The former employee who still had the keys

A business runs an access review, sometimes because it was scheduled, sometimes because someone asked a question that happened to prompt one, and a name appears on the list that should not be there. A staff member who left months ago, not on good terms, still has active credentials to the business systems. As far as anyone can tell, the account was never used after they left, but it could have been at any point during that time, and, for a period that is now difficult to look back on comfortably, the door was wide open to someone with every reason to walk through it.

The question the business owner is now sitting with is not how to fix it, because that part is already done. The harder question is how long it was the case without anyone noticing, and whether there are other accounts or other access points sitting in a similar state right now.

One second from a disclosure event

A file is attached to an email, the recipient field is filled in from the autocomplete list, and the send button is almost pressed before someone catches it. The attachment contains medical records, financial details, or other data that carries legal disclosure obligations if it reaches the wrong person, and the wrong person was a single click away from receiving it. The attachment is removed, the email is redirected, and the moment passes, leaving behind the realisation that the only thing standing between the business and a formal regulatory notification was a second glance that, on a busier day, might easily not have happened.

The server that almost took the data with it

Physical risk tends to get less attention than digital risk, but it produces the same uncomfortable question when it comes close. A surge event, a burst pipe, a maintenance issue somewhere in the building, and something comes within a short distance of the room or the cabinet where the business data lives. The equipment survives and the data is intact, but the conversation that follows tends to drift somewhere the business owner was not prepared for: if that had been worse, what exactly was the recovery plan, and is there actually an off-site copy of everything that matters?

For some businesses, the honest answer that surfaces in that conversation is that the data and the only backup of that data were sitting in the same room, and they were both nearly gone at the same time.

Recovered, but only just

A shared folder is deleted, or a file that represents months of accumulated work simply disappears from where it should be, and IT is able to recover it from a backup. The immediate crisis passes, but the version that comes back is several hours old, and in the gap between when the backup was taken and when the deletion happened, there is work that is simply gone with no way to retrieve it. The business got most of it back, and under the circumstances "most" was close enough to count as a win, but the question of what would have happened if the backup had been a day older, or if there had not been one in place at all, does not have a comfortable answer.

What a near miss is actually telling you

A real incident forces decisions, leaving you no choice but to act, and the actions you take in the process tend to answer questions you did not know you had, whereas a near miss surfaces exactly the same questions and then leaves you to decide whether to answer them now or wait for circumstances that make the decision unavoidable.

That is actually the more useful outcome, because you still have time to act on what the near miss revealed before anything goes wrong. The access review, the file-handling process, the off-site backup, the recovery test: none of these require an incident to justify them. They just require someone to decide that the near miss was warning enough to be worth taking seriously.

If something recently made you think "that could have been so much worse," that feeling is worth following up on. Get in touch and let's work out what it is pointing at.