Dabish Digital
Security

Three myths about access control

This is one of those topics that looks small until it costs you something. A few things about access control that get repeated more often than they get checked.

The realistic threat for most small businesses is automated and opportunistic, not targeted. The practical test is whether someone new to the project could tell, in a minute, that it had been handled.

“It only matters for big sites”

Give the least access that lets someone do their job. None of that requires a large budget, only a decision and someone to own it. Check it against what you would want a competitor's site to get wrong.

“We can deal with it after launch”

Sometimes true, usually expensive. Getting it slightly wrong is survivable. Ignoring it entirely is not.

“Our platform handles it”

Shared logins destroy accountability. Where this goes wrong is almost never a lack of knowledge. Assume whoever inherits this will have half your context and none of your patience.

The short version

Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about access control before you move on:

  • Someone can say what the current setup is without going to look
  • Give the least access that lets someone do their job — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

None of this needs a rewrite. Most of it is a morning's work once someone decides to do it.