New Blog
The Cost of Convenience: Why Account Separation Matters for Cyber Security
Using one account for everything might be convenient, but it can also create unnecessary cyber security risk.
In this blog, we explore why account separation and the Principle of Least Privilege matter, how they can help limit the impact of a breach, and where Cyber Essentials fits into building stronger security foundations.


The Cost of a Single Account
There is no denying the convenience of a single account.
You have all the freedom you need to manage your account, files, software installations and much more, all while being able to check your emails, browse the web, and whatever you need to tick through the menial tasks of the day.
What’s more, the IT Helpdesk don’t have to deal with constant administrative requests from users, because they have them already! Everyone has all the autonomy they need. What’s not to like?
As it turns out, all this convenience can come at a significant risk and cost.
When a system has limitless freedom to view, execute and change anything, then so will anyone who uses it. That means anyone.
Most major breaches don’t involve an elite hacker, they involve a compromised entity, and if such a system were to be compromised, there’s no telling where a threat actor would stop. The most obvious cost will often be financial, especially with a Ransomware attack. However, an attack could also cost the organisation their ability to operate, their highly sensitive data, their reputation, and potentially expose them to legal ramifications, all of which will amount to further financial loss. In some instances, businesses cannot recover from the effects of an attack.
Unfortunately, there is no such thing as ‘complete security’. Even with the world’s best security tools and practices in place, a security breach of some degree occurring at some point is not only possible; it’s highly likely. When this occurs, the priority of any organisation should be to ensure the damage, or ‘blast radius’, is as limited and confined as possible.
Think of it like designing a building with the aim of minimising a fire outbreak: The key is to compartmentalise the building into individual ‘cells’, so that if a fire does break out in one cell, it’s at least contained within it and can’t spread as quickly or as easily.
In Cyber Security, one of the easiest, simplest, most effective (and cost effective) ways to compartmentalise an organisation is through Account Separation.
Account Separation
Account Separation is the simple practice of using separate accounts for different roles or risk levels. While administrative privileges are often necessary to perform critical actions, it is vital that these actions are only performed using dedicated admin accounts, rather than ‘standard accounts’ used for everyday tasks.
Standard Accounts - Most medium, large, and enterprise-sized companies will be primarily made up of ‘standard’ users, who do not require admin-level privileges for their day-to-day work. Therefore, these accounts should not have any admin privileges.
Admin Accounts – There are certain tasks that will absolutely require admin-level privileges to be performed. Examples could include software and System Configuration settings, such as installation rights, Network and Security settings, such as control of firewall rules, and Data Access rights, which could include access to certain restricted files. These are just some examples of privileges which should only be provided to dedicated admin accounts. Naturally, admin accounts also shouldn’t be used for standard day-to-day tasks, such as web browsing, email or internet downloads.
Principle of Least Privilege
The Principle of Least Privilege is a foundational security concept that can be summarised as the practice of ensuring users and their accounts are only given the absolute minimum level of access needed to do their job, and nothing more. When accounts are configured for users in different roles within an organisation, there should always be technical controls in place to restrict what they’re able to access. When committing to put Principle of Least Privilege into practice, Account Separation is one of the most effective actions an organisation could take, as it ensures only the accounts specifically dedicated for carrying out critical system changes and other elevated operations are able to do so.
Preventing Lateral Movement
For malicious actors trying to access a system, Lateral Movement is one of most critical phases of most attacks. It’s the act of gaining access to one target, which could be ‘low-value’ like an employee’s laptop and then moving laterally towards higher-value targets on the network, such as systems used for critical security functions, or for managing sensitive data.
With Account Separation, the attackers are significantly restricted to that system, making it much harder for them to find a path to progress further into the network.
Here is a common scenario: Once attackers have gained access to one lower-level system, which could be through a simple Phishing attack, they will often search for admin credentials on that system. These credentials are stored as ‘tokens’ which sit the system memory and once attackers find them, they can then use them to authenticate and ‘jump’ to the next system.
However, if the account they have compromised has only standard privileges and the separate admin account has been signed out of all sessions, they will not be able to find these credentials as the admin session-tokens within the system memory have been invalidated.
Ultimately, the standard account is restricted in its abilities by design. Even with the correct admin credentials, the account itself has been determined to never have the necessary authorisation to access a higher-level system without further authentication.
Account Separation vs. Privilege Elevation
When a task requires admin-level privileges, it is imperative to recognise the distinction between logging into a separate admin account, and ‘elevating’ the standard account to give it admin-level privileges.
Many larger organisations will have dedicated admin users, such as an IT Administrator, and only they can carry out admin tasks on company systems. If staff are able to request admin level privileges, it is often simpler to temporarily provide their standard account with admin level privileges, rather than provide them with credentials to log into their separate admin account.
This can carry significant risks, however, and should always be avoided.
If an attacker has already acquired the login password, for instance via phishing or a keylogger, then they simply need to wait for a moment when the account is elevated, and strike at the opportunity.
Ultimately, a separate, dedicated account is the only way to truly ensure a barrier sits between the compromised endpoint and the rest of the network.
Conclusion
At its core, the move toward Account Separation acknowledges a simple truth in cyber security: Convenience is the greatest ally of an attacker. When users within an organisation have an ‘all-in-one’ account, they aren't just making their own lives easier, they are clearing a path for anyone who managed to steal their digital identity.
By implementing account separation and adhering to the Principle of Least Privilege, an organisation transforms its network from a wide-open floor plan into a series of fortified vaults. It ensures that a single compromised laptop remains a contained incident rather than a business catastrophe that appears in headlines.
The Path Forward
Adopting this strategy doesn't require the world's most expensive tools or a huge amount of technical expertise. It requires a shift in mindset:
Acknowledge that administrative capability is a tool to be used, not a status to be held.
Enforce technical boundaries that keep day-to-day work and critical operations in separate worlds.
Educate users on why that extra login or the ‘switch user’ step is the most effective shield they have.
In an era where ‘complete security’ is impossible, compartmentalisation is the best defence. Account Separation provides the necessary segregation to ensure that when an initial breach occurs, your organisation has the structure in place to protect itself and its data.
The cost of a second account is a few extra seconds. The cost of a single account could be everything else.
Certifications
For organisations looking to proactively safeguard against cyber threats, pursuing a security certification is a highly effective approach for improving security posture, while also reinforcing credibility and trust in the eyes of suppliers, regulators and the public.
Account separation is just one part of building a stronger security posture. Cyber Essentials provides a practical framework for putting key controls in place, including user access management, helping organisations reduce risk and strengthen their overall resilience.
If you’re looking to improve your cyber security foundations, explore how WorkNest Secure can support you with Cyber Essentials certification.
Share your challenge with us and we’ll help you find the right level of support for your business.












