Identity Sprawl: Why Australian Businesses Need an Identity Maturity Assessment in 2026

Identity Sprawl: Why Australian Businesses Need an Identity Maturity Assessment in 2026
Identity Sprawl: Why Australian Businesses Need an Identity Maturity Assessment in 2026
Identity Sprawl: Why Australian Businesses Need an Identity Maturity Assessment in 2026
Identity Sprawl: Why Australian Businesses Need an Identity Maturity Assessment in 2026
Identity Sprawl: Why Australian Businesses Need an Identity Maturity Assessment in 2026

A Perth engineering consultancy discovered during a routine software licence audit that a project manager who had left the company eight months earlier still had active login access to the firm’s cloud file storage, its project management platform, and two client-facing SharePoint sites. Nobody had revoked the accounts. As far as anyone could tell, the former employee had not misused the access — but for eight months, someone with no relationship to the business held the technical ability to download confidential client drawings, financial models, and tender documents.

This is not a rare oversight. It is the default state of identity management at most Australian small and mid-sized businesses. As companies adopt more cloud applications — accounting software, CRM, project management, file storage, HR systems — the number of places an employee has an active login multiplies. Onboarding a new starter is usually handled reasonably well. Deprovisioning a leaver, revoking a contractor’s access when an engagement ends, or tightening admin rights that were granted “just for one project” and never removed — these are the gaps that accumulate quietly until an audit, a breach, or a penetration test surfaces them.

Why Identity Has Become the New Perimeter

For years, businesses treated the network firewall as the primary line of defence. That model no longer reflects how people actually work. Staff log in from home, from client sites, and from personal devices, into SaaS applications that live entirely outside the traditional network boundary. In that environment, a valid set of credentials is often all an attacker needs — there is no firewall to breach if the attacker can simply log in. The Australian Signals Directorate has repeatedly identified compromised or misused credentials as one of the most common entry points into Australian organisations. Identity — who has access to what, and how that access is granted, reviewed, and removed — has effectively become the new perimeter.

The Identity Gaps We Find Most Often

When we run Identity Maturity Assessments for Australian businesses, the same patterns turn up again and again, regardless of industry.

GapWhy It MattersHow Common
Orphaned accounts from former staffEx-employees retain access to email, files, and client systemsExtremely common
No formal offboarding checklistAccess removal depends on someone remembering, not a processVery common
Contractors and vendors with standing accessThird parties often keep access long after the engagement endsCommon
Excess admin and privileged rightsStaff hold far more access than their role requires, widening the blast radius of any compromiseVery common
No MFA on privileged or admin accountsA single stolen password can grant full administrative controlCommon
No periodic access reviewsNobody is checking whether existing access still makes senseExtremely common

Key point: An Identity Maturity Assessment does not assume malicious insiders. Most exposure comes from accounts nobody remembered to close, not employees behaving badly. The risk is dormant, not active — until an attacker, or a curious former contractor, finds it first.

Your Legal and Regulatory Exposure

Identity failures are not just a technical loose end — they carry direct compliance weight. Under the Privacy Act 1988, businesses holding personal information are required to take reasonable steps to protect it from unauthorised access, and a former employee retaining system access for eight months would be difficult to defend as “reasonable” in an OAIC investigation following a breach.

The ACSC Essential Eight, which the Australian government increasingly expects businesses of all sizes to align with, includes “Restrict Administrative Privileges” as one of its eight core mitigation strategies — directly targeting the excess-admin-rights gap described above. For businesses regulated by APRA, CPS 234 explicitly requires identity and access management controls proportionate to the sensitivity of information assets, including timely revocation of access. Businesses pursuing ISO 27001 certification will find access control forms a core part of the audit.

Key point: If your business has never mapped who has access to what, you cannot demonstrate compliance with any of these frameworks — regardless of how strong your other security controls are.

What an Identity Maturity Assessment Actually Covers

An Identity Maturity Assessment is a structured review of how your business manages digital identity across its full lifecycle, not just a login audit. It typically examines onboarding and offboarding processes, privileged and administrative access, multi-factor authentication coverage across business-critical systems, single sign-on adoption, contractor and third-party access management, and the frequency (if any) of formal access reviews. The output is a maturity rating against each of these areas, plus a prioritised list of what to fix first — usually starting with the gaps that create the most exposure for the least effort to close.

Practical Steps You Can Take This Month

  1. Run a full user access audit across your core systems. Export the active user list from email, file storage, and your practice or project management software, then compare it against your current staff list — anyone who has left in the last 12 months should be flagged immediately.
  2. Enable MFA on every privileged and admin account first. If you can only tackle one system this month, make it the accounts with the most access — not the ones that are easiest to configure.
  3. Build an offboarding checklist and assign an owner. Access revocation should not depend on someone remembering — a simple checklist tied to your HR exit process closes the majority of orphaned-account risk.
  4. Set an expiry date on every contractor and vendor account. Standing access with no end date is how third-party engagements quietly turn into permanent, unmonitored access.
  5. Schedule a quarterly access review. Even a basic 30-minute review of who has admin rights, run once a quarter, catches privilege creep before it becomes a liability.

What We Find in Identity Maturity Assessments

In the first pass of an Identity Maturity Assessment, we typically uncover at least one former employee or contractor with active access, administrative rights held by staff who have no operational need for them, no consistent MFA enforcement across cloud applications, and no documented process for reviewing or revoking access. None of this requires a sophisticated attack to exploit — it requires only that someone finds the door was never locked.

Find Out What Is Already Exposed About Your Business

Run a free Cybernod dark web scan on your domain. See exactly what credentials and data threat actors can already find about your business — in under 5 minutes. If anything surfaces, we will walk you through what it means and what to do next.

Fort1 works with Australian businesses on Identity Maturity Assessments, penetration testing, and compliance advisory. We help you understand exactly who has access to what — and close the gaps before someone else finds them. Reach out at info@fort1.com.au or call +61 1300 294 089.

Fort1 is an Australian cybersecurity firm based in Sydney. We provide penetration testing, compliance advisory, and dark web monitoring. Contact us at info@fort1.com.au or +61 1300 294 089.