Access governance · Confidential service
Access review and key-person risk
When the systems, databases, projects or processes of a company, or of its subsidiary in Spain or elsewhere in the EU, depend on one administrator or one managed service provider, management loses the ability to decide. We map who controls what and deliver a 90-day plan to redistribute privileges without disrupting operations.
- Scope
- Systems, data and processes
- Outcome
- 90-day de-escalation plan
- Reporting
- In English, to management
Your information stays inside our own certified management system. Hard2bit is certified to Spain's ENS at the HIGH category and to five ISO standards.
What is an access review, and when does a company need one?
An access review establishes who can access, change or lock the systems, data, applications and processes of a company, and how much of that control depends on a single person or provider. Companies commission one when management cannot answer that question with confidence, or when a departure, an acquisition or an audit requires the answer to be documented.
It is also known as a privileged access review or an access governance review. It is not tied to one tool: it covers any system or process whose failure, or loss of control, would affect the business.
Four situations behind most reviews
-
A subsidiary run by one local administrator
Headquarters sets the policies, but the servers, databases and accounts of the Spanish or European entity are run by one person. Nobody at group level can say who has access to what.
-
A managed service provider holding the keys
The provider has run the environment for years and holds the admin credentials, the domain and the backups, and the contract says nothing about handing them over.
-
The engineer who built everything is leaving
Integrations, scripts, deployments and the month-end close depend on someone whose knowledge was never written down.
-
An acquisition or investment
Buyers and investors ask who controls the systems and the digital assets, and due diligence needs a documented answer.
Self-check
Does your company, or its subsidiary, depend on one person?
Tick what applies today. None of these is anyone's plan: they build up over years because one person kept things running.
Result
0 / 8
Scope
What one person may control, and why it matters
Key-person risk goes well beyond Microsoft 365. It appears wherever one account, one password or one person's memory keeps the business running.
| Area | What we check | Why it matters |
|---|---|---|
| Identity and email | Microsoft 365, Google Workspace, Active Directory and Entra ID: admin roles, MFA, forwarding rules, consented apps | A global administrator can lock everyone else out. |
| Databases | SQL Server and other engines: permissions per database, service accounts, exports, BI tools | Data can be read, changed or deleted without anyone noticing. |
| Business applications | ERP, CRM, payroll, invoicing, in-house and SaaS apps: who administers each one | One person can create users and grant access to themselves. |
| Projects and code | Repositories, environments, deployment pipelines, integrations, scripts | Releases stop, or secrets stored in code outlive the person who wrote them. |
| Infrastructure | Servers, virtualisation, VPN and remote access, firewall, cloud, backups | A backup that only one person can restore is a single point of failure. |
| Digital assets | Domain, DNS and registrar, certificates, social accounts, cloud billing accounts | Assets registered to a person are not formally owned by the company. |
| Payments and signatures | Online banking, payment gateways, digital representative certificates | One set of credentials may be enough to move money or act for the company. |
| Processes and knowledge | Critical routines only one person can run, missing documentation, no deputy | Operations continue only while that person is available. |
When a managed service provider holds the keys, the review maps what the provider controls and what the contract says about handover. Afterwards, third-party risk management keeps that control in place.
Method
How the access review runs
- 01
Confidential scoping with management
An NDA is signed before any detail is shared. We agree objectives, scope and how the work is presented internally, usually as an organisation-wide security review.
- 02
Read-only access and log retention
Management creates a temporary account that we use only to read. The first task is to preserve activity logs: Microsoft 365 standard audit logs are kept for 180 days.
- 03
Access inventory
For every system, database, application, project, digital asset and provider: who has access, at what level, since when and through which route, including service accounts and stored secrets.
- 04
Concentration analysis
Exclusive control, risky combinations of rights, access outside a person's role, actions that leave no trace, and knowledge held by one person only.
- 05
Findings for management
A role-based report, with named detail delivered to management only, and the de-escalation plan.
De-escalation plan
A 90-day privilege de-escalation plan
Removing privileges overnight from the person who runs the systems can stop operations. The plan therefore moves in phases: first it makes sure the company cannot be locked out, then it separates and shares control, and finally it leaves procedures to maintain it.
- 1
Days 0-7
Secure
- Break-glass accounts held by management
- Domain, DNS and cloud accounts in the company's name
- Critical credentials under corporate custody
- Activity logs preserved
- 2
Day 30
Separate
- Admin accounts separate from day-to-day accounts
- MFA on company-owned devices
- Standing privileges removed where not needed
- Service accounts and stored secrets reviewed
- 3
Day 60
Share
- Segregation of duties across systems, data and payments
- Dual approval for critical changes
- Corporate password vault with role-based access
- Critical routines documented, with a deputy
- 4
Day 90
Maintain
- Periodic access reviews
- Alerts on changes to privileged roles
- Joiner, mover and leaver procedure
- Custody and handover clauses with providers
Confidentiality
Discretion throughout the engagement
Only management knows why the review is taking place. The engagement is organised so that it stays that way, from the first call to the final report.
Legal basis
For staff based in Spain, the review is carried out on company systems within the GDPR, Article 87 of Spain's data protection act (LOPDGDD) and Article 20.3 of the Workers' Statute. For other EU countries, local employment rules should be confirmed with your legal counsel.
An access review is not a forensic investigation. If a specific incident has already occurred, the right service is digital forensics with chain of custody.
- NDA signed before any detail is shared.
- One point of contact on the management side, or whoever management appoints.
- A small team with need-to-know access.
- The work can be presented internally as a general security review.
- We review access, permissions and configuration, never the content of communications.
- Role-based report; named detail goes to management only.
- Information held under our certified management system and returned or destroyed at closure.
- Employment decisions remain exclusively with the company.
Team and assurance
Who does the work, and what backs it
Each engagement combines technical analysis, which finds access that no inventory shows, with governance work, which turns the findings into clear ownership.
-
Service ownership
Thilina Manana, Director of Operations and Security and ISO 27001:2022 Lead Auditor (CQI IRCA), is accountable for scope, confidentiality and quality.
-
Technical security team
Specialists in systems, Microsoft 365, Active Directory, databases, cloud, offensive security and digital forensics. They find access that no inventory shows.
-
Compliance and GRC team
ISO 27001, ENS and NIS2 consultants and auditors. They turn findings into segregation of duties, policies and clear ownership.
Hard2bit is certified to Spain's ENS at the HIGH category (certificate ENS_2.026.061) and to ISO 27001, 22301, 20000-1, 9001 and 14001. The review supports the segregation-of-duties and privileged-access requirements of ISO 27001 (controls 5.3, 5.18, 6.5 and 8.2), NIS2 (Article 21(2)(i)) and Spain's ENS, and feeds business continuity planning. For ongoing leadership, a virtual CISO can own access governance afterwards.
Duration
How the review is scoped
There is no fixed package: the review is scoped in working days according to what needs to be examined. A typical scope takes two to five weeks. After the confidential scoping call we send a proposal with scope, days and timeline.
Arrange a confidential callWhat drives the number of days
- Systems, databases, applications and projects in scope
- Privileged and service accounts
- Sites, subsidiaries and providers with access
- Depth of technical analysis and number of interviews
- Optional support during de-escalation
FAQ
Common questions about access reviews
Our IT administrator is the only person with the admin passwords. Where do we start?
Our managed service provider will not hand over the admin credentials. What can we do?
Can you review a Spanish subsidiary while management sits at headquarters abroad?
Will the person concerned find out about the review?
Is it lawful to review an employee's access rights in Spain?
Is the review limited to Microsoft 365?
What does privilege de-escalation mean in practice?
How long does an access review take and how is it scoped?
Is an access review a forensic investigation?
Related terms
Concepts from our cybersecurity glossary that connect directly with this service.
Regain control of who can access your systems
A first call with management only, under NDA, to understand the situation and propose a scope.
Reviewed by Thilina Manana and Hard2bit's technical and Compliance and GRC teams. Last reviewed: .

