By Stan Kreydin, Managing Director of Cyber Risk and Technology Advisory
Reviewing user and administrative access during IT due diligence can reveal key-person dependencies, excessive privileges, former employee access, weak segregation of duties, and single points of failure that may not appear on an organizational chart. Organization charts tell you who holds the title. Access lists show who holds the keys.
In a recent risk screener engagement, one engineer held sole administrative access to all customer service and back-office systems. No runbooks documented how the environment worked, and no backup designee had equivalent access or institutional knowledge. This type of dependency is not uncommon in the lower and middle markets.
Companies grow. New applications are added. Systems are configured quickly. The employee who originally set something up retains administrative access because formally transferring that knowledge or privilege is never an immediate priority. Over time, that employee can become a single point of failure for the technology the business cannot operate without.
How Can User Access Create Operational Risk?
The operational risk is straightforward. If the only person with administrative access leaves, becomes unavailable, or departs after a transaction is announced, the organization may lose the ability to administer systems that are critical to daily operations.
That dependency can influence several parts of a transaction, including:
- Employee retention planning
- Transition agreements
- Day 1 readiness
- Knowledge transfer
- Integration sequencing
The issue is not simply whether the employee is important. It is whether the business can operate without that person’s access and knowledge.
How Can Privileged Access Create Cybersecurity Risks?
The same concentration of access also creates cybersecurity exposure. One account with administrative privileges across numerous systems gives a threat actor a much larger blast radius if that account is compromised. In some environments, an attacker would ordinarily need to move laterally from one system to another and escalate privileges along the way. When one credential already has broad administrative access, much of that work has effectively been done for them.
What Should Acquirers Review Before Day 1?
Access reviews should identify:
- Who holds administrative privileges
- Which systems each administrator can access
- Whether shared administrator accounts exist
- Whether former employees retain access
- Whether backup administrators are designated
- Whether critical procedures are documented
- Whether privileged accounts use appropriate security controls
- Whether administrative access can be transferred before close
For an acquirer, these issues are often easier to address before Day 1 than during integration after a key employee has already departed. Key-person risk is not always visible on the org chart. Sometimes it is sitting in the access list.
Related Questions
- What is privileged access? Privileged access allows a user to perform administrative or high-level actions within a system, such as changing configurations, managing users, or accessing sensitive data.
- What is key-person technology risk? Key-person technology risk arises when critical knowledge, credentials, system access, or operational responsibility is concentrated in a single individual.
- Why review former employee accounts during diligence? Inactive or former employee accounts can create unnecessary cybersecurity exposure, especially when they retain access to sensitive or administrative systems.
- Should access be reviewed before closing? Yes. Identifying access dependencies before closing can inform retention planning, security remediation, and day 1 integration priorities.
For any questions regarding cyber risk and technology advisory services, contact Stan Kreydin at [email protected].