IT & Cyber Audit
Shared & Generic Account Usage
Use of shared, generic and default logins that defeat individual accountability and audit trails.
Shared logins destroy the individual accountability the audit relies on
Shared, generic and default accounts break the link between an action and an individual, defeating the audit trail and making it impossible to attribute fraud, error or unauthorised change to a person. This directly undermines the access-control and accountability principles the AGSA tests and the King IV expectation of responsible technology use. AuditPro Core detects use of shared and generic credentials so that anonymous access is eliminated and every system action can be traced to a named individual.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Generic accounts active
146
▼ 22 vs prior review
Concurrent-login events
3 410
On financial systems
39
Default vendor logins
12
Generic accounts in use by month
Generic accounts on critical systems
| Account | System | Logins (30d) | Distinct IPs |
|---|---|---|---|
| admin | Revenue system | 412 | 9 |
| finance01 | BAS | 287 | 6 |
| scmuser | SCM portal | 198 | 4 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Accountability requires unique identity
Audit trails are only meaningful when each login maps to one person. A shared account means any action could have been taken by several people, so culpability can never be established.
Default and built-in accounts
Vendor default accounts such as generic administrator or database superuser logins are widely known and rarely attributable. Their continued use is both an accountability gap and a security exposure.
Concurrent and improbable use
A genuine sign that an account is shared is concurrent sessions from different locations or logins that no single person could plausibly perform. These patterns expose shared use even where it is denied.
Operational excuses are not exemptions
Shift handovers and operational convenience are often cited to justify shared logins, but supported alternatives such as individual accounts with role assignment remove the need without losing functionality.
How AuditPro Core Bridges the Gap
- Detection: shared, generic and default account usage is identified across monitored systems.
- Anomaly analysis: concurrent and improbable session patterns flag accounts that are shared in practice.
- Exception workflow: identified shared accounts are routed for conversion to individual identities or decommissioning.
- Traceability to source: findings link to the login events so the evidence supports remediation and audit.
Key Takeaways
- Shared accounts break the action-to-person link the audit trail depends on.
- Disable or rename vendor default and built-in generic accounts.
- Concurrent or improbable sessions expose shared use even when denied.
- Replace operational shared logins with individual accounts and role assignment.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
