Former Employee Login Exposes Flaws in Corporate IT Design

The Structural Problem Behind a Former Employee's Login

A former employee logged into the VPN late at night—this "anomaly" was reported in an article by Keyman's Net. At first glance, it may seem like an isolated security incident. However, this case highlights a fundamental flaw in corporate IT design. Why was the former employee's account still active? Why couldn't the late-night login be detected? These questions directly point to a management approach that has left IT to the "IT department."

This article uses this case to analyze the cost of management failing to define the purpose of IT. It then explains concrete measures to prevent recurrence from a management decision-making perspective.

Why Do Former Employee Accounts Remain Active?

The reason former employee accounts are not deactivated is not simply a "procedural oversight." It is evidence that the purpose of IT has been set only to "stable operation." In many companies, the evaluation criteria for IT departments are biased toward "keeping systems running." As a result, "mundane but critical tasks" like account management are deprioritized.

Furthermore, the offboarding process itself is often ad-hoc. There is often no system for HR to relay departing employee information to the IT department, relying instead on the memory of individual staff members. This is a direct result of management viewing IT solely as "administrative IT."

If management had expanded the purpose of IT to include "business growth" or "reproducibility of decision-making," account management would not be just a security measure but a means of controlling management resources. However, because many companies fail to define the purpose of IT, such basic risks are left unaddressed.

The Organizational Blind Spot That Misses Late-Night Logins

The failure to detect a late-night login stems from a structure where log monitoring is limited to "incident response." In many companies, VPN connection logs are only used to check if "the system is running normally." However, logs exist to record "who did what and when" and to detect anomalous behavior.

This blind spot is a result of management limiting the role of IT to "administrative IT." If management had adopted a "business IT" or "strategic IT" perspective, log data would have been used for early detection of unauthorized access and strengthening internal controls. However, management's demand for "zero incidents" from the IT department has created this monitoring gap.

Specifically, the purpose of log monitoring needs to be set to "detecting security incidents," with a system in place to automatically notify of anomalous logins during late nights or holidays. Such a system can be implemented simply by introducing tools. For example, SIEM tools like Splunk or Microsoft Sentinel can automatically detect unusual login patterns. However, the attitude of "leaving log monitoring to the IT department" often becomes a barrier to implementation in many companies.

The Cost of Management Not Defining the Purpose of IT

This case illustrates the tangible cost of management failing to define the purpose of IT. Leaving former employee accounts active not only creates a risk of data leaks but also fosters an environment for internal fraud. Missing a late-night login is equivalent to overlooking signs of a cyberattack.

These risks are a natural consequence of management leaving IT to "the experts." If management sets the purpose of IT only to "stable operation," tasks like account management and log monitoring are neglected. And this neglect can lead to critical incidents.

Moreover, this is not just a security issue. In organizations where the purpose of IT is undefined, all IT investments become ad-hoc. Even when introducing a system for managing former employee accounts, if the purpose of "why it is needed" is not clear, budgets won't be approved, and operations won't continue after implementation.

Management Decisions Needed to Prevent Recurrence

To prevent recurrence, management must redefine the purpose of IT. Specifically, the following three decisions are required.

First, expand the purpose of IT from "administrative IT" to "strategic IT." Position account management and log monitoring not as mere costs, but as a means of controlling management resources. To achieve this, a system for regularly reporting IT risks at management meetings is necessary.

Second, automate the management of former employee accounts. For example, implement a system that automatically deactivates accounts on the employee's last day by integrating with the HR system. Specific tools like Okera or Azure AD's automation features are effective. These tools can be introduced for a few hundred to a few thousand yen per month (roughly $2 to $30 USD), offering extremely high cost-effectiveness.

Third, change the purpose of log monitoring from "incident response" to "security detection." This requires implementing SIEM tools and setting rules for anomaly detection. Management's responsibility is not to tell the IT department "what to monitor," but to define "why we monitor."

Conclusion: IT Design is Management's Responsibility

The case of a former employee logging in late at night is a classic result of management failing to define the purpose of IT. This problem cannot be solved by the efforts of the IT department or security personnel alone. Management must redefine the purpose of IT and make investment and organizational design decisions based on that purpose.

IT is not a "technical area to leave to experts" but a management resource that management must define directly. Use this case as a lesson and consider reviewing your company's IT design. When management defines IT, security risks are significantly reduced, and the effectiveness of IT investments is also maximized.