When employees leave a company or new ones join, many small and medium-sized enterprises (SMEs) struggle to manage digital access properly, leaving accounts vulnerable to cyberattacks. Without a dedicated information security officer, SMEs often rely on limited resources to handle employee transitions. This can lead to delays in revoking access for departing staff, or hastily setting up accounts for new hires without proper security measures. During these gaps, old accounts with unchanged passwords may remain accessible, creating opportunities for exploitation by former employees, disgruntled contractors, or hackers. According to Cybermalveillance.gouv.fr, 80% of cyberattacks on SMEs stem from human error or poor handling of digital access. Many information security officers also point out that employees are the weakest link in data protection. New hires are especially at risk during their first week, as they may be targeted by phishing emails—deceptive messages designed to steal login credentials or install malware. This risk is even higher during large recruitment drives, such as for interns or seasonal workers, where HR teams may create accounts quickly without considering the specific needs or access levels of each new employee. These individuals, often lacking multi-factor authentication or awareness of internal protocols, are more susceptible to targeted attacks like spearphishing (email-based attacks tailored to a specific person) or vishing (voice phishing). Unused or forgotten accounts can also pose serious risks. The State of Data Security Report 2025 by Varonis found that 88% of organizations have at least one active but unused account. These accounts may contain sensitive data, and if not properly managed, they can lead to data breaches. In some cases, employees store work files only on personal computers, increasing the risk of data loss if no archiving plan is in place before their departure. Forgotten email accounts may contain contracts, invoices, and confidential communications that are accessible to anyone who discovers the password. The consequences of unmanaged accounts can be financial as well. In 2025, the CNIL (France’s data protection authority) recorded 6,167 personal data breaches, a 9.5% increase from the previous year. Half of these were due to hacking, often linked to unsecured employee accounts. The CNIL requires companies to report breaches within 72 hours, regardless of their size. In 2025, the CNIL issued 83 sanctions totaling 486.8 million euros, with some penalties capped at 20,000 euros per violation. Companies must also maintain a detailed record of all breaches, even if they are not reported to the CNIL, for potential audits. To reduce these risks, SMEs are encouraged to use password managers, grant access only to necessary resources, and regularly check active employee lists against payment accounts before contract renewals. For example, Tesla recently sued a former employee for allegedly stealing data before leaving the company. Managing digital accounts is crucial, as they are numerous and more complex to track than physical access cards. Proper oversight can help protect both company data and avoid costly legal consequences.