As a cybersecurity consultant, I see organizations investing heavily in security programs, tools, and processes, but some of the same gaps continue to surface across environments. Often, the issue isn’t a lack of awareness or effort. It’s that seemingly straightforward security improvements can get buried beneath competing priorities, complex environments, and the demands of keeping the business running.
What’s easy to overlook is that some of these issues are more actionable than they appear. A few targeted changes can strengthen an organization’s security posture, reduce unnecessary risk, and save significant time and resources down the road.
There are four mistakes in particular that I’ve seen repeated across organizations. Here’s why they continue to happen, what they can cost, and, most importantly, how to address them.
1. Lack of MFA and password hygiene
Employees are not aware of proper password hygiene and are not properly trained on the security issues of reusing passwords across platforms and in both personal and work contexts. Employers also do not consistently technically enforce password complexity requirements and frequent password rotations. It only takes one employee's reused personal password being exposed for attackers to find a working password to your systems.
Here’s how to fix it:
Enforce MFA across all systems that support it, prioritizing email, VPN, and privileged accounts first.
Deploy a password manager organization-wide so employees aren't relying on memory or reuse to manage credentials.
Set technical controls for complexity and rotation through your identity provider rather than relying on policy alone, and monitor for credentials appearing in breach data so exposed passwords can be forced to reset before they're used against you.
Pair these controls with recurring, scenario-based training that explains why password reuse across personal and work accounts creates risk, not just that it's against policy.
2. Lack of proper risk tracking and follow through
Many organizations do not have a properly developed and updated risk register to track risks to remediation, including assign accountability and likelihood impact ratings. Many employers neglect to track risks and ensure there is an assigned responsible party, there are proper prioritizations established, and the risk register is integrated into remediation procedures. When organizations fail on the follow-through, it significantly negates the impacts of assessments, tabletop exercises, and other methods used to identify weak points in the organization's security procedures. Failure to remediate identified issues is often what leads to breach susceptibility and increased attack surface. This follow-through is an integral part of ensuring ROI on these tests and keeping your environment secure.
Here’s how to fix it:
Build a centralized risk register that captures each identified risk, its likelihood and impact rating, an assigned owner, a target remediation date, and current status.
Review it on a set cadence, not just after an assessment, and treat findings from audits, assessments, and tabletop exercises as inputs that must flow directly into the register rather than living in separate reports.
Assign accountability to a specific person or role, not just a team, and report status to leadership regularly so unresolved risks don't quietly age past their target dates.
3. Lack of familiarity and proper testing and updating of IRPs
Many organizations develop Incident Response Plans due to regulatory requirements and industry expectations, but many organizations do not properly and frequently update their IRPs annually and following significant changes. Additionally, organizations do not implement frequent training and reviews on the IRP. In the event of a cybersecurity incident, incident responders are less familiar with the IRP, increasing response time and exacerbating the cyber attack. It is integral to ensure familiarity with security procedures and documentation so that employees are prepared to respond to incidents and understand their responsibilities.
Here’s how to fix it:
Review and update the IRP at least annually, and immediately following any material change to infrastructure, personnel, or the threat landscape.
Run tabletop exercises at a regular cadence so responders practice their roles before a real incident forces them to learn on the fly, and update the plan based on what those exercises reveal.
Make sure every person named in the plan knows their specific responsibilities and has access to the current version, not an outdated copy.
Treat the IRP as a living document tied to training, not a compliance artifact that gets filed away after it's written.
4. Over-permissioning access
Many security teams will permit administrative access to critical resources to employees and/or contractors that may not require all of the privileges involved in these roles. To limit access to confidential information and critical resources, organizations should conduct regular RBAC reviews to ensure users only have the access they need to execute regular job functions. Otherwise, in the event of an attack, exposure to critical infrastructure and data is much more likely. It is also more likely for employees, whether intentionally or unintentionally, to expose sensitive data or otherwise inflict harm onto critical organizational infrastructure.
Here’s how to fix it:
Apply the principle of least privilege as the default for all roles, including contractors and third parties, and require justification for any elevated access.
Conduct RBAC reviews on a recurring schedule to catch privilege creep, especially after role changes, project completions, or offboarding.
Use time-limited or just-in-time access for administrative tasks instead of standing privileged accounts, and log and review privileged access activity so unusual use is caught early rather than discovered after an incident.
A reused password, an unclosed risk, an untested plan, an overprovisioned account: these aren't edge cases, they're the norm, and attackers know it. People get distracted by their daily to-do lists and other tasks with concrete, approaching due dates. It’s human nature that organizations prioritize increasing efficiency and completing tasks that are looming over their heads, rather than those that solve an abstract problem that hasn’t happened yet. In my observations, I've noticed that many significant and costly gaps are not closed due to a lack of urgency and understanding of the implications of exploitation. The organizations that stay ahead aren't the ones with the most tools. They're the ones that close the loop: enforce MFA everywhere, remediate what the risk register already flagged, rehearse the IRP before it's needed, and review access before someone else finds the gap first. Security maturity is less about identifying gaps and more about closing them.
If any of this sounds familiar, our Risk Advisory + GRC team can help. From building out a risk register to reviewing access and testing your Incident Response Plan, we work with organizations to close these gaps before they turn into breaches.