None of what follows is exotic, and none of it is a criticism. These are what happens to any network that has been looked after by busy people for more than a few years. They are also, not by coincidence, the things attackers look for first.
1. An account for someone who left
Almost without exception. Usually still licensed, often still receiving mail, occasionally still signed in on a phone in somebody's kitchen drawer. We wrote a whole note on why offboarding gets missed.
2. More administrators than staff who need it
The owner, because they are the owner. The office manager, because it was easier that day. A supplier who needed it once in 2021. Every administrator is another set of keys to everything; most offices need two.
3. Multi-factor authentication, with exceptions
MFA is switched on, except for the three people who complained. Those three are, reliably, the most senior people in the organization and therefore the most valuable accounts in it.
4. A backup nobody has restored
See the Friday test. The green tick is not evidence.
5. Something forwarded through the firewall
A remote desktop port, a camera recorder, a printer. Opened for a good reason, by someone who meant to close it afterwards.
6. One machine running something unsupported
It drives the plotter, or the door system, or the one piece of software the supplier stopped updating. It cannot be replaced this year. It can be fenced off from everything else in an afternoon.
7. Nobody knows who owns the domain name
It was registered by a web designer in 2012 using an email address that no longer exists. This one is not a security finding so much as a business-continuity cliff edge, and it is the finding clients thank us for most.
If you recognized four or more, you are entirely normal. If you would like to find out for certain, that is what the audit is for.