Glossary

Principle of Least Privilege

Give people only the access they need, nothing more. The intern doesn't need admin rights. The accountant doesn't need access to HR files. Less access means less damage if compromised.

What is Principle of Least Privilege?

Security principle that users should have only the minimum access rights needed to perform their job functions.

Why Should You Care?

Overprivileged accounts become high-value targets for attackers—a compromised employee account with admin rights or cross-functional access can be weaponized to breach multiple systems at once. Limiting access reduces the blast radius when credentials are stolen or an insider becomes malicious, since the attacker can only reach what that role genuinely requires. Organizations that enforce least privilege see dramatically fewer lateral movement attacks, because attackers can't simply pivot from an email account into the entire database.

Is your business exposed?

Real-World Example

A support agent who only needs to view customer orders shouldn't have credentials to modify billing systems or access payment card data—yet many organizations grant broad database access to entire departments. When that agent's laptop gets infected with malware, the attacker gains only read-only access to orders instead of the ability to process fraudulent refunds or exfiltrate payment information. Similarly, third-party contractors should never receive persistent admin access to internal systems; instead, they should get time-limited, role-specific credentials that expire when their contract ends.

How to Protect Against Principle of Least Privilege

  1. 1.

    Review all user permissions

  2. 2.

    Remove unnecessary admin rights

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required