A client walked us through their security stack a while ago. It was genuinely impressive. Detection and response, a threat intelligence feed, a platform for correlating alerts, all of it recent and all of it costing real money.

Then we asked how many administrative accounts they had. Nobody knew.

That gap shows up constantly. Organizations invest in tooling that assumes the fundamentals are handled, and often they are not. Which is a problem, because most incidents we see did not require sophistication. They required an account that should have been closed, or a credential with no second factor on it.

Here are the five we find missing most often.

1. Multifactor authentication on everything, not just email

Almost every organization has multifactor on email now. Far fewer have it everywhere else

The gaps are predictable. Remote access. The finance system. Legacy applications that do not support modern authentication and got an exception years ago that nobody revisited. Administrative interfaces on network equipment. Vendor portals.

Attackers do not go where the controls are. They look for the account that still works with a password alone, and in most environments that account exists.

The fix is a list. Every system that accepts a login, and whether it requires a second factor. That exercise usually takes a day and it usually surprises people.

2. Knowing what you actually have

You cannot protect an asset you do not know about, and most organizations have more than their inventory shows.

We routinely find servers still running after the project that needed them ended. Test environments holding copies of production data. A subdomain pointing at a platform nobody in the current team set up. Cloud resources spun up by a department outside of IT.

None of those are monitored, because nothing monitors what it does not know exists. They also tend to be unpatched, since patching follows the inventory too.

An accurate asset inventory is unglamorous work that makes every other control more effective. It is also the control most often assumed to be someone else’s job.

3. Administrative accounts

Back to the question the client could not answer.

Administrative access accumulates. Someone needs elevated rights for a project and keeps them afterward. A vendor gets an account during an implementation and it is never closed. A service account is created with broad permissions because narrowing them would have taken longer, and it is still running with a password nobody has changed in years.

Each of those is a path into the environment with the ability to do serious damage, and none of them will look unusual to monitoring, because administrative activity is normal.

Start by counting. Then ask, for each one, whether the person or service still needs it and whether anyone would notice if it were used at three in the morning.

4. Backups you have actually restored from

Backups run. That is different from backups working.

We have seen backup jobs reporting success for months while silently skipping a critical database. We have seen backups stored in the same environment as the systems they protect, which means one bad day takes both. We have seen restore procedures that had never been performed, so nobody knew a full restore would take four days rather than the four hours everyone assumed.

The test is simple and almost nobody runs it. Pick a system. Restore it somewhere isolated. Time it. Confirm the data is complete and usable.

Ransomware turns this from an operational question into an existential one, because a tested backup is the difference between a difficult week and a decision about whether to pay.

5. Removing access when people leave

Offboarding is usually handled well for the obvious things. Email is disabled, the laptop comes back, the badge is deactivated.

What lingers is everything else. Accounts in systems procured by individual departments. Shared credentials the person knew. Access to a vendor portal. Membership in a group that grants permissions indirectly. Personal devices still holding a valid token.

The reliable version of this is a documented offboarding checklist built from the asset inventory, reviewed periodically against actual departures rather than assumed to be working.

Why this is worth saying out loud

None of these five are interesting. That is precisely why they get skipped. Advanced tooling is easier to fund, easier to present to a board, and easier to feel good about than an access review.

But tooling is built on the assumption that the basics hold. When they do not, the tools generate alerts about a compromise that a closed account would have prevented.

If you have recently invested in security technology, the highest return next step is usually not another product. It is confirming that the ground it stands on is solid.

If you are not sure where you stand on these five, that is worth finding out before someone else does. We run this review for clients regularly and it does not take long. Reach out and we will tell you what it involves.
https://systemcustom.com/