Five Login Habits That Quietly Put Your Business at Risk

None of these start as bad decisions

Every habit on this list began as somebody solving a real problem quickly. That is worth saying up front, because lists like this usually read as a scolding, and a scolding is not useful to anyone.

These are the five patterns we find most often in growing businesses, why each one made sense at the time, and what to do instead. None of them require a technical background to fix. Most of them take an afternoon.

The shared login everybody uses

There is one account for the shipping portal. Or the utility company. Or the industry association everybody needs into occasionally. The password lives on a sticky note, in a shared document, or in the memory of whoever has been there longest.

Why it happened: individual accounts cost money, or the vendor made them a nuisance to set up, and you needed four people in there by Thursday.

The actual problem: not that someone will misuse it. The problem is that a shared login has no record. If something changes in that account, nobody can say who changed it, and that is true whether the cause was a mistake, a departure, or something worse. You have also just made that one password impossible to change, because nobody knows the full list of people it would break. This is really the spare key problem in a different shape.

What to do: start with the accounts that touch money, client data, or anything a funder or insurer would ask about. Individual logins for those, even if it costs a little more. For genuinely shared service accounts, put the credentials in a proper password manager rather than a document, so at least access can be granted and revoked deliberately. A managed IT services partner can help set this up correctly the first time.

Passwords that outlive the people who knew them

Someone left eighteen months ago on good terms. Their email was shut off the same week. And their access to the payroll portal, the file sharing account, and two vendor systems is, as far as anyone can confirm, still live.

Why it happened: offboarding almost always focuses on the obvious accounts. Email and the main systems get handled. The long tail does not, because nobody has the full list of the long tail.

The actual problem: this is the one auditors, insurers, and funders ask about most directly, and it is uncomfortable precisely because the honest answer is usually “we think so.”

What to do: write down the offboarding steps once, as a checklist, while you can still remember them. Then go back through everyone who has left in the past two years and work the list. That second part is tedious and it is the part that actually closes the gap. Solid network management makes this kind of review far easier to run consistently.

Multi-factor authentication turned on for some things

Multi-factor authentication, sometimes shortened to MFA, is the extra step after your password, usually a code on your phone or a prompt you approve. It is on for email, because email was the first thing anyone worried about. It is not on for the file storage, the accounting system, or the remote access tool. As we’ve noted before, MFA alone rarely tells the whole story.

Why it happened: it got rolled out during one project, for one system, and there was never a second project.

The actual problem: partial coverage gives you most of the inconvenience and a fraction of the protection. It also gives you a false read on where you stand, which is worse than knowing you have none of it.

What to do: list every system that holds client, financial, or personnel information, then check each one honestly. Turn it on wherever it is available. Where it is not available, note that, because the note is what turns an unknown into a decision you can make later. This is the kind of gap a proper cybersecurity assessment is built to catch.

Company access living in personal places

A staff member forwards work documents to a personal address so they can look at them on the weekend. Somebody uses a personal phone for company email, with no separation between the two. A former contractor still has a folder in their own cloud account with your files in it.

Why it happened: people trying to do their jobs around a tool that was not convenient enough. That is nearly always what this is, and it is a signal about the tool rather than the person.

The actual problem: your data is now in places you do not control and cannot inventory. When someone leaves, it goes with them, and not because anyone intended that.

What to do: ask why the workaround exists before you ban it. If people are forwarding documents home, remote access is probably harder than it should be. Fix the friction and the habit usually resolves on its own. Proper cloud services configuration often removes the need for the workaround entirely.

Nobody has the full list

This is the one underneath the other four. Ask a growing business to name every online service holding company data and you will get the main ones immediately, a few more after some thought, and then a pause. The pause is the finding.

Why it happened: accounts get created by whoever needed them, when they needed them, over years, often on a card that no longer belongs to anyone still employed.

What to do: pull twelve months of card and bank statements and write down every recurring technology charge. That single exercise surfaces most of the list, and it usually finds a few subscriptions worth cancelling while you are in there. A structured IT services procurement process prevents this pile-up from building again.

Where this actually sits

Notice what these five have in common. Not one of them is exotic, and not one of them is a technology failure. They are all record-keeping and process gaps, and they exist because the person handling technology at your business is doing it alongside another full-time job.

That is honest framing. This is not a security problem that appeared out of nowhere. It is the same capacity problem showing up in a different place.

If your organization answers to funders, insurers, boards, or clients who ask what you have in place, these five are usually the first questions on the form. Our compliance page covers the access controls, documented policies, and audit evidence side of this in more detail, and habit two connects directly to how data backup and recovery is handled. Ongoing IT support is usually what keeps these habits from creeping back in.

A straightforward review, no obligation

CMIT Solutions of Austin East offers a free thirty-minute IT assessment. We will go through these five with you honestly, tell you which ones apply, and give you a clear picture of where you stand. If you are in better shape than you expected, we will say so.

 

Frequently Asked Questions

1. Why are shared logins a security risk for businesses?+
Shared logins make it difficult to identify who accessed an account or made a change. They also make password changes, employee departures, and access reviews harder to manage because there is no clear record of individual activity.
2. Should every employee have their own login credentials?+
For systems involving financial information, client data, employee records, or other sensitive information, individual accounts are strongly recommended. Individual credentials make it easier to grant, review, and revoke access when needed.
3. Is it ever acceptable for employees to share an account?+
Some service accounts may need to be shared, but their credentials should be stored in a secure password manager rather than a spreadsheet, shared document, email, or sticky note. Access should also be limited to people who genuinely need it.
4. What is the best way to manage shared business passwords?+
A business password manager can securely store credentials while controlling who can view or use them. It also makes it easier to revoke access when responsibilities change or someone leaves the company.
5. Why is employee offboarding important for cybersecurity?+
Offboarding helps ensure former employees no longer have access to company email, cloud storage, payroll systems, vendor portals, remote access tools, and other business systems after they leave.
6. What accounts should be disabled when an employee leaves?+
Businesses should review email, Microsoft 365 or Google Workspace, file storage, accounting software, payroll systems, CRM platforms, vendor accounts, remote access tools, industry applications, and any other service the employee used.
7. How can businesses improve their employee offboarding process?+
Create a documented offboarding checklist listing every system that may require access removal. The checklist should be followed consistently for employees, contractors, temporary staff, and anyone else with company access.
8. Should businesses review accounts belonging to former employees?+
Yes. Growing businesses should periodically review older accounts to confirm that former employees and contractors no longer have active access to company systems or data.
9. What is multi-factor authentication?+
Multi-factor authentication, or MFA, requires users to provide an additional form of verification after entering a password, such as approving a mobile notification, entering a security code, or using an authentication application.
10. Which business systems should have MFA enabled?+
MFA should be enabled wherever possible, especially for email, cloud storage, accounting systems, payroll platforms, remote access tools, administrative accounts, and systems containing client, financial, or personnel information.
11. Is enabling MFA for email enough to protect a business?+
No. Email protection is important, but attackers may also target cloud storage, accounting platforms, remote access applications, and other systems. Businesses should review MFA coverage across their entire technology environment.
12. Why is inconsistent MFA coverage a problem?+
Partial MFA coverage can leave important systems vulnerable even when other accounts are protected. Businesses may also assume they have stronger security than they actually do if they have never reviewed which systems are covered.
13. Is it safe for employees to send work files to personal email accounts?+
Generally, company information should remain within approved business systems. Personal email accounts may not provide the same security controls, monitoring, retention policies, or access management as company-managed accounts.
14. Can employees safely use personal devices for work?+
Personal devices can sometimes be used for work if the organization has appropriate security policies and device management controls. Without those protections, company data may be stored somewhere the business cannot properly monitor or remove.
15. Why do employees create unauthorized technology workarounds?+
Employees often create workarounds because approved systems are inconvenient, difficult to access remotely, or do not fit how they actually work. Businesses should understand the reason behind the workaround before simply prohibiting it.
16. How can cloud services reduce the use of personal accounts?+
Properly configured cloud services can provide secure remote access to documents, applications, email, and collaboration tools, reducing the need for employees to forward files to personal accounts or store business information outside company systems.
17. Why should a business maintain a complete list of its technology services?+
A technology inventory helps businesses understand where company data is stored, who has access, which services are still needed, what subscriptions are being paid for, and which systems may introduce security or compliance risks.
18. How can a business identify forgotten software subscriptions and online accounts?+
Reviewing approximately 12 months of business credit card and bank statements can reveal recurring technology charges. Those charges can then be matched with software platforms, cloud services, vendor accounts, and other subscriptions.
19. How do managed IT services help prevent these problems?+
Managed IT services can provide consistent account management, employee onboarding and offboarding, security reviews, MFA deployment, technology documentation, cloud management, network management, and ongoing IT support.
20. What should businesses look for during an IT security and compliance review?+
A review should examine user accounts, shared credentials, former employee access, MFA coverage, personal devices, cloud services, data storage locations, software subscriptions, backups, security controls, written procedures, and the documentation needed for clients, insurers, boards, or auditors.

Hero banner for CMIT Solutions of Austin East offering secure IT solutions; shows a woman in a blazer using a laptop emerging from a smartphone with a red Contact Us button on the right.

 

Back to Blog

Share:

Related Posts

Business handshake overlayed with urban landscape, symbolizing collaboration in IT and construction industries.

Cybersecurity for Construction in Central Texas: Protecting Projects Amid Rapid Growth

Central Texas has been experiencing unprecedented growth and development over the past…

Read More
Magnified binary code with 'Virus Found' text indicating computer virus detection for business protection.

Understanding Computer Viruses and How CMIT Solutions Protects Your Business

Understanding Computer Viruses and How CMIT Solutions Protects Your Business Did you…

Read More
Two construction workers shaking hands with a digital padlock overlay, representing cybersecurity for construction firms.

Strengthening Cybersecurity for Construction Firms: Addressing Secondary Challenges

Strengthening Cybersecurity for Construction Firms: Tackling Critical Challenges As the construction industry…

Read More