The forgotten integration that becomes the biggest risk in the stack
Written by Ray Stephens
Two years ago, someone connected a tool to solve a problem that no longer exists, the project finished and the team moved on. Nobody switched off the connection. It's still there, still linked to your core systems, still holding access nobody remembers granting.

That's not a rare oversight. It's how most technology stacks actually grow.
The myth technology leaders believe
Ask a founder or CTO where their biggest technology risk sits, and most will point to something visible. The main platform, the customer database, the system everyone talks about in board meetings.
That instinct is understandable, it's also wrong.
The biggest risks rarely live in the systems people watch closely. They live in the ones nobody's looked at for years. A payment connector built for a campaign that ended. An automation set up to solve a one off data problem. A service account created for a contractor who left the business eighteen months ago.
These connections were never malicious. They were never even careless at the time. They were reasonable decisions made to solve immediate problems. The risk isn't in how they were built. It's in what happened after, nothing.
Why forgotten connections are so dangerous
Every integration you add to your stack needs something to work. Usually that means access. Often privileged access, reaching into systems that hold customer data, financial information or operational controls.
When that integration is active and monitored, the access is a calculated cost of doing business.
When the original purpose disappears and the connection stays live, that same access becomes a door nobody's watching.
Attackers understand this better than most businesses do. A forgotten integration is rarely patched. It's rarely reviewed. It often sits outside whatever security monitoring the rest of the stack benefits from. For someone looking for a way into your systems, that's a far easier target than the platform your team checks every day.
The damage isn't limited to the integration itself. Because these connections often touch core infrastructure, a breach there can expose far more than the tool ever needed access to in the first place.
How the risk accumulates
No single forgotten integration is likely to sink a business. The danger is cumulative.
Add one connection to solve a problem. Add another for a new platform. Add a third to support a project that runs for six months and then quietly stops. Multiply that across a few years of growth, and most organisations end up with a web of APIs, service accounts and automations that nobody has fully mapped.
Ask who owns each one. Ask what data it can reach. Ask whether it's still needed.
If those questions don't have clear answers, you've already found a gap in your governance, whether or not anything has gone wrong yet.
Treating integrations as assets, not artefacts
The businesses that manage this well don't have fewer integrations than everyone else. They have better ownership of the ones they keep.
That starts with documentation. Every connection should have a named owner, a stated business purpose and a scheduled review date. If a tool can't justify its access on those three points, it shouldn't have that access.
It continues with regular audits. Not a one off clean-up exercise, but a standing practice of reviewing what's connected, why and whether it still earns its place in the stack.
It also means treating access reviews as routine business, the same way you'd review supplier contracts or staff permissions. When someone leaves a project, their integrations should leave with them.
None of this requires exotic tooling or a large security budget. It requires someone taking responsibility for asking the questions on a schedule, rather than waiting for an incident to force the conversation.
The safest technology stacks aren't the ones with the fewest connections. They're the ones where every connection has an owner who can explain why it's still there.
Let's wrap this up
The biggest threat in your technology stack probably isn't the system your team discusses in meetings. It's the one nobody's mentioned in two years.
Every integration should have a documented owner, a clear purpose and a review date. Legacy connections often carry privileged access to core systems, which makes them attractive targets precisely because nobody's watching them. Regular audits reduce that risk while also improving data quality and simplifying the stack you're trying to scale.
Take an hour this week and list every integration currently connected to your core systems. For each one, ask who owns it, what it does, what data it touches and whether it's still needed.
If you can't answer those questions, you've found where your next risk is hiding.