New year, new starters, same access problem
January is when a business hires, and quietly loses track of who can get into what. Ten minutes now saves a bad afternoon later.
Access sprawl is not dramatic. It is the shared login you set up for a busy fortnight in December, the freelancer still on the invoicing tool in March, the old email account that never got closed. None of it feels urgent, which is exactly why it accumulates. Each item is a small convenience that quietly becomes a way in.
The pattern we see in most of the businesses we check is the same: nobody can list, from memory, everyone who has access to the money and the mail. That is the real problem. An attacker does not need to break anything if a dormant account with a weak password is sitting there waiting, still trusted by every system it was ever added to.
The fix is a list, not a project. Write down every tool that touches your bank, your invoices, your email and your customer records. For each one, note who can sign in and whether they still need to. It is dull work and it takes about ten minutes per system, which is why it gets skipped and why doing it puts you ahead of most.
January is the right moment because it is when the changes happen. New starters need adding, seasonal help needs removing, and the person who left in November may still be on three things. Do the round once now, then diarise it quarterly. Little and often beats the annual panic when a client or an insurer asks who has access.
- ✓List every tool that touches money, mail or customer data.
- ✓For each one, name who can sign in and remove anyone who left.
- ✓Kill shared logins - give people their own accounts with their own passwords.
- ✓Put a quarterly reminder in the diary to run the list again.
- Cyber Aware: protect your accounts NATIONAL CYBER SECURITY CENTRE ↗
- Small business guide: keeping devices and accounts secure NATIONAL CYBER SECURITY CENTRE ↗
- Managing staff access and leavers GOV.UK ↗
Links open each publisher’s live coverage of this topic.