Skip to content

Five gaps we almost always find

Across dozens of security assessments, these five findings recur in nearly every system we examine.

Tim Neuraltan · 16 July 2026 · 7 min read

Every system has its quirks. But after dozens of assessments, five findings keep reappearing — in large enterprises and small companies alike.

1. Old accounts nobody switched off

An employee left two years ago; the account is still active. Sometimes still with full database access. This is the most common finding, and the cheapest to fix.

Check it yourself: pull the list of all accounts and compare it against current staff. The difference is your homework.

2. One password opening many doors

The same administrator password on the server, the database, and the hosting panel. One leak opens everything.

3. Customer data reachable without logging in

A page that should require a login turns out to open directly if the address is guessed. This is the single most common cause behind large data breaches in Indonesia.

Check it yourself: open a customer-data page, copy the address, and load it in a private window. If the contents appear, you have a problem.

4. Backups nobody has ever restored

Backups run every night. But nobody has attempted a restore. We once found backups that had run faithfully for eight months — and were entirely empty.

Check it yourself: restore yesterday's backup to a separate server. If it cannot be done within an hour, you do not have a backup.

5. No record of who changed what

When something goes wrong, nobody can say who changed it, when, or from where. Without that record, recovery becomes guesswork.

What you can do this week

Four of the five above can be checked without special tools. You do not need to wait for an audit budget. Start with the account list — it gives results fastest.

Facing something similar?

Describe your situation. We will reply with the approach that makes most sense for it.