Most breaches don't start with a hacker. They start with a door nobody closed
The hacker in a hoodie guessing passwords is mostly a movie. Most real breaches start smaller: an ex-employee's login nobody revoked, a password shared in a chat two years ago, a plugin nobody remembers installing.
The hacker in the hoodie is mostly fiction
The image everyone has is someone in a dark room brute-forcing their way past a firewall. Most real incidents look nothing like that. Someone logs in with a valid username and password, because the credentials still work. Nobody breaks the lock when the door was never actually closed.
Every 'temporary' access becomes permanent
A freelancer gets admin rights for a two-week project and keeps them for two years. A former employee's email still opens the CMS, the analytics dashboard, the payment provider. A password gets shared in a group chat once, gets screenshotted, and outlives three job changes. None of this feels like a decision at the time. It just never gets undone.
The real question is not 'are we secure'
"Are we secure" is not a question anyone can answer honestly - it always sounds like yes. The useful question is smaller and more uncomfortable: who, right now, can log into this system, and does every single one of them still need to? Most companies have never actually written that list down.
The ACS approach
We treat access like inventory, not a one-time setup step. That means an offboarding checklist that actually revokes logins the day someone leaves, credentials that get rotated instead of inherited forever, and a periodic pass through who has keys to what. It is not glamorous work, but it is the difference between a mistake staying a mistake and a mistake becoming a headline.