Five Login Habits That Quietly Put Your Business at Risk

None of these start as bad decisions

Every habit on this list began as somebody solving a real problem quickly. That is worth saying up front, because lists like this usually read as a scolding, and a scolding is not useful to anyone.

These are the five patterns we find most often in growing businesses, why each one made sense at the time, and what to do instead. None of them require a technical background to fix. Most of them take an afternoon.

 The shared login everybody uses

There is one account for the shipping portal. Or the utility company. Or the industry association everybody needs into occasionally. The password lives on a sticky note, in a shared document, or in the memory of whoever has been there longest.

Why it happened: individual accounts cost money, or the vendor made them a nuisance to set up, and you needed four people in there by Thursday.

The actual problem: not that someone will misuse it. The problem is that a shared login has no record. If something changes in that account, nobody can say who changed it, and that is true whether the cause was a mistake, a departure, or something worse. You have also just made that one password impossible to change, because nobody knows the full list of people it would break.

What to do: start with the accounts that touch money, client data, or anything a funder or insurer would ask about. Individual logins for those, even if it costs a little more. For genuinely shared service accounts, put the credentials in a proper password manager rather than a document, so at least access can be granted and revoked deliberately.

Passwords that outlive the people who knew them

Someone left eighteen months ago on good terms. Their email was shut off the same week. And their access to the payroll portal, the file sharing account, and two vendor systems is, as far as anyone can confirm, still live.

Why it happened: offboarding almost always focuses on the obvious accounts. Email and the main systems get handled. The long tail does not, because nobody has the full list of the long tail.

The actual problem: this is the one auditors, insurers, and funders ask about most directly, and it is uncomfortable precisely because the honest answer is usually “we think so.”

What to do: write down the offboarding steps once, as a checklist, while you can still remember them. Then go back through everyone who has left in the past two years and work the list. That second part is tedious and it is the part that actually closes the gap.

Multi-factor authentication turned on for some things

Multi-factor authentication, sometimes shortened to MFA, is the extra step after your password, usually a code on your phone or a prompt you approve. It is on for email, because email was the first thing anyone worried about. It is not on for the file storage, the accounting system, or the remote access tool.

Why it happened: it got rolled out during one project, for one system, and there was never a second project.

The actual problem: partial coverage gives you most of the inconvenience and a fraction of the protection. It also gives you a false read on where you stand, which is worse than knowing you have none of it.

What to do: list every system that holds client, financial, or personnel information, then check each one honestly. Turn it on wherever it is available. Where it is not available, note that, because the note is what turns an unknown into a decision you can make later.

Company access living in personal places

A staff member forwards work documents to a personal address so they can look at them on the weekend. Somebody uses a personal phone for company email, with no separation between the two. A former contractor still has a folder in their own cloud account with your files in it.

Why it happened: people trying to do their jobs around a tool that was not convenient enough. That is nearly always what this is, and it is a signal about the tool rather than the person.

The actual problem: your data is now in places you do not control and cannot inventory. When someone leaves, it goes with them, and not because anyone intended that.

What to do: ask why the workaround exists before you ban it. If people are forwarding documents home, remote access is probably harder than it should be. Fix the friction and the habit usually resolves on its own.

Nobody has the full list

This is the one underneath the other four. Ask a growing business to name every online service holding company data and you will get the main ones immediately, a few more after some thought, and then a pause. The pause is the finding.

Why it happened: accounts get created by whoever needed them, when they needed them, over years, often on a card that no longer belongs to anyone still employed.

What to do: pull twelve months of card and bank statements and write down every recurring technology charge. That single exercise surfaces most of the list, and it usually finds a few subscriptions worth cancelling while you are in there.

Where this actually sits

Notice what these five have in common. Not one of them is exotic, and not one of them is a technology failure. They are all record-keeping and process gaps, and they exist because the person handling technology at your business is doing it alongside another full-time job.

That is honest framing. This is not a security problem that appeared out of nowhere. It is the same capacity problem showing up in a different place.

If your organization answers to funders, insurers, boards, or clients who ask what you have in place, these five are usually the first questions on the form. Our compliance page covers the access controls, documented policies, and audit evidence side of this in more detail, and habit two connects directly to how backup and recovery is handled.

A straightforward review, no obligation

CMIT Solutions of San Marcos & New Braunfels offers a free thirty-minute IT assessment. We will go through these five with you honestly, tell you which ones apply, and give you a clear picture of where you stand. If you are in better shape than you expected, we will say so.

 

Frequently Asked Questions

1. Why are shared logins a security risk for businesses?+
Shared logins make it difficult to know who accessed an account or changed information. They also make password updates, employee departures, and access reviews harder because multiple people may depend on the same credentials.
2. Should every employee have their own login credentials?+
For systems that contain financial, client, employee, or sensitive business information, individual user accounts are generally the better approach. They make access easier to track, review, and revoke when responsibilities change.
3. What is the safest way to manage a shared business account?+
If an account genuinely needs to be shared, credentials should be stored in a secure password manager rather than in a document, spreadsheet, email, or sticky note. Access should also be limited to people who actually need it.
4. Why should businesses avoid storing passwords in shared documents?+
Shared documents often provide limited control over who can view, copy, or continue using a password. A password manager provides stronger access controls and makes it easier to grant or revoke access deliberately.
5. Why is employee offboarding important for cybersecurity?+
A proper offboarding process helps ensure former employees no longer have access to email, cloud storage, accounting platforms, payroll systems, vendor portals, remote access tools, or other company resources.
6. What accounts should be reviewed when an employee leaves?+
Businesses should review email, Microsoft 365 or Google Workspace, payroll systems, accounting software, cloud storage, CRM platforms, vendor portals, remote access tools, industry applications, and any other service the employee used.
7. How can a business improve its employee offboarding process?+
Create a written checklist that identifies every system where access may need to be removed. Use the same process for employees, contractors, temporary workers, and others who have access to company systems.
8. Should businesses review accounts belonging to former employees?+
Yes. Periodic reviews can uncover active accounts or permissions that were missed during offboarding. Businesses that have grown quickly should consider reviewing former employee and contractor access across all major systems.
9. What is multi-factor authentication?+
Multi-factor authentication, or MFA, requires an additional form of verification beyond a password, such as an authentication app, security code, hardware key, or approval notification.
10. Which business systems should have MFA enabled?+
MFA should be enabled wherever possible, especially for email, cloud storage, accounting systems, payroll applications, remote access tools, administrative accounts, and systems that contain sensitive business information.
11. Is enabling MFA only for email enough?+
No. Email is important, but attackers may also target file storage, accounting software, remote access platforms, and other cloud applications. Businesses should review MFA coverage across their entire technology environment.
12. Why is partial MFA coverage a problem?+
Partial coverage can leave important systems exposed while creating the impression that the business is fully protected. A complete review helps identify where MFA is enabled, where it is missing, and where additional controls may be necessary.
13. Is it safe for employees to send work files to personal email accounts?+
Business information should generally stay within company-approved systems. Personal email accounts may not provide the same security controls, monitoring, retention policies, or access management as company-managed accounts.
14. Can employees use personal phones for business email?+
They can in some environments, but the business should have clear security policies and appropriate device controls in place. Without them, company data may remain on devices the organization cannot properly manage or remove.
15. Why do employees create technology workarounds?+
Most workarounds begin because an approved system is inconvenient or difficult to use. Instead of only banning the workaround, businesses should identify the underlying friction and improve the tools or process causing it.
16. How can cloud services reduce unsafe workarounds?+
Properly configured cloud services can make company documents and applications securely accessible from approved devices and locations, reducing the need to forward files to personal accounts or store them outside company systems.
17. Why should a business maintain a complete technology inventory?+
A technology inventory shows which applications, cloud services, devices, subscriptions, and vendor accounts the business uses. It can help identify security gaps, unnecessary expenses, forgotten accounts, and systems containing sensitive information.
18. How can businesses find forgotten software subscriptions?+
One practical method is to review approximately twelve months of company credit card and bank statements for recurring technology charges. Those charges can then be matched to active software and service accounts.
19. How do managed IT services help prevent these habits from returning?+
Managed IT services can provide ongoing account management, access reviews, cybersecurity monitoring, employee onboarding and offboarding, password management, documentation, backups, network management, and technology planning.
20. How can CMIT Solutions of San Marcos & New Braunfels help identify IT security gaps?+
CMIT Solutions of San Marcos & New Braunfels can review user accounts, passwords, MFA coverage, former employee access, cloud systems, backups, subscriptions, documentation, and other technology processes to help identify gaps and prioritize practical improvements.

CMIT Solutions hero banner: dark blue gradient with logo and copy, a man in a suit using a laptop on the right, and a red Contact Us button.

Back to Blog

Share:

Related Posts

Behind the Scenes at Edo National Association Worldwide’s Convention

Behind the Scenes at Edo National Association Worldwide’s Convention August 3, 2023…

Read More

Boost Your Business’s Cybersecurity

Boost Your Business’s Cybersecurity August 18, 2023 Improving cybersecurity for your business…

Read More

6 Types of Hackers

Do you ever wonder who is behind all those cyberattacks that steal private information or cause mayhem online? Well, there are many different types of hackers out there, from black hats to red hats and everything in between.

Read More