Small business cyber safety
Shared Logins Feel Convenient—Until Someone Leaves
One password for the whole team seems simple. The hidden cost appears when access changes, an account is misused or nobody can tell who did what.
Start with one practical action: list every business login known by more than one person. Include email, banking, accounting, social media, website administration, supplier portals, cloud storage, booking systems and the password for any shared counter device.
You do not need to fix the whole list today. Mark the accounts that can move money, reset other accounts, expose customer information or change who has administrator access. Those are the first shared logins to replace.
Why one shared password creates several problems
A shared login hides individual responsibility. If three people use the same username, the service may show that “the account” changed a payee, downloaded a customer list or deleted a file—but not which person did it.
The Office of the Australian Information Commissioner gives the same risk practical weight in its security guidance: a shared store login can leave a business with no way to track or audit who accessed personal information. This is not only untidy account management; where customer information is involved, it can weaken a business’s ability to understand and respond to an incident.
- You cannot remove one person cleanly. The password must be changed for everyone, across every device where it may be saved.
- The password spreads. It ends up in messages, notebooks, browser storage or spreadsheets because the team needs an easy way to pass it around.
- Multi-factor authentication becomes awkward. Approval prompts or recovery codes may depend on one person’s phone.
- Access outlives the job. Former staff, contractors, bookkeepers and IT providers may retain a credential long after they need it.
- A compromise has a wider effect. One stolen shared password can expose every function available to that account.
Individual accounts do not mean everyone gets more access
The safer pattern is a named account for each person, with only the permissions their work requires. Security professionals call this least privilege. For a small business, it means access should match the job.
The Australian Cyber Security Centre recommends restricting privileged access to people with a demonstrated business need. It also notes that fewer privileged accounts mean fewer opportunities for criminals to obtain powerful credentials.
- The person raising invoices may not need permission to change bank details.
- A social-media contributor may not need ownership of the business page.
- A bookkeeper may need accounting access without access to email administration.
- An owner may use a normal account every day and a separate administrator account only for deliberate changes.
Individual accounts improve both security and ordinary management: permissions can change without interrupting everyone else, and activity records are more useful when something needs checking.
Use team features instead of passing around the password
Many services provide roles, delegated access or team membership. These options may cost more than a single-user plan, but they let the business remove one person without resetting everybody and may provide a clearer record of activity.
Look for:
- named users with separate sign-ins;
- owner, administrator, editor, billing or read-only roles;
- the ability to require multi-factor authentication;
- activity or audit records;
- central recovery contacts controlled by the business; and
- a clear process for suspending or deleting a user.
Do not automatically make every named user an administrator. A separate login is useful only when its permissions are also proportionate.
Shared vault is not the same as shared account
A reputable business password manager can share access to a credential without putting the password in chat, email or a spreadsheet. That is safer than informal sharing, but it does not turn a shared service account into an individual one.
Use a shared vault when the service genuinely provides only one business credential or while you are moving to a better arrangement. Protect the vault with strong authentication, limit membership and review who can reveal, edit or export credentials.
Where the service supports named users, prefer them. The password manager can then store each person’s unique strong password or passkey and can hold recovery information under business control.
A same-day offboarding checklist
Access should end when the work ends—not weeks later when someone remembers an old portal.
- Disable the person’s named accounts. Do this for email, cloud services, accounting, banking, website, social media, supplier and booking systems.
- Remove roles and delegated access. Check teams, groups, shared mailboxes, page roles and third-party applications.
- Change every shared credential they knew. Start with email recovery, banking, password manager, domain registrar and administrator accounts.
- Revoke active sessions and remembered devices. A password change may not automatically end every existing session.
- Recover business devices and information. Include phones, laptops, keys, security tokens, backup codes and locally stored files.
- Check recovery details. Remove personal phone numbers and email addresses belonging to the departing person.
- Transfer ownership. Make sure scheduled jobs, shared documents, online listings and subscriptions have an accountable current owner.
- Record completion. Keep a short access list so the next departure is a routine task rather than an investigation.
Plan for leave and emergencies as well as departures
A business should not lose access because the only administrator is ill, travelling or has lost a phone. At the same time, the answer is not to give everybody permanent administrator rights.
- Keep at least one controlled recovery route that belongs to the business.
- Nominate a backup administrator where the platform and business size make that sensible.
- Store recovery codes securely and separately from the device used for sign-in.
- Document which provider or trusted person can help without recording secret values in the procedure.
- Test the recovery route before an emergency.
If you cannot remove shared logins immediately
Some tills, legacy systems and supplier portals may not support proper team access. Reduce the risk while you investigate alternatives:
- keep the credential in a protected business password manager rather than messages or paper;
- limit who can access the shared vault entry;
- turn on multi-factor authentication where practical and keep recovery under business control;
- change the password whenever somebody with access leaves;
- do not reuse that password anywhere else;
- review the account’s activity and recovery settings regularly; and
- record the limitation so it does not become a forgotten permanent exception.
A ten-minute access review
Choose one high-consequence service and ask:
- Who can sign in today?
- Does each person have their own account?
- What can each account do?
- Who can add another user or change recovery details?
- Do any former staff or suppliers still have access?
- Could the business recover access if the main administrator were unavailable?
Fix the highest-risk answer, then repeat the review with another service next week. A small, maintained access list is more useful than a large policy nobody updates.
Sources and further reading
Frequently asked questions
Is a shared email address such as accounts@ always unsafe?
The address itself is not the problem. The safer arrangement is usually a shared mailbox or group that each authorised person opens through their own named account, rather than several people signing in with one password.
Do very small businesses really need separate administrator accounts?
Start with the highest-consequence services. Separating everyday and administrator access is especially valuable for email, cloud administration, the domain registrar and systems that can add users or change payment settings.