More than 50% of major cyber incidents since 2021 would have been prevented if organizations had followed one specific principle. The Principle of Need to Have Available describes surrendering permissions not required for the next set of premeditated tasks. We compare this with the Principle of Need to Know and show how more than half of recent major cyberattacks in 2023 could have their impact limited. This is not just a principle to protect against ransomware, but also helps in longer and more targeted campaigns as it required attackers to work harder to get your data. Unfortunately, applying this principle requires a little bit more work than updating your information security policy and it might be that your organization has not yet reached a level of maturity where you are able to see a return on security investment from it. As an example of critique, given not all work within the organization can be broken into premeditated tasks, the principle cannot be applied to all roles and ranks without prior impact evaluations. Still to protect your organization, the Principle Need to Have Available provides an addition for your arsenal worthy of considering. There are no pre-requisites for this workshop.