None of these start as bad decisions
Every habit on this list began as somebody solving a real problem quickly. That is worth saying up front, because lists like this usually read as a scolding, and a scolding is not useful to anyone.
These are the five patterns we find most often in growing businesses, why each one made sense at the time, and what to do instead. None of them require a technical background to fix. Most of them take an afternoon.
The shared login everybody uses
There is one account for the shipping portal. Or the utility company. Or the industry association everybody needs into occasionally. The password lives on a sticky note, in a shared document, or in the memory of whoever has been there longest.
Why it happened: individual accounts cost money, or the vendor made them a nuisance to set up, and you needed four people in there by Thursday.
The actual problem: not that someone will misuse it. The problem is that a shared login has no record. If something changes in that account, nobody can say who changed it, and that is true whether the cause was a mistake, a departure, or something worse. You have also just made that one password impossible to change, because nobody knows the full list of people it would break.
What to do: start with the accounts that touch money, client data, or anything a funder or insurer would ask about. Individual logins for those, even if it costs a little more. For genuinely shared service accounts, put the credentials in a proper password manager rather than a document, so at least access can be granted and revoked deliberately.
Passwords that outlive the people who knew them
Someone left eighteen months ago on good terms. Their email was shut off the same week. And their access to the payroll portal, the file sharing account, and two vendor systems is, as far as anyone can confirm, still live.
Why it happened: offboarding almost always focuses on the obvious accounts. Email and the main systems get handled. The long tail does not, because nobody has the full list of the long tail.
The actual problem: this is the one auditors, insurers, and funders ask about most directly, and it is uncomfortable precisely because the honest answer is usually “we think so.”
What to do: write down the offboarding steps once, as a checklist, while you can still remember them. Then go back through everyone who has left in the past two years and work the list. That second part is tedious and it is the part that actually closes the gap.
Multi-factor authentication turned on for some things
Multi-factor authentication, sometimes shortened to MFA, is the extra step after your password, usually a code on your phone or a prompt you approve. It is on for email, because email was the first thing anyone worried about. It is not on for the file storage, the accounting system, or the remote access tool.
Why it happened: it got rolled out during one project, for one system, and there was never a second project.
The actual problem: partial coverage gives you most of the inconvenience and a fraction of the protection. It also gives you a false read on where you stand, which is worse than knowing you have none of it.
What to do: list every system that holds client, financial, or personnel information, then check each one honestly. Turn it on wherever it is available. Where it is not available, note that, because the note is what turns an unknown into a decision you can make later.
Company access living in personal places
A staff member forwards work documents to a personal address so they can look at them on the weekend. Somebody uses a personal phone for company email, with no separation between the two. A former contractor still has a folder in their own cloud account with your files in it.
Why it happened: people trying to do their jobs around a tool that was not convenient enough. That is nearly always what this is, and it is a signal about the tool rather than the person.
The actual problem: your data is now in places you do not control and cannot inventory. When someone leaves, it goes with them, and not because anyone intended that.
What to do: ask why the workaround exists before you ban it. If people are forwarding documents home, remote access is probably harder than it should be. Fix the friction and the habit usually resolves on its own.
Nobody has the full list
This is the one underneath the other four. Ask a growing business to name every online service holding company data and you will get the main ones immediately, a few more after some thought, and then a pause. The pause is the finding.
Why it happened: accounts get created by whoever needed them, when they needed them, over years, often on a card that no longer belongs to anyone still employed.
What to do: pull twelve months of card and bank statements and write down every recurring technology charge. That single exercise surfaces most of the list, and it usually finds a few subscriptions worth cancelling while you are in there.
Where this actually sits
Notice what these five have in common. Not one of them is exotic, and not one of them is a technology failure. They are all record-keeping and process gaps, and they exist because the person handling technology at your business is doing it alongside another full-time job.
That is honest framing. This is not a security problem that appeared out of nowhere. It is the same capacity problem showing up in a different place.
If your organization answers to funders, insurers, boards, or clients who ask what you have in place, these five are usually the first questions on the form. Our compliance page covers the access controls, documented policies, and audit evidence side of this in more detail, and habit two connects directly to how backup and recovery is handled.
A straightforward review, no obligation
CMIT Solutions of San Marcos & New Braunfels offers a free thirty-minute IT assessment. We will go through these five with you honestly, tell you which ones apply, and give you a clear picture of where you stand. If you are in better shape than you expected, we will say so.


