Created with AI.
A semiannual access review takes a few hours and eliminates most of the accumulated risk.
Who has which role. Start with the system administrators—the list is usually longer than expected.
No login activity in the past ninety days. These are usually former employees or people who have changed roles.
They are systematically forgotten because no manager owns them. Find out what each one is used for and who owns it.
Ask them to confirm or decline. Set a deadline. Without a deadline, the responses will never come.
The standard should be that access which no one confirms is removed. The opposite rule results in a review with no effect.
If the same problem keeps recurring—for example, if a change of role never triggers a clean-up—it is the role-change procedure that needs to be fixed, not the review.
Ask a question or share what helped you.

Published 3/28/2025
We work continuously to improve information security (ISO 27001), quality (ISO 9001), and environmental management (ISO 14001), and are therefore proud to have successfully completed a new audit of our certifications in these areas.
Read morePublished 8/30/2024
Over the past few years, hybrid workplaces have become the norm for many. Along with this shift, both IT functionality and security needs have changed. Here are some useful tips from our Head of IT and Security on how organizations should approach securing their IT in a hybrid world.
Read moreDo you have a question or experience to share?
Be the first to contribute.