The Account That Never Died: Two Kinds of IT Risk
A CFO leaves the company, attends a goodbye party, and moves on. Months later, the same corporate login still reaches the company bank account.
Disabling that account would have taken minutes. The failure was not a lack of software or budget. It was a missing owner, a missing checklist, and a missing confirmation.
That story highlights two categories leaders often mix together: risks that can be fixed immediately through disciplined work, and structural problems that require investment.
The free problem leadership must own
An active former-employee account is a management failure expressed through technology. So are forgotten administrator permissions, incomplete equipment returns, and passwords that remain unchanged after a contractor leaves.
The control is straightforward: create a written offboarding checklist covering every place the person had access, then require a manager to verify completion.
Do not stop at email and a laptop. Include banking, payroll, payment processors, customer platforms, cloud tools, state portals, shared passwords, and vendor systems.
The expensive problem needs a plan
Other risks cannot be resolved with a five-minute task. Untested backups, unsupported operating systems, aging servers, security gaps, and fragile networks need money, sequencing, and leadership decisions.
When every technology issue is treated like a ticket, major risks remain buried in a queue. When every issue is treated like a crisis, money gets wasted on symptoms. The solution is to sort findings into two lanes: fix now or plan and fund.
Seven questions to ask this week
Create a safe conversation with the person responsible for technology, then ask:
- When did we last complete a full test restore of our backups?
- If our systems were encrypted tonight, when would we operate again?
- Which systems are unsupported or approaching end of life?
- How many company devices exist, and how many are protected?
- What is our oldest missing security patch?
- What exactly happens when an employee or contractor leaves?
- What technology recommendation did leadership previously decline?
Answers should include evidence, dates, ownership, and a business impact. A green icon is not proof that recovery works.
If these questions expose uncertainty, start with an AITS risk and readiness assessment. The goal is not to create fear. It is to distinguish a free fix from a funded project before a preventable incident makes that decision for you.
Adapted from The Digital Dilemma newsletter.
Frequently asked questions
What is an orphaned user account?
An orphaned account belongs to a former employee or contractor but remains active after that person leaves. It can preserve access to email, files, banking, payroll, and other critical systems.
What should an employee offboarding checklist include?
It should cover company devices, email, identity systems, banking, payroll, payment processors, cloud services, vendor portals, licensing systems, and any shared credentials, with a manager confirming completion.
How can a CEO get an honest view of IT risk?
Make it safe for the technology team to report problems, then separate immediate process fixes from infrastructure risks that require budget and planning.
Never miss an episode
Subscribe to The Digital Dilemma
Straight talk on AI, cybersecurity, and business technology — no hype, no vendor propaganda. Follow on whatever platform you already use: