CPS-127 · Impact

The Pain of Not Knowing Who Still Has Access to Your Business Systems — and the Financial Risk of Uncontrolled Access

Access accumulates quietly. Employees change roles, contractors finish projects, old accounts remain, and permissions that once made sense continue long after the business need has disappeared.

Mellorca Impact·Cybersecurity, Passwords & Access Control·2 September 2026

The tolerated pain is access nobody can confidently explain

A growing business can add accounts faster than it removes them. A new employee gets access to several systems. Six months later the person changes role but keeps the old permissions. A contractor receives temporary access that never expires. A shared mailbox or administrator account survives because nobody wants to risk breaking something.

Individually, these decisions look harmless. Together they create a basic control problem: the business cannot answer, with evidence, who can reach which systems and why.

Why uncontrolled access survives

Access is usually granted at moments of urgency and reviewed at moments of inconvenience. Managers focus on getting people productive. IT teams avoid removing permissions unless ownership is clear. Smaller organisations may have no central identity-governance process at all, so each application develops its own history of users, roles and exceptions.

CISA's identity and access management guidance recommends maintaining an access inventory and periodically reviewing and reconciling accounts and privileges. The same guidance connects these practices to least privilege: users should retain only the access required for their job functions. NIST SP 800-53 similarly treats account management and least privilege as core controls.

How the pain becomes money

  • Incident exposure: an unnecessary account or permission can widen what a compromised credential can reach.
  • Administrative rework: staff spend time reconstructing who should have access when audits, incidents or role changes force the question.
  • Operational delay: urgent access removals become slower when ownership and dependencies are unclear.
  • Audit and compliance effort: proving appropriate access becomes labour-intensive when evidence is scattered across applications.
  • Licence waste: accounts that should have been removed can continue consuming paid seats or privileged features.
The commercial signalIf the business cannot produce a current list of active users, privileged accounts, owners and business justification for important systems, it is managing access by memory rather than control.

Quantify the operating cost before trying to price the risk

Do not invent a generic breach number. Start with what can be measured directly.

Annual access-administration cost
access requests, reviews and corrections per month × average handling time × loaded labour cost × 12
Licence leakage
inactive or unnecessary paid accounts × monthly licence cost × 12

For risk exposure, model scenarios separately. Ask which systems an unnecessary account could reach, what transaction authority it carries, what data it exposes, and how much paid response time would be required if that access were abused or compromised.

Role changes are where access debt accumulates

Joiners and leavers receive attention because they are visible events. Internal moves are easier to miss. A promotion, transfer or project change can add permissions without removing the old ones. Over time, access expands while accountability weakens.

This is why access reviews should not be treated only as an annual compliance exercise. The most useful control is a repeatable lifecycle: grant, change, review and remove.

When this becomes commercially urgent

Priority is high when former employees still appear in systems, contractors have open-ended access, privileged accounts are shared, managers cannot explain why users hold certain roles, sensitive files are broadly accessible, or a merger or restructuring has created overlapping identity systems. Another trigger is a licensing review: access and subscription waste often expose the same weak offboarding process.

What good looks like

A controlled environment has named system owners, a reliable identity source, documented access roles, time-bound exceptions, prompt deprovisioning and periodic reviews that produce evidence. Privileged access is smaller, more visible and more deliberately managed than ordinary access.

The goal is not to make every permission request bureaucratic. It is to make access intentional and reversible.

Practical next actions

  1. Inventory important business applications and identify an accountable owner for each.
  2. Export active users and privileged roles from those systems.
  3. Compare the list with current employees, contractors and role assignments.
  4. Remove dormant accounts and unnecessary permissions through a controlled change process.
  5. Set expiry dates for temporary and supplier access where supported.
  6. Create a recurring review for high-risk systems and privileged roles.
  7. Link access removal to the employee and contractor offboarding process.

Bottom line

The financial risk is not created by access itself. It is created when access outlives the business reason for granting it and nobody can prove otherwise. A current access inventory and disciplined lifecycle reduce security exposure, licence waste and the labour required to reconstruct permissions under pressure.

Sources and further reading

Method noteThis article does not use a generic breach-cost benchmark. Quantify direct access-administration and licence costs from your own records, then model security scenarios separately.