Analysis

Access Management Is the Backbone of Security

5 October 2026 · Author: Lisbeth Loft

The case of unauthorised access to the Danish Central Person Register (CPR) shows how decisive access management is – not only for keeping unauthorised people out, but also for governing legitimate access securely.

On 5 October 2026, it was announced that the Danish Central Person Register (CPR) in Denmark had identified a serious security incident.

Unauthorised parties had gained access to information on around 8.8 million registered persons, including names, addresses and CPR numbers, via a private Danish company’s legitimate access to the Danish CPR system (DR).

The CPR administration terminated the company’s access, reported the incident to the Danish Data Protection Agency, and the case is being investigated by the police.

The precise course of events is still being investigated, and we should therefore be cautious about drawing conclusions about the specific cause.

But the case illustrates an important point:

An access that has been legitimately established can still pose a serious risk if it is misused.

Access Is More Than Login

Access management is not only about usernames, passwords and multi-factor authentication.

It is also about who has access to what, why the access is needed, how extensive it is, how long it should exist, and how it is actually used.

That is why access management is an ongoing governance task rather than a purely technical configuration.

ISO/IEC 27001 and ISO/IEC 27002 treat access control as a central part of information security, and the NIS2 rules impose corresponding requirements on governing access to network and information systems (ISO/IEC 27001 and NIS2).

Legitimate Access Is Not the Same as Unlimited Trust

The CPR case is interesting because the unauthorised activity took place through an existing legitimate access.

It shows why security cannot stop at the question:

Is the user allowed to be here?

We must also ask:

Is the access being used in a way that is consistent with the agreed purpose?

A legitimate access can be misused if an account is compromised, if rights are too broad, or if unusual activity goes undetected.

Access must therefore not only be granted. It must be reviewed regularly, limited, monitored and capable of being revoked quickly.

Logging Is Part of Access Management

It is not enough to know who can access a system. We should also be able to see how that access is actually used.

Logging only delivers real value when it is used to detect deviations.

Very large volumes of lookups, activity at unusual times, or use that deviates markedly from the normal pattern should be able to trigger follow-up.

Access management and logging are therefore two sides of the same coin: who may do what – and can we see when something does not look right?

Least Privilege

A fundamental security principle is that users and systems should only hold the rights they actually need.

That sounds simple, but access tends to grow over time. Employees change roles, suppliers take on new tasks, integrations are extended, and temporary accesses become permanent.

Rights should therefore be reviewed on an ongoing basis. Supplier accesses, privileged accounts and access to large volumes of data deserve particular attention.

Before, During and After a Security Incident

Strong access management is about preventing, detecting and responding.

Before an incident, the organisation should know who has access to what, limit rights according to need, use strong authentication, follow up on privileged and external accesses, and ensure logging that can actually be used for monitoring.

When an incident is detected, the first task is to limit the damage. The compromised access should be stopped or restricted, relevant logs and traces must be preserved, and the organisation should quickly establish an overview of which systems and information may be affected.

The organisation’s incident response process should be activated, and relevant internal and external parties must be involved.

If the incident involves a breach of personal data security, the controller must, as a starting point under the GDPR, notify the breach to the Danish Data Protection Agency without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk to the rights and freedoms of the individuals concerned. Where the risk is likely to be high, the affected individuals may also have to be informed (Danish Data Protection Agency on data breaches).

Other regulatory frameworks may impose additional reporting and handling requirements. For organisations in scope of NIS2, for example, there may be separate requirements for reporting significant security incidents.

After the incident, the organisation should not simply reopen the access. It should examine why the incident could happen, whether rights were too broad, whether monitoring responded quickly enough, and which technical or organisational changes need to be implemented.

The incident should also be used to update the risk assessment and improve the controls.

Access Management Is the Foundation

Access management is not a single product or a single system.

It is the interplay between identity, rights, authentication, logging, monitoring, incident response and ongoing follow-up.

If that foundation is weak, many other security measures may be correctly implemented and still have limited value.

That is why access management in practice is part of the backbone of security.

Contact

Let’s talk

Tell us about your situation, and we will find out how we can best help.