AI-generated image

Access governance · Confidential service

Access review and key-person risk

When the systems, databases, projects or processes of a company, or of its subsidiary in Spain or elsewhere in the EU, depend on one administrator or one managed service provider, management loses the ability to decide. We map who controls what and deliver a 90-day plan to redistribute privileges without disrupting operations.

Scope
Systems, data and processes
Outcome
90-day de-escalation plan
Reporting
In English, to management

Your information stays inside our own certified management system. Hard2bit is certified to Spain's ENS at the HIGH category and to five ISO standards.

What is an access review, and when does a company need one?

An access review establishes who can access, change or lock the systems, data, applications and processes of a company, and how much of that control depends on a single person or provider. Companies commission one when management cannot answer that question with confidence, or when a departure, an acquisition or an audit requires the answer to be documented.

It is also known as a privileged access review or an access governance review. It is not tied to one tool: it covers any system or process whose failure, or loss of control, would affect the business.

Four situations behind most reviews

  • A subsidiary run by one local administrator

    Headquarters sets the policies, but the servers, databases and accounts of the Spanish or European entity are run by one person. Nobody at group level can say who has access to what.

  • A managed service provider holding the keys

    The provider has run the environment for years and holds the admin credentials, the domain and the backups, and the contract says nothing about handing them over.

  • The engineer who built everything is leaving

    Integrations, scripts, deployments and the month-end close depend on someone whose knowledge was never written down.

  • An acquisition or investment

    Buyers and investors ask who controls the systems and the digital assets, and due diligence needs a documented answer.

Self-check

Does your company, or its subsidiary, depend on one person?

Tick what applies today. None of these is anyone's plan: they build up over years because one person kept things running.

Signs of dependency on one person or provider

Scope

What one person may control, and why it matters

Key-person risk goes well beyond Microsoft 365. It appears wherever one account, one password or one person's memory keeps the business running.

Area What we check Why it matters
Identity and email Microsoft 365, Google Workspace, Active Directory and Entra ID: admin roles, MFA, forwarding rules, consented apps A global administrator can lock everyone else out.
Databases SQL Server and other engines: permissions per database, service accounts, exports, BI tools Data can be read, changed or deleted without anyone noticing.
Business applications ERP, CRM, payroll, invoicing, in-house and SaaS apps: who administers each one One person can create users and grant access to themselves.
Projects and code Repositories, environments, deployment pipelines, integrations, scripts Releases stop, or secrets stored in code outlive the person who wrote them.
Infrastructure Servers, virtualisation, VPN and remote access, firewall, cloud, backups A backup that only one person can restore is a single point of failure.
Digital assets Domain, DNS and registrar, certificates, social accounts, cloud billing accounts Assets registered to a person are not formally owned by the company.
Payments and signatures Online banking, payment gateways, digital representative certificates One set of credentials may be enough to move money or act for the company.
Processes and knowledge Critical routines only one person can run, missing documentation, no deputy Operations continue only while that person is available.

When a managed service provider holds the keys, the review maps what the provider controls and what the contract says about handover. Afterwards, third-party risk management keeps that control in place.

Method

How the access review runs

  1. 01

    Confidential scoping with management

    An NDA is signed before any detail is shared. We agree objectives, scope and how the work is presented internally, usually as an organisation-wide security review.

  2. 02

    Read-only access and log retention

    Management creates a temporary account that we use only to read. The first task is to preserve activity logs: Microsoft 365 standard audit logs are kept for 180 days.

  3. 03

    Access inventory

    For every system, database, application, project, digital asset and provider: who has access, at what level, since when and through which route, including service accounts and stored secrets.

  4. 04

    Concentration analysis

    Exclusive control, risky combinations of rights, access outside a person's role, actions that leave no trace, and knowledge held by one person only.

  5. 05

    Findings for management

    A role-based report, with named detail delivered to management only, and the de-escalation plan.

De-escalation plan

A 90-day privilege de-escalation plan

Removing privileges overnight from the person who runs the systems can stop operations. The plan therefore moves in phases: first it makes sure the company cannot be locked out, then it separates and shares control, and finally it leaves procedures to maintain it.

  1. 1

    Days 0-7

    Secure

    • Break-glass accounts held by management
    • Domain, DNS and cloud accounts in the company's name
    • Critical credentials under corporate custody
    • Activity logs preserved
  2. 2

    Day 30

    Separate

    • Admin accounts separate from day-to-day accounts
    • MFA on company-owned devices
    • Standing privileges removed where not needed
    • Service accounts and stored secrets reviewed
  3. 3

    Day 60

    Share

    • Segregation of duties across systems, data and payments
    • Dual approval for critical changes
    • Corporate password vault with role-based access
    • Critical routines documented, with a deputy
  4. 4

    Day 90

    Maintain

    • Periodic access reviews
    • Alerts on changes to privileged roles
    • Joiner, mover and leaver procedure
    • Custody and handover clauses with providers

Confidentiality

Discretion throughout the engagement

Only management knows why the review is taking place. The engagement is organised so that it stays that way, from the first call to the final report.

Legal basis

For staff based in Spain, the review is carried out on company systems within the GDPR, Article 87 of Spain's data protection act (LOPDGDD) and Article 20.3 of the Workers' Statute. For other EU countries, local employment rules should be confirmed with your legal counsel.

An access review is not a forensic investigation. If a specific incident has already occurred, the right service is digital forensics with chain of custody.

  • NDA signed before any detail is shared.
  • One point of contact on the management side, or whoever management appoints.
  • A small team with need-to-know access.
  • The work can be presented internally as a general security review.
  • We review access, permissions and configuration, never the content of communications.
  • Role-based report; named detail goes to management only.
  • Information held under our certified management system and returned or destroyed at closure.
  • Employment decisions remain exclusively with the company.

Team and assurance

Who does the work, and what backs it

Each engagement combines technical analysis, which finds access that no inventory shows, with governance work, which turns the findings into clear ownership.

  • Service ownership

    Thilina Manana, Director of Operations and Security and ISO 27001:2022 Lead Auditor (CQI IRCA), is accountable for scope, confidentiality and quality.

  • Technical security team

    Specialists in systems, Microsoft 365, Active Directory, databases, cloud, offensive security and digital forensics. They find access that no inventory shows.

  • Compliance and GRC team

    ISO 27001, ENS and NIS2 consultants and auditors. They turn findings into segregation of duties, policies and clear ownership.

Hard2bit is certified to Spain's ENS at the HIGH category (certificate ENS_2.026.061) and to ISO 27001, 22301, 20000-1, 9001 and 14001. The review supports the segregation-of-duties and privileged-access requirements of ISO 27001 (controls 5.3, 5.18, 6.5 and 8.2), NIS2 (Article 21(2)(i)) and Spain's ENS, and feeds business continuity planning. For ongoing leadership, a virtual CISO can own access governance afterwards.

Duration

How the review is scoped

There is no fixed package: the review is scoped in working days according to what needs to be examined. A typical scope takes two to five weeks. After the confidential scoping call we send a proposal with scope, days and timeline.

Arrange a confidential call

What drives the number of days

  • Systems, databases, applications and projects in scope
  • Privileged and service accounts
  • Sites, subsidiaries and providers with access
  • Depth of technical analysis and number of interviews
  • Optional support during de-escalation

FAQ

Common questions about access reviews

Our IT administrator is the only person with the admin passwords. Where do we start?

With measures that remove the risk without disrupting operations: break-glass accounts held by management, confirmation that the domain and cloud accounts are in the company's name, and preserved activity logs. Once the access map is available, you decide what to separate and share. This is the first phase of the plan we deliver.

Our managed service provider will not hand over the admin credentials. What can we do?

We map what the provider controls, review what the contract says about ownership of credentials, documentation and assets, and plan an orderly handover that keeps the service running, whether you stay with the provider or move on. Afterwards, third-party risk management keeps that control in place.

Can you review a Spanish subsidiary while management sits at headquarters abroad?

Yes. The work is mostly remote, reporting is in English, and interviews or the findings session can take place on site in Spain or by video with headquarters. We agree with you who at group level receives the named detail.

Will the person concerned find out about the review?

The review is planned with management and is usually presented as an organisation-wide security review, which is a legitimate and increasingly common exercise. Only management knows the specific reason, and the team involved is small and bound by confidentiality.

Is it lawful to review an employee's access rights in Spain?

Yes, on company systems and within the GDPR, Article 87 of Spain's data protection act (LOPDGDD) and Article 20.3 of the Workers' Statute. We review access, permissions and configuration, not the content of communications, and check whether a digital-use policy has been communicated to staff. For other EU countries, local employment rules should be confirmed with your legal counsel.

Is the review limited to Microsoft 365?

No. Microsoft 365 is often the starting point, but dependency also sits in SQL databases, ERP and business applications, repositories and pipelines, servers and backups, domains and certificates, online banking, and routines only one person can run. If you only need Microsoft 365, see our Microsoft 365 security audit.

What does privilege de-escalation mean in practice?

Reducing concentrated control in four phases over 90 days: secure, separate, share and maintain. Removing someone's rights overnight can stop the operations they support, so each phase is planned to avoid service interruptions.

How long does an access review take and how is it scoped?

It is scoped in working days, based on the number of systems, databases, applications and projects, privileged and service accounts, sites and providers. A typical scope takes two to five weeks. After the confidential scoping call we send a proposal with scope, days and timeline.

Is an access review a forensic investigation?

No. The review assesses access governance and how to restore it; it does not gather evidence and has no evidential value. If there is already a specific incident, such as a leak, a deletion or unauthorised access, the right service is digital forensics with chain of custody, carried out as a separate engagement.

Concepts from our cybersecurity glossary that connect directly with this service.

Regain control of who can access your systems

A first call with management only, under NDA, to understand the situation and propose a scope.

Reviewed by Thilina Manana and Hard2bit's technical and Compliance and GRC teams. Last reviewed: .