top of page
Tissu délicat
Ombres douces

THE DIGITAL GOVERNANCE CASE FILES

True stories… or almost.

Situations inspired by real-life cases that shed light on the often-overlooked risks associated with digital assets, access, licenses, and responsibilities within organizations.

Executive urgently seeking his company's Google access credentials, illustrating the risks associated with undocumented administrator accounts and reliance on a single individual.
CASE FILE 006

Who has Google access?

An urgent publication, necessary access… and no one knows who owns the administrator account. The problem is no longer technical: it's a governance issue.

A publication needs to be made quickly. The manager requests access to the company's Google tools.


Problem: no one knows exactly which account holds administrative rights , who has the login credentials, or which people currently have access to the different services.


Access was created gradually over the years by employees, managers, agencies, or external suppliers. Some resources are associated with work accounts, others with personal addresses.


When the time comes to intervene quickly, the company discovers that it uses its Google environment daily without having a clear view of who actually controls it .

ASSET CONCERNED

Google ecosystem, administrator accounts and digital access

GOVERNANCE ISSUE

Control, allocation and continuity of administrative access

GOVERNANCE FINDINGS

The organization does not have a centralized and up-to-date register of its accounts, administrators, owners, and authorization levels .


Operational access to a service does not necessarily mean that the company has administrative control over it.


When a digital asset depends on an individual account or a single person, that person unintentionally becomes a single point of failure .


Business continuity then relies more on the availability of an individual than on a governance structure belonging to the organization.

IDENTIFIED RISKS

  • Loss or blockage of administrative access

  • Dependence on an employee, manager, or supplier

  • Business accounts linked to personal addresses

  • Inability to intervene quickly during an emergency

  • Maintaining access after an employee leaves

  • Excessive allocation of administrative privileges

  • Difficulty in determining who made a change

  • Complex recovery of a compromised account

  • Interruption of essential services

  • Security risks associated with sharing credentials

RECOMMENDED MEASURES

  • List all Google accounts and services used by the organization

  • Identify the owners and administrators of each asset

  • Use company-controlled business accounts

  • Avoid having a single person with sole administrator access

  • Appoint at least one primary administrator and one backup administrator

  • Enable multi-factor authentication on sensitive accounts

  • Assign privileges according to actual responsibilities

  • Document the procedures for adding, modifying, and removing access

  • Review authorized users periodically

  • Establish a procedure for recovering and maintaining access

WHAT TO CHECK IN YOUR ORGANIZATION

☐ The Google accounts used by the company are listed
☐ The owner of each asset is identified
☐ The administrators are known and documented
☐ Critical accounts belong to the organization
☐ No single personal account constitutes the sole administrative access
☐ A backup administrator is planned
☐ Multi-factor authentication is enabled
☐ The old users have been removed
☐ Authorization levels are tailored to responsibilities
☐ A procedure for recovering access exists

KEY PRINCIPLE

Having access to a tool does not mean having control over it.

bottom of page