem — an IAM system can follow later.
How does this work without blocking daily business?
Step by step: critical systems first, clear transition periods, and rights granted along actual tasks. Done well, everyday work barely notices.
What does this have to do with NIS2?
Access control and traceability are among the core requirements. Whoever has order here has already completed a large part of the mandatory programme.
Is a password manager not enough?
It is an important building block, but it does not replace a role model or an offboarding process. Only the combination keeps things in order permanently.
Do you also handle the technical implementation?
Yes — from structure to implementation with your IT team or service provider, including modern approaches like SSO, OAuth2 or policy-based authorization (e.g. OPA).

Do you know who can currently access your systems?

A compact assessment creates clarity — and shows the measures with the biggest leverage.

Let's talk about it