When hiring new employees, companies often set up their computer accounts by copying the access rights of existing colleagues. This approach can result in new employees receiving more access than they actually need for their roles. Similarly, when employees leave, their access to company systems may remain active for weeks or even months, as there are often no clear procedures in place to deactivate these accounts. These practices increase the risk of cyberattacks, especially for small and medium-sized enterprises (SMEs), which are particularly vulnerable due to limited resources and expertise in cybersecurity. The National Cybersecurity Agency of France (ANSSI) has outlined thirteen essential measures to improve data security in SMEs, but none of these specifically address the creation or deletion of user access rights. In smaller companies—those with fewer than 100 employees—the same person often manages both hiring and offboarding processes, including IT access. This lack of specialization can lead to oversights in following best practices, such as ensuring that each employee has only the access they need for their role. Copying access rights from existing colleagues can lead to serious security issues. New employees may inherit shared passwords, access to files unrelated to their role, or even forgotten administrator rights from previous tests. This practice violates ANSSI recommendations, which emphasize separating different types of access and avoiding the use of administrator accounts for routine tasks. In 2025, the ANSSI sanctioned fourteen organizations for poor data security practices, including the use of simple passwords and shared accounts. These issues often go unchecked during hiring or later due to competing priorities, even though creating a new account is an opportunity to implement two-factor authentication, a critical defense against unauthorized access. When employees leave, there is often no set date for account closure, allowing former employees to retain access to company systems. This can lead to tampering with documents or tasks, especially if the departure was contentious. The French Data Protection Authority (CNIL) requires employers to inform employees of their professional email closure date, giving them time to retrieve their data. Failure to comply can result in fines of up to 20,000 euros. However, this requirement is rarely followed in most SMEs due to the lack of a formal IT charter outlining procedures. Unused accounts and subscriptions can also pose risks. For example, an intern might be given a graphic design license that remains active after they leave, and the IT department may not notice if the subscription was paid for with a personal credit card or an unregistered professional email. According to a study by Vendr, nearly all companies surveyed had at least one unused license, with an average of 1.4 dormant licenses per SME. In a company with 50 employees, even a few inactive accounts can significantly increase the risk of cyberattacks. These accounts appear legitimate to the system and are not detected by traditional security tools like firewalls or antivirus software. In 2021, hackers accessed a major U.S. pipeline operator through an inactive account that lacked two-factor authentication. While SMEs may not run pipelines, they face similar risks from unmonitored active accounts. To reduce these risks, SMEs should establish a clear IT charter that includes account closure dates for departing employees, shared between HR and IT. Employees should be informed of their professional email closure date as required by the CNIL. At least once every quarter, companies should review all active accounts, including SaaS subscriptions, to identify unnecessary access rights. Service accounts and shared access should be inventoried and assigned to specific individuals. Managers should report employee departures immediately, not waiting for the end of the notice period. Access should be deactivated according to offboarding procedures, and two-factor authentication should be enabled on all accounts, including the oldest and least used ones. Automating account creation and deletion using a single sign-on tool with mandatory authentication and connection tracking can also help prevent security breaches.