“The review mapped every standing admin account on our core banking hosts and gave us a clear attestation pack for the external auditors. The kickoff took longer than we hoped because our asset list was incomplete, but the findings were precise enough that control owners could act without a second round of clarification.”
Client stories
Evidence from completed reviews
Comments from control owners, risk leads, and infrastructure managers who worked through privileged access attestation with our facilitators.
“We had break-glass accounts that nobody could explain. Siteridgepoint walked each owner through the evidence, not a generic checklist, and left us with a reduction plan tied to our change windows.”
“Patient-system access certification used to mean weeks of spreadsheet chasing. Their facilitators kept reviewers focused on entitlements that actually matter, and the sign-off trail held up in our internal audit.”
“They designed a quarterly review cadence that fits our staffing reality in Nelson Mandela Bay—not a programme copied from a larger metro. Six months later we are still running the same rhythm without outside consultants for each cycle.”
Extended engagement notes
Quarterly attestation for a payment switch
A payments operator needed evidence that privileged access to its switch environment was reviewed before year-end. Over three weeks Siteridgepoint reconciled directory groups to host roles, interviewed eight control owners, and produced an attestation pack with residual risks ranked by system criticality.
Outcome: External auditors accepted the pack without follow-up questions on privileged access.
Emergency admin clean-up after a contractor exit
When a long-term contractor left a manufacturing firm, residual domain-admin rights remained on shop-floor servers. A focused privileged access review identified orphaned accounts, shared credentials, and undocumented remote paths within ten working days.
Outcome: All orphaned privileged accounts were revoked before the next maintenance window.