Old accounts are often forgotten, and forgotten accounts can become security problems.
When an employee leaves, their access should be disabled quickly. Accounts for former vendors, temporary workers, interns, and contractors should also be reviewed.
An unused account may still have access to email, shared files, VPN services, cloud applications, or administrative tools.
If an attacker discovers a forgotten account, the activity may not be noticed because no one expects that user to sign in.
Businesses should create a standard offboarding process. This should include disabling accounts, removing licenses, reviewing shared access, transferring important files, and changing passwords for shared systems when necessary.
Regular access reviews can also help find accounts that should no longer exist.
Good security includes knowing not only who has access today, but also who should no longer have access at all.
