Shared mailboxes: convenience with a long tail
Reception, accounts, info@. The shared mailbox everyone uses and nobody owns is convenient today and a problem the day someone leaves.
Almost every business has one: the info@ or accounts@ or reception@ address that several people share. It is genuinely convenient. Cover is easy, nothing gets missed when someone is off, and customers have one address to remember. The trouble arrives slowly, in the long tail, which is why it is easy to ignore until it is not.
The first problem is ownership. When everyone can read a mailbox, nobody is responsible for it. Attachments get opened because “someone must have been expecting that”, and a dodgy invoice slips through because it is nobody's job in particular to be suspicious. Shared responsibility quietly becomes no responsibility.
The second problem is leavers. A shared mailbox is exactly the account people forget to close. The password is written on a note by the desk, three former staff still know it, and when one of them leaves on bad terms the account is still live and still holds years of correspondence. In most of the businesses we check, at least one such account is still open to someone who should not have it.
The fix is to treat the shared address as a proper mailbox, not a shared password. Modern email lets several named people access one inbox while each still signs in as themselves, with their own second step. That way there is a record of who did what, and closing a leaver's access does not mean changing a password everyone has to relearn.
For a regulated business this also gives you the audit trail you will be asked for. Who could see the customer data in that inbox, and when did their access end. With individual sign-in you can answer that. With a shared password on a sticky note, you cannot.
- ✓Convert shared logins into a shared mailbox that named people access as themselves.
- ✓Give each person their own second sign-in step, not a shared password.
- ✓Remove access the day someone leaves, and confirm it is gone.
- ✓Name one person as owner responsible for what lands in that inbox.
- Protecting bulk personal data and shared accounts NATIONAL CYBER SECURITY CENTRE ↗
- Access control when staff leave GOV.UK ↗
- Keeping personal data secure INFORMATION COMMISSIONER'S OFFICE ↗
Links open each publisher’s live coverage of this topic.