CybersecurityIT ManagementRisk

The Account That Never Died: Two Kinds of IT Risk

An abandoned employee badge with active digital access paths into company systems

A CFO leaves the company, attends a goodbye party, and moves on. Months later, the same corporate login still reaches the company bank account.

Disabling that account would have taken minutes. The failure was not a lack of software or budget. It was a missing owner, a missing checklist, and a missing confirmation.

That story highlights two categories leaders often mix together: risks that can be fixed immediately through disciplined work, and structural problems that require investment.

The free problem leadership must own

An active former-employee account is a management failure expressed through technology. So are forgotten administrator permissions, incomplete equipment returns, and passwords that remain unchanged after a contractor leaves.

The control is straightforward: create a written offboarding checklist covering every place the person had access, then require a manager to verify completion.

A security professional deactivating a former employee across company systems
Offboarding is complete only when every access path is verified closed.

Do not stop at email and a laptop. Include banking, payroll, payment processors, customer platforms, cloud tools, state portals, shared passwords, and vendor systems.

The expensive problem needs a plan

Other risks cannot be resolved with a five-minute task. Untested backups, unsupported operating systems, aging servers, security gaps, and fragile networks need money, sequencing, and leadership decisions.

When every technology issue is treated like a ticket, major risks remain buried in a queue. When every issue is treated like a crisis, money gets wasted on symptoms. The solution is to sort findings into two lanes: fix now or plan and fund.

Executives separating immediate IT controls from planned infrastructure investments
Separate quick control failures from projects that require investment.

Seven questions to ask this week

Create a safe conversation with the person responsible for technology, then ask:

  1. When did we last complete a full test restore of our backups?
  2. If our systems were encrypted tonight, when would we operate again?
  3. Which systems are unsupported or approaching end of life?
  4. How many company devices exist, and how many are protected?
  5. What is our oldest missing security patch?
  6. What exactly happens when an employee or contractor leaves?
  7. What technology recommendation did leadership previously decline?

Answers should include evidence, dates, ownership, and a business impact. A green icon is not proof that recovery works.

If these questions expose uncertainty, start with an AITS risk and readiness assessment. The goal is not to create fear. It is to distinguish a free fix from a funded project before a preventable incident makes that decision for you.

Adapted from The Digital Dilemma newsletter.

Frequently asked questions

What is an orphaned user account?

An orphaned account belongs to a former employee or contractor but remains active after that person leaves. It can preserve access to email, files, banking, payroll, and other critical systems.

What should an employee offboarding checklist include?

It should cover company devices, email, identity systems, banking, payroll, payment processors, cloud services, vendor portals, licensing systems, and any shared credentials, with a manager confirming completion.

How can a CEO get an honest view of IT risk?

Make it safe for the technology team to report problems, then separate immediate process fixes from infrastructure risks that require budget and planning.

Free AI Risk Scan
FREE · 90 SECONDS · NO SIGNUP

Most clients like to start here to learn their current AI readiness posture — and how a free 30-minute call, backed by a lot more data, helps you make faster decisions.

Run my free AI Risk Scan →