Analysis

Access Management Is the Backbone of Information Security

5 October 2026 · Author: Lisbeth Loft

The case of the millions of leaked Danish CPR records shows how decisive access management is – not only for keeping unauthorised people out, but for governing legitimate access securely.

On 5 October 2026, the CPR administration reported that unauthorised parties had gained access to information on around 8.8 million registered persons via a private company’s legitimate access to the CPR system (DR).

The incident is still being investigated, and we should therefore be cautious about drawing conclusions about the specific cause.

But the case illustrates an important point:

An access that has been legitimately established can still pose a serious risk if it is misused.

Access Is More Than Login

Access management is not only about usernames, passwords and multi-factor authentication.

It is also about who has access to what, why the access is needed, how extensive it is, and how it is actually used.

That is precisely why access management is an ongoing governance task rather than a purely technical configuration.

Legitimate Access Is Not the Same as Unlimited Trust

The CPR case is interesting because the unauthorised activity took place through an existing legitimate access.

It shows why security cannot stop at the question:

Is the user allowed to be here?

We must also ask:

Is the access being used in a way that matches its purpose?

A legitimate access can be misused if an account is compromised, if rights are too broad, or if abnormal activity goes undetected.

Access must therefore not only be granted. It must also be limited, monitored and revocable.

Logging Is Part of Access Management

It is not enough to know who can access a system. We should also be able to see how that access is actually used.

Logging only delivers real value when it is used to detect deviations.

Very large volumes of lookups, activity at unusual times, or use that deviates markedly from the normal pattern should be able to trigger follow-up.

Access management and logging should therefore be seen as two sides of the same problem: who may do what – and can we see when something does not look right?

Least Privilege Remains a Strong Principle

A fundamental security principle is that users and systems should only have access to what they actually need.

That sounds simple, but rights tend to grow over time. Employees change roles, suppliers take on new tasks, and temporary accesses become permanent.

If rights are not reviewed, the impact of a compromise also becomes larger.

The CPR Case Is Also About Identity

When CPR numbers, names and addresses are compromised on such a scale, it also becomes clearer that such information should not stand alone as proof of identity.

Following the incident, authorities and industry bodies have encouraged companies and organisations to review their identity verification and supplement it where it currently relies on information such as CPR number, name or address.

This underlines how closely identity and access are connected.

Weak identity verification also means weak access management.

Access Management Is the Foundation

Access management is not a single product or a single system.

It is the interplay between identity, rights, authentication, logging, monitoring and ongoing follow-up.

If that foundation is weak, many other security measures may be correctly implemented and still have limited value.

That is why access management in practice is part of the backbone of information security.