Skip to content

You Didn’t Approve the Risk, But You’re Still Responsible for It

You didn’t sign off on the configuration.

You didn’t install the server.

You didn’t create the account, approve the exception, or authorize the shortcut.

But when the question came—Who owns this risk?—everyone in the room turned toward you.

That’s how January started.

The incident was small. Embarrassingly small. A former employee logged into a system they shouldn’t have been able to access. No damage. No theft. No malice proven.

Just access.

The account had never been disabled. Not intentionally. It had simply been overlooked during a busy transition months earlier. HR assumed IT handled it. IT assumed HR would flag it. Operations assumed someone else was tracking it.

No one was negligent.

Everyone was exposed.

If you run a financial firm, you already understand how unforgiving this is. Regulators don’t ask who meant well. They ask who was responsible. Healthcare executives know it even more intimately. Patient data doesn’t care about intent. Legal firms live in this reality every day—privilege is either preserved or it isn’t. Engineering firms feel it when intellectual property quietly leaks, not in dramatic thefts, but in access that never should have existed.

In 2007, Microsoft’s platforms were no longer forgiving ambiguity. Identity was becoming central. Access logs were precise. Audit trails were deep. Silence was no longer deniability—it was evidence of inattention.

The meeting that followed wasn’t technical.

It was operational.

“How many accounts do we have that no one owns?”
“How many systems still trust people who’ve moved on?”
“How many decisions were made by default instead of design?”

Those questions land differently when you’re the one answering to a board, a regulator, or a client who trusts you with their livelihood.

The uncomfortable truth surfaced quickly: access had been treated as a convenience instead of a contract.

People were granted credentials to get work done—and then forgotten. Exceptions accumulated. Temporary permissions hardened into permanent exposure.

You don’t need a breach for that to matter.

You only need discovery.

January forced leadership to confront a reality most organizations avoid: if no one explicitly owns risk, leadership owns it implicitly.

The response wasn’t dramatic. No mass shutdowns. No performative crackdowns.

It was procedural. Methodical. Quiet.

Accounts were reviewed—not just for activity, but for justification. Each one answered a simple question: Why does this still exist?

Many didn’t survive the answer.

That process was uncomfortable for staff. It always is. But it was clarifying for leadership.

Because once you accept that you are responsible for risks you didn’t personally approve, you stop tolerating systems that depend on memory, goodwill, or silence.

January didn’t bring fear.

It brought clarity.

And clarity, in regulated industries, is protection.

Leave a Reply

Discover more from Matrixforce Pulse

Subscribe now to keep reading and get access to the full archive.

Continue reading