The account that never died and the two kinds of IT problems
Why the riskiest things cost nothing to fix — and the seven questions every CEO should ask this week.
Nick Dreyfus started the recording with a detail that ended a meeting in a phone call: a CFO had left, attended his goodbye party, and yet his corporate login — the same username and password that appeared in a public credential dump — still had access to the company bank account.
That single, quiet fact separates two very different problems leaders mix up all the time: the things you can fix for free if someone simply does the work, and the systemic gaps that need budget and planning. Treat them the same and you will make the wrong decision every time.
The free problem you must own
The account that stayed active was not a budget problem. Disabling it was a five-minute task that never happened because it sat on a long list of non-urgent tickets. Nick’s point: that is a management failure, not a technical one. If you find something like this, it is a Monday conversation — who owns offboarding, who verifies completion, and who signs off to prove it was done.
A concrete control that would have prevented the bank access: a written offboarding checklist that logs every place a departing employee had credentials, including bank portals, payroll, credit processors and state licensing portals — and a manager’s signature confirming each item was actually completed.
“If you have never heard bad news from your IT team, that is not an all clear.” — Nick Dreyfus
The expensive problem that keeps you awake
The second kind of problem is slow corrosion: untested backups, decade-old servers, free consumer security on systems that need enterprise protection. Those are not things an overworked IT person can fix without budget. When leadership confuses them with tickets, two things happen: you punish the messenger when they finally bring bad news, or you waste money buying a band-aid for what needed investment.
Nick tells a hard story: a company declined a proposal to replace old infrastructure, were attacked three months later, and spent months rebuilding by hand. They lost three of their largest customers — roughly a quarter of revenue — and now ownership is deciding whether to continue the business. The ransom itself was zero; the real bill was downtime, customer churn and the rebuild.
Why IT often doesn’t tell you the truth
There are two blunt forces that keep problems hidden:
The message sounds like a raise request. Telling the CEO “we need more money” can be heard as failure in the role you already pay for.
Shame. When every unpatched server or stale account reads like a report card on the person responsible, that report often never leaves the desk.
That silence does not erase risk. It causes teams to improvise — free tiers, consumer licenses, delayed patching — decisions that make immediate sense but accumulate into catastrophic exposure.
Seven questions every CEO and CFO should ask this week
Sit down with whoever runs your technology and make it safe for them to be honest. Then ask these seven questions and sort answers into two buckets: free-to-fix or requires-budget.
When did we do a complete test restore of all our backups, how long did the restore take, and who watched it? (If no date, you have hope.)
If every server were encrypted tonight, how many days until we’re operating again, and who decided that is acceptable?
What operating systems are we running and which hit end-of-life this year?
How many devices do we own, how many are protected, and what is the gap?
How many machines are missing patches right now, and what is the oldest unpatched item?
Walk me through exactly what happens when someone leaves the company — who tells IT, how fast, and who confirms every login was removed (including external services)?
What did you recommend that we declined and when? (If the answer is “nothing,” they either never recommended anything or stopped bothering.)
If you do one thing after reading this: ask question six. Nick calls that the free fix that catches bank access and other silent exposures.
A final, practical calibration
Replace vague fear with two simple routines: make it safe for the person who knows to tell you the truth, and then ask targeted questions that reveal whether the issue is human work or budget. The right protocol separates a five-minute offboarding task from a multiweek recovery problem — and lets you act correctly.
Nick’s last ask is direct: sit down with your tech lead, promise nothing they tell you will be held against them, and run the questions above. If they answer well, you buy peace of mind for the price of one meeting. If they can’t, you found something worth knowing today instead of three months from now when it’s expensive.
If you want the full list Nick read and the sources he cited, it’s in the episode description with links and an offer for a second set of eyes. This is not a sales pitch. It’s a discipline: know which kind of problem you’re looking at before you decide how to fix it.