Sentinel Vault
← All field notes
Cyber Leadership & Risk · May 25, 2026

Your Highest-Value Attack Vector Already Has a Badge

Your Highest-Value Attack Vector Already Has a Badge

On May 23, 1997, a Marine Corps veteran and former NSA staffer named Robert Lipka pleaded guilty to one count of espionage in a federal courtroom in Pennsylvania. He took an eighteen-year sentence in exchange for the plea. Lipka had worked in the NSA's central communications room. For years he had walked classified material out the front door and handed it to KGB officers at pre-arranged dead drops. He was paid roughly twenty-seven thousand dollars across the operation. He stopped on his own in 1974. He was caught more than twenty years after he stopped.

This happened with no internet. No cloud. No phishing emails, no AI, no zero-day exploits. The technology of espionage was a manila envelope under a park bench. The bottleneck was a person with a badge, an access card, and a reason to walk through the building.

The technical attack surface has expanded by orders of magnitude since 1997. The human surface has only grown with it. Every endpoint, every SaaS tenant, every shared admin password is another place where a single authorized human can do more damage than an unauthorized intruder ever could.

If you are running a small or mid-size organization in 2026, your highest-value attack vector is not phishing. It is not ransomware delivered by a stranger. It is the person who already has a badge, a login, and a reason to be in the system.

Modern echoes, at descending altitude

In April 2023, federal agents arrested Jack Teixeira, a twenty-one-year-old airman in the Massachusetts Air National Guard. For months he had been taking classified intelligence material on the war in Ukraine, photographing it on his bedroom floor, and posting it to a private Discord server he hosted for a group of online friends. The leaks included sensitive battlefield assessments, satellite imagery, and intelligence on allied governments.

The story is not about Russia hacking the Pentagon. The story is about access. Teixeira's job did not require him to read the documents he leaked. His clearance gave him the technical permission. No process around that permission ever asked the question that mattered: does this junior airman actually need to be reading the daily intelligence briefing on a foreign war? The answer was no. The question was never asked.

That is least-privilege failure. It is the same failure that produced Edward Snowden and Reality Winner. It is the same failure that will produce the next one. And it is the failure that almost every small organization carries in some form.

Consider a real pattern, anonymized from cases I have worked. An accounts payable clerk at a forty-employee distribution company is granted database administrator access to the accounting system, temporarily, to help finish a year-end migration. The migration completes. Nobody removes the access. Three years later she resigns to take a position at a competitor. On her last morning she runs a single query against the vendor master table, exports it to a flash drive, and walks out at lunch. The company discovers it six weeks later when their largest supplier starts receiving outreach from her new employer with knowledge of their pricing terms, payment schedules, and contract dates.

The technical "breach" took ninety seconds. The conditions that made it possible took three years to build.

Or take a smaller pattern. A managed services provider with seven employees has full administrative access to twenty-three client Microsoft 365 tenants. One of those seven employees gets fired for performance reasons on a Friday. On Monday his access to the MSP's own systems is revoked. His access to the twenty-three client tenants is not, because nobody at the MSP keeps a list of every external system any employee has been granted. He keeps the keys to twenty-three businesses for as long as he wants to. Most of the time nothing happens. Sometimes it does.

These are not edge cases. These are the unglamorous middle of the bell curve.

What small organizations actually miss

In ten years of cyber-fraud investigations, I can count on one hand the number of mid-market victims who had formal answers to four questions:

Who has privileged access to what, by name, today?

What happens to that access when the person leaves?

When was the last time anyone reviewed whether a vendor still needs the access we granted them?

If someone with privileged access started doing something unusual at two in the morning, would anyone know?

The standard SMB cyber posture is built around the perimeter. Firewalls, anti-virus, phishing simulations, an MFA rollout that took eight months to land. All of this defends against the outsider who has to break in. None of it defends against the insider who is already in and was given the keys legitimately.

The most expensive insider failures I see do not start with a malicious decision. They start with a casual one. A temporary access grant that never expires. A shared admin password that nobody changes when the IT person quits. A vendor account labeled "QuickBooks consultant 2022" that still has full books access two years later. A backup operator with read access to every file on the server because that was the easiest way to set up the backup software in 2019.

Each one of these is a Lipka in slow motion. Most of them never fire. The ones that do are not stopped by any tool in the standard SMB security stack. They are stopped, or not stopped, by process discipline that almost nobody has.

The recognition gap, again

Two weeks ago I wrote about the gap between recognizing a scam and acting on the recognition. The same gap shows up in insider cases, in a more uncomfortable form.

In nearly every insider case I have worked, at least one colleague noticed something before it became a crisis. The unusual interest in systems outside their role. The late-evening access that did not match their normal hours. The conversation about a competitor that landed wrong. The mood shift in the weeks before resignation. Sometimes it is gut feel, sometimes it is something concrete enough to write down.

It almost never gets reported.

The reasons are predictable. Reporting a colleague carries social cost. Most organizations have no clear channel for "this might be nothing but I want to flag it." The person doing the flagging assumes that if it is real, somebody else will catch it. The person who would catch it assumes that if it were real, somebody would have flagged it.

The fix here is not a tool. It is a culture where flagging is normalized, where the person who flags is protected, and where leadership treats early warnings as load-bearing rather than as gossip. That is hard work. It is also the single most effective insider-threat control most organizations have available, and it does not show up on any security product roadmap.

A ninety-day plan you can actually run

Pick a Tuesday in the next two weeks. Block ninety minutes. Do these five things.

Inventory privileged accounts. Pull the list of every account in every system with admin, owner, or full-access rights. Write down the human owner of each account by name. If you cannot identify a human owner, that account either has the wrong access level or should be deleted.

Build the departure checklist. HR and IT together. When an employee or contractor leaves, what gets revoked, by whom, and on what timeline. Twenty-four hours for system access. Forty-eight hours for vendor portals. Seven days for shared cloud storage. Put it in writing. Run it the next time someone leaves.

Audit vendor access. Every external party that has any login into your systems. Has each one logged in within the last ninety days. If not, revoke. If yes, confirm with the vendor that the named person who has the access still works there and still needs it. This one is harder than it sounds and uncovers a surprising number of zombie accounts.

Turn on file-access logging on the three most sensitive systems you have. Customer database, financial system, document repository. You do not need to read the logs daily. You need them to exist so that when something happens, you can reconstruct what was accessed and by whom.

Run a five-minute insider scenario at your next leadership meeting. Not a tabletop, just a thought exercise. If a long-tenured employee resigned this morning, what would happen to their access by close of business. Walk through it out loud. Note what does not have an answer. Assign someone to fix the gaps before the next meeting.

None of this requires a security product. None of it requires a consultant. All of it requires that someone in the organization decide insider risk is real and worth ninety minutes of leadership attention.

The human layer outpaces the technical one

Robert Lipka walked classified material out of the National Security Agency for years without anyone noticing. He was not an exotic threat. He was a person with a badge, an unsupervised job, and the patience to take a small risk repeatedly. The agencies hunting him had every technical advantage of their era. The technical advantage was not the bottleneck.

It still is not the bottleneck. The next breach in your industry is more likely to walk in with a name badge than with a phishing email. The training your team needs is not the kind that fits on a phishing simulation dashboard. It is the kind that names the four questions in the previous section and answers them every quarter, in writing, by people whose job depends on getting the answers right.

The technical layer is necessary. It is not sufficient. The human layer is where the real money is at risk, and it is the layer almost no SMB security program is actually working on.

Spend ninety minutes on it next week. You will find at least one thing that surprises you, and that one thing was already in the building.

About the author
Pete Hish, Sentinel Vault founder
Taught by Pete Hish · Founder

A working cyber-fraud supervisor, not a vendor consultant.

US Army veteran. Active sergeant supervising a cyber and fraud investigations team at a large Southern California law-enforcement agency. Ten-plus years inside the cases that hit small businesses, families, and public-sector agencies first. The training is shaped by what actually goes wrong, not what vendor decks predict.

Certified Cybersecurity SpecialistCertified Cyber Fraud SpecialistCalifornia POST Certified Instructor
Hacked or Hardened? book cover
Prefer the long-form version?

Hacked or Hardened? covers these patterns end-to-end: the four ways small businesses get hit, what to fix first, and how to lead through an incident.

Keep pulling the thread
The fiction version

Fleeced Nation is a crime series about industrialized fraud, from the elder-fraud call centers to the quiet machinery that turns dirty cash clean. Same terrain as the case files, minus the parts a report will not hold. I started it as fiction. The case files keep publishing the sequel.

fleecednation.com ↗
Related field notes
Next step

Want this kind of analysis for your team?

A 2–4 hour cyber risk briefing: the threats specific to your business, the controls that actually pull their weight, and a 90-day action plan.