Synergised Consulting
Proof asset

The Passwords and Permissions You Inherited: Build the Access Baseline in Week One

6 min read
Passwords and Permissions You Inherited: Build the Access Baseline in Week One

Last Updated: 17 September 2026

The first thing to do with the passwords and permissions you inherited is count them: every system, every account, every admin right, and every login that lives in only one person's head. You have inherited an access estate nobody has mapped, and government data showing 43% of UK businesses breached in the last year makes "probably fine" a poor assumption. Inventory it in week one, kill what cannot be justified, and file the register.

You Inherited an Access Estate Nobody Has Mapped

The access you took on at close was built by the previous owner's habits, not by design. Shared logins sit in a password file two employees have used for years. Admin rights were granted by tenure rather than by role. Accounts belonging to people who left the business still work. Nothing about this is visible from the outside, which is exactly why it survives an acquisition untouched: the invoices arrive, the systems run, and the assumption that access is under control sits undisturbed because no one has ever had a reason to look.

The odds do not support that assumption. According to the Department for Science, Innovation and Technology's Cyber Security Breaches Survey 2025/2026, 43% of UK businesses identified a cyber security breach or attack in the preceding twelve months, which the survey estimates at roughly 612,000 businesses. Prevalence rises with size: medium businesses reported breaches at 65% and large businesses at 69%, against 46% for small and 42% for micro firms. A small acquired business is not exempt from this pattern; it is simply less likely to have noticed. The survey itself cautions that it can only capture incidents organisations identified, so the true scale is likely higher than the figures show.

What Actually Gets Businesses Like This One Breached

Breaches at businesses of this size are not exotic. The attacks that actually land go through the front door of identity: a phishing message someone acts on, or a password that was already stolen somewhere else. That matters for a new owner because both routes are functions of the access estate, and the access estate is the one thing in the business you have complete authority to fix in week one.

Phishing Is Still the Front Door

Phishing remains the most prevalent type of breach or attack by far, experienced by 38% of UK businesses, and DSIT's survey found that 69% of affected businesses named it the most disruptive incident they suffered. The share of breached businesses experiencing phishing as their only attack type rose from 45% to 51% this year, so this is not one threat among many; for most breached businesses, it is the whole incident. Phishing works on people, but its damage is governed by access: what the person who clicks can actually reach. An estate of shared logins and broad admin rights turns one mistaken click into a wide compromise. A scoped one contains it.

Credentials Are the Way In

Verizon's 2025 Data Breach Investigations Report, which analysed more than 22,000 security incidents including 12,195 confirmed breaches, puts numbers on the identity problem. The human element featured in roughly 60% of breaches, and the use of compromised credentials was the leading initial access vector at 22% of breaches, ahead of exploitation of vulnerabilities at 20% and phishing at around 15%. Third-party involvement in breaches doubled from 15% to 30%, which matters here because an acquired business's third parties include its outsourced IT provider and its long-standing software suppliers, none of whom your diligence interviewed. A business that cannot say which accounts exist cannot begin to know which of them have already leaked.

The Week-One Access Inventory

The first-100-days answer is a complete enumeration of who can reach what, produced in week one and filed as the business's first access baseline. It is a documentation exercise, not a security project: list every system the business pays for or depends on, name every account holder on each, and mark every account that is shared, belongs to a leaver, or carries admin rights. The output is a system access register, and it becomes both the baseline you reset from and the evidence artefact you keep.

How the Enumeration Actually Gets Done

Start where the money and the customers are: email, banking and finance systems, the customer database or CRM, and the operational systems the product or service runs on. Where a system offers an admin export of users, take it; where it does not, ask the longest-serving employee to walk through it with you, because that person usually holds the working map of who uses what. In discovery workshops, the access question is one of the fastest to expose how much of a business runs on undocumented knowledge: the list of who can reach what typically gets built in the conversation, system by system, because no written version exists anywhere in the business. Expect the register's first draft to surface accounts nobody can explain. Those are the findings, not embarrassments; each one gets a named owner or a deletion date.

The Reset: Week One Is the Only Cheap Moment

Killing a shared login in week one is housekeeping. Killing the same login in month nine is politics, because by then someone's daily routine runs through it and the change looks like a judgement on how the place was run. This is the comparison that should drive the timing: the same action costs friction in week one and costs goodwill later, and week one is also the only point at which "the new owner is putting access on a proper footing" is the automatically accepted explanation.

What the Reset Covers

Do three things. Close every shared account and issue named ones. Disable every leaver account, including ones from before the acquisition. Scope admin rights down to the people whose role requires them, and record who holds them. Each action is small; taken together they close the specific gaps that phishing and credential abuse exploit.

Finding on the inventory

Action in week one

Evidence recorded

Shared login covering two or more people

Close it, issue named accounts

Register entry: named holders, date closed

Account belonging to a former employee

Disable the same day

Register entry with disable date

Admin rights held by tenure, not role

Scope down to role requirement

Admin holders listed in the register

Account nobody can explain

Suspend, then delete if unclaimed

Decision note filed with the register

The Register Outlives the First 100 Days

An access register only stays true if someone owns it. Give day-to-day custody to an office or operations manager, make it a standing item at whatever review cadence the business already runs, and date every review so the register carries its own history. The named owner matters as much as the document: an unowned register decays into fiction within a quarter, while an owned one becomes the single place a question about access gets answered.

It also becomes evidence. A buyer's diligence process eventually asks who can reach the financial systems, the customer data and the operational core, and most founder-led businesses answer that question with archaeology. A dated register naming each system, its account owners, its admin holders and its review history answers it from a file, and it demonstrates the habit of access control rather than asserting it. That is the difference between telling a buyer the estate is clean and showing them the record that would have caught it if it were not.

Sources

  1. [1] Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025/2026, published 30 April 2026:
  2. [2] Verizon, 2025 Data Breach Investigations Report, released 23 April 2025 (22,000+ incidents analysed, 12,195 confirmed breaches):
  3. [3] Background reading (qualitative guidance, no figures): NCSC Cyber Essentials scheme guidance on user access control as a first-line control,