A client called us in a mild panic last spring. A contractor they'd let go eight months earlier had, out of curiosity more than malice, logged into the company's old analytics dashboard just to see if he still could. He could. Nobody had ever removed him.
That's not a hacking story. That's a filing story. And it's more common than almost any owner wants to believe.
The exit interview covers the wrong things
When someone leaves a company, the checklist is usually about hardware and HR: laptop back, final paycheck, sign the NDA. What rarely makes the list is the twenty-plus places that person had a login — the CRM, the shared Google Drive, the payment processor, the AWS console, the social media scheduler, the domain registrar. Most of those accounts were set up one at a time, over years, by whoever needed access at the moment, and nobody kept a master list.
So when the person leaves, IT (if there is an IT) revokes email and maybe Slack. Everything else just... stays. Not because anyone decided it should. Because nobody was assigned to decide.
Where the access actually lives
We did an audit for a fifteen-person e-commerce company last year and found forty-one active third-party logins tied to former employees, two of them former employees from over three years back. One had standing access to the Stripe dashboard. Another still had edit rights on the DNS records for the company's primary domain — the single setting that, misused, can take a business offline or redirect its traffic entirely.
None of this was a security breach waiting to happen in the dramatic sense. Most former employees never think about it again. But "probably fine" isn't a control, and the one time it isn't fine, it's expensive — in the time it takes to prove what happened, in the trust it costs with a payment processor or a customer, in the hours spent resetting credentials across a dozen tools nobody remembers is connected to what.
Nobody owns the list
The pattern we see across almost every SME is the same: access accumulates faster than anyone tracks it, because granting access is somebody's urgent task and revoking it is nobody's job at all. There's no single owner, because the access itself is scattered across a dozen vendors with a dozen different admin panels, none of which talk to each other.
This is, structurally, the same problem as technical debt — small decisions made under time pressure, with no one responsible for cleanup, compounding quietly until the bill comes due. It just shows up as a security line item instead of a refactor.
The fix isn't more security software
You don't need a fancier tool. You need one document — a real, maintained list of every system the business uses and who has access to it — and one person whose job includes checking it every time someone leaves. That's it. It's boring, it takes an afternoon to build and twenty minutes a quarter to maintain, and almost nobody does it until something forces the question.
Part of what we do in our managed IT engagements is exactly this kind of housekeeping — not because it's glamorous, but because the companies that skip it are the ones calling us in a panic eight months after the fact.
If you can't name, right now, everyone who still has access to your company's most important systems, that's worth an afternoon before it's worth an incident.