Security advice for small businesses often jumps straight to technical recommendations that assume a dedicated IT team. Most small businesses do not have one, and they do not need enterprise-grade tooling to close the gaps that cause most real incidents. A handful of consistent habits covers most of the risk. The hard part is not understanding the habits. It is installing them before something goes wrong, when nobody feels urgency.
A retail operator we advised still had a former weekend cashier logged into the POS admin app six months after she left — the invite had been sent to a personal Gmail nobody removed. Same-day offboarding would have taken four minutes. The access review that finally caught it took longer only because nobody owned the list.
Ignore vendor decks that imply you need a full identity platform on day one. Start with shared credentials, unique passwords, two-factor authentication, and a same-day offboarding habit. Those four moves prevent more damage than most expensive “security suites” sold to teams that still keep the Instagram password in a group chat.
Before and after: what “good enough” actually looks like
Before
A seven-person shop stores logins in a shared spreadsheet titled “Passwords — DO NOT SHARE.” The sheet lives in cloud storage that every contractor can open. The company Facebook page uses one password known by four people. Two-factor is on for the bank and nowhere else. A contractor who left in January still has access to the project board because nobody remembers inviting them. When someone asks who can log into the domain registrar, three people shrug.
After
Shared logins sit in a team password manager. People get access to vaults by role, not by forwarding a sheet. Social and billing accounts use unique generated passwords; most teammates never see the raw secret. Two-factor is on for email, banking, cloud storage, domain, and the password manager itself. Offboarding includes a one-page access list reviewed the same day a role ends. A quarterly fifteen-minute review catches leftovers the daily habit misses.
The after state is not perfect security. It is boring, maintainable control — which is what small teams can actually sustain.
Stop sharing passwords in chat or spreadsheets
The single most common access management gap in small businesses is a shared document or chat thread containing passwords for shared accounts — email, social media, billing tools. That document spreads further than intended, stays outdated as passwords change, and offers no way to know who has actually seen it.
A team password manager solves this directly: it lets people use shared accounts without emailing the secret around, and access can be revoked when someone leaves. You do not need the most expensive plan. You need one vault for company credentials, clear folders by system, and a rule that new shared logins go into the manager first — not into chat “temporarily.” Temporary almost always becomes permanent.
Expect pushback the first week. Autofill feels awkward until it does not. Budget an hour to migrate the ten accounts that actually matter: email, domain, hosting, banking, accounting, primary CRM or project tool, social profiles, ad accounts, and any storefront admin. Migrate the long tail later. Waiting for a perfect inventory is how the spreadsheet survives another year.
Unique passwords beat clever variations
A common but risky habit is using the same password with small variations across accounts. If one service is compromised, attackers routinely try the same password, with tweaks, against other services. Every account tied to business operations should have a genuinely unique password. That is realistic only with a password manager, not by memory.
Length matters more than theatrical complexity rules. A long random password from a manager beats “Summer2026!” on every marketing site. Save mental energy for phrases you must memorize — typically the password manager master password — and let the tool handle the rest.
If someone insists they can remember variations, ask them to list every business login from memory. The awkward silence usually ends the debate. Habit change sticks when the tool is installed on phones and laptops, not when it lives as a bookmark nobody opens.
Turn on two-factor authentication where it counts
Two-factor authentication remains one of the highest-value, lowest-effort security steps available. Make a deliberate pass through every business-critical account — email, banking, cloud storage, domain registrar, password manager — and confirm it is enabled. It is easy to skip during setup and easy to forget afterward.
Prefer an authenticator app or hardware key over SMS when the service offers a choice. SMS is better than nothing and worse than app-based codes, especially for accounts that control everything else. Store backup codes in the password manager, not in a desk drawer photo. If only one person holds the second factor for a shared inbox, you have created a single point of failure disguised as security. Share recovery access intentionally among two trusted people.
Do the two-factor pass as a calendar event, not a vague intention. Block ninety minutes, share a checklist of systems, and check them off together. Unfinished “we'll get to it” security work is how gaps survive for years.
Remove access the same day someone leaves
Former employees and contractors retaining access is one of the most common and most avoidable gaps in small businesses. The fix is a simple offboarding habit: the same day someone's role ends, walk through every shared account and tool they touched and revoke it. Do not park it as “cleanup for later.” Later is how January contractors still have March access.
Contractors are the usual blind spot because they were never in payroll systems and were invited ad hoc. Keep a living list of external people and which tools they use. When a project ends, revoke on that day even if you might hire them again. Re-inviting is cheap. Forgotten access is not.
Pair offboarding with password rotation for any shared account that person could have seen in plaintext historically — including anything that once lived in the spreadsheet you retired. Revoking a password-manager share is not enough if they still know an old social media password from 2022.
Access management checklist
- Move shared account credentials out of chat and documents into a team password manager.
- Confirm unique passwords on all business-critical accounts — start with email, domain, banking, and cloud admin.
- Enable two-factor authentication on every account that offers it, prioritizing email and the password manager.
- Store two-factor backup codes in the password manager; name two people who can recover shared accounts.
- Maintain a simple list of who has access to what, including contractors.
- Revoke access the same day a role ends; treat contractors like employees for this step.
- Review the access list quarterly for fifteen minutes — look for dead projects and leftover invites.
- Never reuse personal passwords for business admin accounts.
- Document the offboarding steps so revocation does not depend on one person's memory.
Shared inboxes and “god accounts”
Small teams love shared inboxes and a single admin login for “the company” social profiles. Those patterns are convenient and dangerous. Prefer role-based access where the product allows it: separate users for each person, shared labels or queues for the work. When a vendor only offers one login, put that credential in the password manager, enable two-factor with shared recovery, and never paste the password into onboarding emails.
Also watch for personal accounts used as business infrastructure — a founder's personal Google account holding the company Drive, or a personal domain registrar login. Migrate those to business-owned accounts as soon as you can. The day a personal relationship with the company changes is a terrible time to discover that the website DNS lives in someone's hobby email.
A quarterly review catches what daily habits miss
Even with good habits, access accumulates unnoticed — a contractor's temporary invite, an account created for a project that ended months ago, a former intern still in the newsletter tool. A short quarterly review, walking the list of who has access to what, catches drift before it becomes exposure.
Use the review to delete unused accounts, not only to trim people. Abandoned SaaS logins with weak or reused passwords are quiet liabilities. If nobody can explain why an account exists, disable it and rotate anything that shared that password historically.
Bring a printout or spreadsheet of systems, not a vague conversation. Walk email admin, cloud storage admin, password manager groups, domain and hosting, banking and accounting, CRM, ad platforms, and social. Fifteen focused minutes beats an hour of “we should get more organized someday.”
You will not get perfect compliance from a five-person team living on chat. You can get a system where the default is safer than a spreadsheet, offboarding is a same-day ritual, and someone notices when access drifts. That is the baseline worth defending — not a fantasy of zero risk, but a practical refusal to leave the front door unlocked because locking it felt like overhead.
When you eventually outgrow this baseline — more employees, audits, customer security questionnaires — you can add SSO and formal identity tools without throwing away the habits. The teams that struggle in audits are rarely missing a logo on a vendor slide. They are missing unique passwords, two-factor, and a living access list. Start there.