Cybersecurity

The account nobody closed

Published August 3, 2026  ·  Exosphere Solutions

Somewhere in your business there is an account nobody has closed.

Not because anyone was careless. Because closing it was nobody’s job. The person left, the paperwork got filed, the laptop came back — and the login to the booking system, or the shared inbox, or the account that pays the internet bill, quietly stayed open.

It is the most common gap we find in small businesses, and it is also the cheapest one to close. It costs an afternoon and no money at all.

Why it happens

Onboarding has a natural owner. Somebody has to set the new hire up before they can do any work, so it gets done on day one, every time, without anyone having to remember.

Offboarding has no such forcing function. Nothing breaks when an old account stays open. Nobody complains. The failure is silent, and silent failures never get scheduled.

So access accumulates. Five years in, a business with eight people can easily be carrying forty live logins, and a good share of them belong to people who no longer work there.

Why a stale login is not a theoretical risk

An old account is the exact thing attackers buy.

The Verizon 2026 Data Breach Investigations Report found that 73% of ransomware victims had a credential leak or an information-stealing infection in the year before the attack — and half of those had the credential event within 95 days of it.

Read that as a sequence, because that is what it is. The login is stolen first. It gets collected, packaged and sold. The break-in happens later, sometimes months later, by someone who simply logged in. An account that belongs to nobody is the ideal candidate, because nobody notices it being used.

The list that fixes it

You do not need software for this. You need one page and an hour.

  1. Write down every account the business depends on. Email. Banking. Payroll. The website and the domain name. Point of sale. Booking or scheduling. Social media. The phone and utility accounts. Anything with a login or a bill.
  2. Next to each one, write who can get into it today. Not who should. Who can.
  3. Cross out anyone who no longer works here. That is your afternoon’s work, and it is usually shorter than people fear.
  4. Mark anything with a shared password. A shared password cannot be revoked from one person — it can only be changed for everybody. That friction is exactly why shared passwords survive departures.
  5. Mark anything only one person can get into. That is the other half of the same problem, and it is the half that bites when somebody is on holiday, in hospital, or leaves badly.

Make offboarding boring

The fix is not vigilance. Vigilance decays. The fix is a checklist that runs the same way every time, whether the person leaves happily or not:

Print it. Tape it inside a cupboard door. The point of a checklist is that it still works on a day when you are distracted, annoyed or short-staffed — which is generally the day somebody leaves.

Two things worth doing while the list is open

Turn on multi-factor authentication for email first. Email can reset nearly every other account you own, which makes it the one worth protecting hardest. It takes about thirty seconds.

Check who the registrar says owns your domain name. Not who built the site — who owns the name. More than one business has discovered that its domain sits in the account of a web designer they parted company with years ago. That is an offboarding problem too, and it is far easier to sort out before you need to move the site than after.

Once a year is enough

Put it on the calendar for the same week each year and treat it like a stocktake.

It will not feel like it accomplished much, which is what a working control feels like from the inside. An hour a year closes more doors than most security software ever will.

Want to know where you actually stand? We do free, no-pressure security checks for small businesses across the East Bay — backups, accounts, defenses. We tell you plainly what to fix first.

(925) 603-3036  ·  exosolutions.us

Ransomware and credential-timing figures from the Verizon 2026 Data Breach Investigations Report. Guidance on multi-factor authentication and account hygiene follows CISA’s Secure Our World campaign.

← All articles