Cybersecurity
The account nobody closed
Somewhere in your business there is an account nobody has closed.
Usually nobody was careless. Closing it simply wasn’t anybody’s job. The person left, the paperwork got filed, the laptop came back, and the login to the booking system, or the shared inbox, or the account that pays the internet bill, stayed open.
It’s the most common gap we find in small businesses, and also the cheapest to close. It costs an afternoon and no money at all.
Why it happens
Onboarding has a natural owner. Somebody has to set the new hire up before they can do any work, so it gets done on day one, every time, without anyone having to remember.
Offboarding has no such forcing function. Nothing breaks when an old account stays open. Nobody complains. The failure is silent, and silent failures never get scheduled.
So access piles up. Five years in, a business with eight people can easily be carrying forty live logins, and a good share of them belong to people who no longer work there.
Why a stale login is a real risk
An old account is exactly what attackers buy.
The Verizon 2026 Data Breach Investigations Report found that 73% of ransomware victims had a credential leak or an information-stealing infection in the year before the attack, and half of those had the credential event within 95 days of it.
Read that as a sequence, because it is one. The login is stolen first. It gets collected, packaged and sold. The break-in happens later, sometimes months later, by someone who simply logged in. An account that belongs to nobody is the ideal target, because nobody notices it being used.
The list that fixes it
You don’t need software for this. You need one page and an hour.
- Write down every account the business depends on. Email. Banking. Payroll. The website and the domain name. Point of sale. Booking or scheduling. Social media. The phone and utility accounts. Anything with a login or a bill.
- Next to each one, write who can get into it today. Write who can, which isn’t always who should.
- Cross out anyone who no longer works here. That’s your afternoon’s work, and the list is usually shorter than people fear.
- Mark anything with a shared password. A shared password can’t be revoked from one person. It can only be changed for everybody, and that friction is why shared passwords survive departures.
- Mark anything only one person can get into. That’s the other half of the same problem, and it bites when somebody is on vacation, in the hospital, or leaves on bad terms.
Make offboarding boring
Vigilance fades. What works is a checklist that runs the same way every time, whether the person leaves happily or not:
- Disable the email account instead of deleting it. You may still need what’s in it, and deleting it can break the other accounts it was used to register.
- Remove them from every account on your list, including the less obvious ones.
- Change any password they knew that somebody else still uses.
- Take them off the phone system, the door codes and the recurring payments.
- Move anything belonging to the business out of their personal drive.
Print it and tape it inside a cabinet door. A checklist still works on a day when you’re distracted, annoyed or short-staffed, which is usually the day somebody leaves.
Two things worth doing while the list is open
Turn on multi-factor authentication for email first. Email can reset nearly every other account you own, which makes it the one worth protecting hardest. It takes about thirty seconds.
Check who the registrar lists as the owner of your domain name. The person who built your site may not be the person who owns the name. More than one business has discovered its domain sitting in the account of a web designer they parted ways with years ago. That’s an offboarding problem too, and it’s far easier to sort out before you need to move the site.
Once a year is enough
Put it on the calendar for the same week each year and treat it like an inventory count.
It won’t feel like it accomplished much, which is how a working control feels from the inside. An hour a year closes more doors than most security software will.
Want to know where you actually stand? We do free, no-pressure security checks for small businesses across the East Bay, covering backups, accounts and defenses. We tell you plainly what to fix first.
Ransomware and credential-timing figures from the Verizon 2026 Data Breach Investigations Report. Guidance on multi-factor authentication and account hygiene follows CISA’s Secure Our World campaign.