← All terms

Principle of Least Privilege

Least privilege means every user, process and system gets only the access it needs, for only as long as it needs it — limiting what a compromised account can do.

The principle of least privilege (PoLP) holds that every user, service account, process and device should be granted only the permissions required to do its job, and only for as long as they are required. An accounts-payable clerk does not need domain-admin rights; a marketing intern does not need read access to the HR file share; a script that rotates log files does not need to write to the production database. The principle is a foundation of zero trust architecture and appears throughout NIST guidance, including SP 800-53, where it is a named access-control requirement.

Why it matters for human risk

Least privilege is the control that decides how bad a successful social-engineering attack gets. Most breaches still begin with a person — the Verizon DBIR 2026 attributes 62% of breaches to the human element — and an attacker who phishes one employee inherits exactly that employee's permissions. If those permissions are broad, a single account takeover becomes lateral movement, data theft or ransomware; if they are narrow, the attacker is boxed in and has to work harder and louder to escalate, which is when detection tends to catch up. The same logic limits the damage an insider threat can do, whether malicious or simply careless. Privilege also shapes who gets targeted: help-desk staff, finance approvers and administrators attract disproportionate attention from help desk fraud and business email compromise precisely because their access is worth more.

How to apply it

Start with an inventory of who can do what — most organizations discover standing admin rights, orphaned accounts and shadow IT tools nobody approved. Remove standing privilege in favor of just-in-time elevation that is requested, approved and time-limited — the discipline privileged access management tooling operationalizes for administrative and service accounts. Separate everyday accounts from administrative ones, review access on a schedule and at every role change, and enforce dual approval for high-consequence actions such as payments above a threshold or beneficiary changes. Then connect privilege to the human-risk picture: a human risk score that weights an employee's access exposure alongside their phishing simulation results tells you where a narrow privilege and a resilient person matter most — and where, as our guide to incident response for social-engineering attacks shows, over-broad access turns a single click into an organization-wide incident.

Related terms

Zero TrustZero trust is a security model that grants no implicit trust based on network location or identity claims — every access request is verified. Where the human layer fits.Insider ThreatAn insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.Account Takeover (ATO)Account takeover is an attack in which a criminal gains control of a legitimate user account and operates it for fraud, theft, or further attacks.Shadow ITShadow IT is technology used without IT approval — unsanctioned apps, accounts, and AI tools that expand attack surface outside security's visibility.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo