← All terms

Privilege Creep

Privilege creep is the gradual buildup of access rights as people change roles and projects without ever losing old permissions — widening breach blast radius.

Privilege creep (also called access creep or permission sprawl) is the gradual accumulation of access rights over a person's time in an organization. Every project, role change, temporary cover and urgent exception adds permissions; almost nothing ever removes them. After a few years, an employee's effective access reflects their entire history rather than their current job — and nobody can say precisely what they can reach.

How it becomes a security problem

Privilege creep silently converts small compromises into large ones. When an attacker phishes an employee, they inherit that employee's permissions in full — the current ones and the forgotten ones. An account that should open three systems but opens thirty gives the intruder lateral movement without ever needing to escalate, defeating the containment that the principle of least privilege is meant to provide. The same surplus raises insider risk: more reachable data means more damage from a malicious insider and more scope for accidental mishandling by a careless one. Creep also compounds at departure — the longer the accumulated entitlement list, the more likely the leaver process misses something, feeding the orphaned-account problem documented in our guide to departing-employee risk. Auditors notice too: access that cannot be justified against a current role is a standard finding under ISO 27001, SOC 2 and similar frameworks.

How to defend against it

Make access expire by default. Grant permissions with an end date or a review date, prefer just-in-time elevation over standing rights — the discipline privileged access management tooling enforces for administrative accounts — and treat every role change as a re-provisioning event that removes the old role's access rather than stacking the new on top. Run scheduled user access reviews in which managers actively confirm each entitlement, with unconfirmed access revoked rather than rolled over. And measure it: access exposure is one of the inputs a human risk score weighs, because the person with the widest reach and the weakest security habits is exactly where training and controls should concentrate first.

Related terms

Principle of Least PrivilegeLeast privilege means every user, process and system gets only the access it needs, for only as long as it needs it — limiting what a compromised account can do.Privileged Access Management (PAM)Privileged access management (PAM) secures and monitors the powerful accounts — admins, service accounts, root — that attackers and insiders prize most.User Access ReviewA user access review is a periodic audit confirming that every account and permission maps to a current person and a current need — and revoking the rest.Insider ThreatAn insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo