---
title: "Identity protection and secure access | Avepto"
canonical_url: "https://avepto.ch/en/cybersecurity/identity"
last_updated: "2026-09-13T20:46:37.063Z"
meta:
  description: "Multi-factor authentication (MFA), single sign-on (SSO) and zero-trust controls secure access. Regular access reviews included."
  "og:description": "Multi-factor authentication (MFA), single sign-on (SSO) and zero-trust controls secure access. Regular access reviews included."
  "og:title": "Identity protection and secure access"
  "twitter:description": "Multi-factor authentication (MFA), single sign-on (SSO) and zero-trust controls secure access. Regular access reviews included."
  "twitter:title": "Identity protection and secure access"
---

# Your access, under control, managed by Avepto.

A meeting to review your access management and internal processes. Avepto then hands you concrete recommendations, ranked by priority.

Book an access audit

The problem

## In most SMEs, the door is left ajar.

You don’t need to be targeted by a sophisticated hacker. Most incidents come from simple things, a forgotten account, a shared password, a right granted then never revoked. Here are the six situations we see most often.

### Former employees may still have access

Their account was never closed. They can still log into your email or your files, from home, from anywhere.

### Every account inventoried, closed on exit

Full access inventory. On every departure, a documented procedure revokes each account the same day.

### Several people share the same password

The « admin » account everyone uses. If one of them loses it, everything is exposed. And no one knows who did what.

### One account per person, no sharing

Each colleague has their own login. Actions are tracked. A departure no longer paralyses the team.

### A password alone is no longer enough

If it’s guessed, stolen or found online, anyone can walk in. Without a second check, nothing stops them.

### Two-factor authentication on by default

A stolen password is no longer enough to get in. Logging in requires a second confirmation, on the employee’s phone.

### The same passwords everywhere

Your team often reuses passwords between work and personal sites. A leak elsewhere exposes you here.

### Shared vault, unique passwords

A team-shared password manager. Each service gets a unique credential, generated and stored securely.

### Everyone sees everything

An intern with access to HR folders. A salesperson seeing the books. Rights granted « just in case » and never reviewed.

### Minimum rights, reviewed every year

Each colleague only sees what their role requires. Permissions are reviewed yearly and corrected when they drift.

### No onboarding or offboarding procedure

Every hire, you improvise. Every departure, something is forgotten. The list of what to do is still to be built.

### Onboarding and offboarding documented

One checklist per profile. On arrival, every access is in place. On departure, everything is revoked the same day.

What we do

## Ten concrete actions, in four phases.

Here is exactly what Avepto does, in order, to take back control of your access. Each action produces a written record that’s yours to keep.

We look

01

### Map it out

See everything that exists, with no blind spots.

#### Full inventory of every open account

Email, applications, remote access, shared files. Including the ones you had long forgotten.

#### Rights review on every account

Everyone keeps the rights their work needs. Those that no longer serve are removed, with your agreement.

We secure

02

### Lock down

Cut what’s useless, harden what remains.

#### Closure of the accounts left unused

Former employees, interns, departed contractors. Their access is closed cleanly, with a report.

#### A second check at every sign-in

Beyond the password, a confirmation on the phone. This blocks almost every intrusion attempt.

#### Connections limited by location

For example: accounting from the office, or only from Switzerland. You decide, we configure.

#### Separation of administrator accounts

Each person needing elevated rights gets one in their name. The shared admin account goes away.

We frame

03

### Keep watch

Spot the abnormal, frame the movements.

#### Watch over suspicious sign-ins

An unusual country, an odd hour, several failures in a row. We are alerted, and we tell you.

#### Framing of arrivals and departures

What to do at hire, at transfer, at departure. Everyone knows what to do, and when.

We hand over

04

### Document

Leave you a clear record and clear priorities.

#### Full documentation, in plain words

Who holds which access, which rules apply, which exceptions exist. One readable document, yours to keep.

#### A priority list for what comes next

Ordered from most to least urgent. With what each point changes for you, and how long it takes.

A scenario we see often

## A reused password opens more than one door.

The same password at home and at work, a leak on another site, a login attempt. What changes is what they run into.

What happens

Without access management

With Avepto

An employee uses the same password for their personal mailbox and their work mailbox.

Nothing stops them. One password holds both accounts.

Multi-factor authentication and the access policy mean a password on its own is not enough to open the work mailbox.

They create an account on an external service with their work address, reusing their usual password.

That reuse creates a dependency on a service you do not control.

Work access does not rest on that password alone: a second verification is still required.

The external service is compromised. The credentials appear in a known breach.

Without identity monitoring, this can go unnoticed.

Identity monitoring flags a work address appearing in a known breach. We pass on the alert and the actions to take.

Someone tries that password on the work mailbox.

If the password is enough on its own, the sign-in can succeed.

The attempt requires a second verification and may be blocked; the event is logged.

The attempts come from an unusual context, and they repeat.

They may blend into ordinary sign-ins.

Depending on the access policy, an unusual context may trigger a block or an additional verification. The event surfaces in monitoring.

Outcome

The compromise may only be discovered after it has been exploited.

A known breach triggers an alert and a remediation action. Even compromised, the password on its own is not enough to open the mailbox.

Frequently asked questions

## Your questions on identity protection.

If yours isn’t here, just ask during the audit.

### What does securing an SME’s identities with Avepto involve?

Scope and nature of the service

Avepto maps out who has access to what across your company: accounts, passwords, files and business applications. We then close access that should no longer exist, protect what matters, and hand you a clear, up-to-date view of your digital identities. You keep the decisions, we handle the setup and the ongoing follow-up.

### Why is a former employee’s account left open dangerous?

Risk of orphaned accounts

Because an orphaned account is a door no one is watching. Its password may be guessable or exposed in a data leak, and whoever finds it can reach your email and files in that person’s name. With no one monitoring the account, the intrusion can go on for months before anyone notices.

### What is multi-factor authentication (MFA) for an SME?

Multi-factor authentication explained

Multi-factor authentication (MFA) adds a second proof of identity to the password: a six-digit code or a notification to approve on the employee’s phone. That confirmation takes two seconds but blocks almost every intrusion attempt using a stolen password. It’s the single most effective security measure an SME can switch on.

### Does securing access complicate employees’ daily work?

Minimal impact on your team

No, and that’s our first concern. Multi-factor authentication (MFA) only triggers in risky situations: a new device, an unusual sign-in location. Day to day, your team barely notices a difference. The goal is more security, not more friction in their work.

### How long does securing an SME’s identities take?

Diagnostic, remediation and timeline

The audit comes first. The full identity diagnostic then takes five to ten days depending on the size of your company. The remediation phase usually runs two to six weeks, depending on what we find. Your business carries on as normal throughout.

Continue exploring

## Related services, and the reading that goes with them.

The services most often deployed alongside this one, and the field notes published by our specialists.

Related services

- [Antivirus & EDR Endpoint detection. Blocks and isolates.](https://avepto.ch/en/cybersecurity/antivirus)
- [Network security Firewall, segmentation, network protection.](https://avepto.ch/en/cybersecurity/networks)
- [Microsoft 365 Mail, SharePoint and collaboration. Tenant set up and maintained.](https://avepto.ch/en/productivity/microsoft-365)
- [Outsourced IT management Geneva service desk. Tickets tracked and documented.](https://avepto.ch/en/managed-it/it-support)

Next step

## Take stock of your access.

We meet to take stock of your access: who gets in, with which rights, under which processes. You leave with concrete recommendations. You choose what happens next, no commitment.