News & Insights
When Over-Privileged Access is Business as Usual
How organisations accidentally create their own insider threat through over-privileged access
Imagine discovering that everyone who has ever worked in your office over the past decade still had a key to the building. Most leadership teams would immediately recognise the risk. They’d want to know how many keys existed, who held them, and why nobody had ever asked for them back. Locks might even be changed before the day was out!
Yet, the digital equivalent is remarkably common. Across applications, platforms and business systems, people retain access inherited through previous roles, completed projects, and temporary requests. This activity rarely attracts attention because nothing appears to be wrong. After all, people are working and systems are running … but those forgotten permissions are sitting quietly in the background. Until somebody tries the door, that is.
Access is easy to give and awkward to take away
Few organisations deliberately create over-privileged access. Most excessive permissions begin as perfectly reasonable attempts to help people do their jobs. Maybe a new project needs to move quickly, or an acquisition brings different teams together. Perhaps a supplier requires temporary access, or an employee needs additional permissions to cover a colleague. Faced with a deadline, granting broader access can feel far more practical than spending time defining precisely what is required.
The trouble is that most organisations measure how quickly access is provided – very few measure how quickly it is removed once the need has passed. You see, speed is visible, because somebody is waiting to start work. When it comes to removal, well that’s usually invisible – particularly when the person still works for the organisation and the access is causing no obvious disruption.
All this creates a predictable outcome. The organisation moves on, but its permissions often stay exactly where they are. Access granted for yesterday’s projects, roles and priorities quietly survives into tomorrow, leaving systems that reflect a historical version of the business rather than its current reality.
This is known as “privilege creep”, i.e., the slow accumulation of access across accounts, systems, and applications. There may be no single reckless decision to uncover, only years of small, defensible choices that were never revisited.
Each permission makes sense when viewed in isolation, however, together, they can leave the business with very little certainty about who can access what and whether they still need to.
An insider threat does not need a “villain”
The phrase “insider threat” tends to conjure up a disgruntled employee downloading sensitive files before leaving the business. That makes for the plot of a thriller, but it can distract leaders from a far less dramatic and much more plausible problem:
People do not have to be malicious to present a risk. They only need access they should not have.
If an employee is successfully phished, their credentials are stolen, or their device is compromised, the attacker inherits the permissions attached to that identity. Those permissions may include legitimate access needed for today’s role, alongside a collection of historic privileges gathered through previous teams, systems, and projects. The employee in question may have innocently forgotten those permissions entirely – however, the attacker will be considerably more curious.
Over-privileged access therefore turns an ordinary compromised account into something far more useful to threat actors. An identity that should open one or two doors may instead provide routes into sensitive data, shared resources, and critical business systems. The initial compromise is important, yes, but the extent of the damage is shaped by what the organisation had already allowed that account to do.
Remember: attackers do not need the employee to be dishonest. They simply need the organisation to have been generous.
The security metrics that avoid the awkward question
Most organisations can report how many suspicious emails were blocked, alerts were investigated, or vulnerabilities were discovered. These metrics are useful, tangible, and relatively easy to present. Fewer could say with confidence how many people hold access they no longer require, which third parties can still enter critical systems, or how much of the organisation a compromised account could reach. That’s partly because it’s easier to measure security activity than security discipline, even though the latter can play a far bigger role in determining the impact of a breach.
This is why over-privileged access can survive alongside substantial cyber security investment. New defensive capabilities can still be added even while old permissions remain largely untouched. In this example, the front door becomes harder to breach, but once somebody crosses the threshold, they discover a ring of keys hanging conveniently on the wall.
In short, resilience depends on limiting what happens even after a compromise.
Privilege was meant to be rare.
Privileged access should be exceptional. It should have a clear purpose, a named owner and a reason to continue existing. In practice, though, we often see that privilege has a habit of spreading because removing it can feel more disruptive than leaving it alone.
Privilege rarely spreads because organisations have made poor decisions. More often, it spreads because nobody wants to become the person who slows something down. Access is granted to keep projects moving, remove friction, and avoid disruption. The original justification may disappear, but the permission remains, quietly becoming part of the environment until nobody remembers why it exists in the first place.
Eventually, elevated access starts to feel ordinary. Administrator rights become a workaround, shared accounts escape proper ownership, and long-standing permissions acquire a kind of immunity because they have “always been there” (a very dangerous way of thinking in cyber!). The organisation may still describe access as controlled, but control requires more than knowing who was originally given permission. It requires knowing whether that permission remains justified now.
Don’t just ask who needs access
Leaders should absolutely ask who needs access, but that question is naturally biased towards granting it. A more revealing question is: who still has access, and would we knowingly approve it again today?
Answering this effectively means treating access as an ongoing business discipline rather than an annual exercise performed for an audit. Access should reflect how the organisation operates today, which means reviews need to follow meaningful business changes. When somebody moves role, a supplier’s engagement ends, a project closes, or a system owner changes, inherited permissions should not simply travel onwards with them.
Organisations also need to know where privileged access exists, who owns it, and how regularly it is reviewed. Access should evolve alongside the business rather than reflecting decisions made years ago. Controls such as role-based access, time-limited permissions, and enhanced oversight can all help, but they are most effective when supported by a culture that is willing to challenge whether access is still necessary in the first place.
The aim is not to make legitimate access painfully difficult. It is to stop convenience becoming a permanent security policy. Good access management enables people to work without giving every identity the digital equivalent of an all-access pass.
Who still has the keys?
Over-privileged access is often the residue left behind by growth, restructuring, new technology, changing responsibilities, and years of reasonable business decisions. As a result, it sits at the intersection of cyber security, governance, and organisational change, requiring visibility, accountability, and ongoing scrutiny across the organisation.
Understanding that risk starts with knowing where access exists, how it has accumulated, and whether it still reflects the way the business operates today. Organisations that manage access effectively make it part of everyday governance – regularly reviewing permissions as teams, priorities, suppliers, and systems change.
Littlefish Group helps organisations gain that visibility, strengthen access controls, and reduce unnecessary risk without creating unnecessary friction for users. If you’re not sure who still has the keys to your organisation, it’s probably time to find out. Find out more about resilient operations or feel free to get in touch with our cyber team.
![]()