Work through every account that matters: who has access, whether the password is unique, whether two-step is on, and whether anybody who left still can.

Why now

This is a task that needs an hour of uninterrupted attention and never gets one.

The week before a break has that hour, and nobody is waiting for anything.

It is also the point at which the year's changes are visible: who joined, who left, what was set up in a hurry, and what a supplier was given access to in March.

And doing it before a period when nobody is watching the systems is better than doing it afterwards.

The accounts that matter

Six or eight accounts covers almost every small business, and the audit is short because the list is short. Everything else can wait for a year without consequence.

Four questions per account

The same four, which makes this mechanical rather than a judgement.

Who has access, by name, and does each of them still need it.

Is the password unique to this account, or used somewhere else.

Is two-step verification on, and where do the codes go.

Would somebody other than you be able to get in if you were unavailable.

Write the answers down as you go, since the record is what makes next year's audit twenty minutes rather than an hour.

Where any answer is uncomfortable, fix it then rather than noting it, because a list of intentions produces nothing.

Start with who has left

Since that is where the real exposure usually sits.

Anybody who left this year, any supplier whose engagement ended, and anybody who did a one-off piece of work.

Removing their accounts is the obvious part, and the part that gets missed is everything that survives removal.

Shared passwords they knew, which are unchanged and still work.

Recovery addresses pointing at their mailbox, application passwords they created, and recovery codes they may have written down.

Change any shared credential they knew, regardless of whether their own account is gone.

A worked example

A business did this for the first time in a quiet week.

They found seven accounts with an administrator belonging to a developer last used in 2020, one shared password known to four people including two who had left, and a recovery address on a domain they no longer owned.

Two accounts had two-step verification switched on with codes going to a phone number that had changed.

Fixing all of it took about ninety minutes, which was longer than expected and shorter than they had feared.

The following year the same audit took twenty-five minutes, because the list existed and most of it was unchanged.

Nothing had gone wrong in either year, which is the point of doing it while nothing has.

The shared password problem

Which is what an audit usually surfaces and what nobody wants to deal with.

Most small businesses have two or three credentials known to everybody, because that was the practical arrangement at the time.

Those cannot be revoked from any individual, cannot show who did what, and are usually the oldest and weakest passwords in the business.

Where the platform supports separate accounts, creating them is an afternoon and removes the problem permanently.

Where it does not, a password manager that shares a credential without revealing it is the next best arrangement, and changing it when somebody leaves becomes a routine step.

Fix one this year rather than all of them, since one fixed beats three intended.

Check the recovery routes too

Because they are the part that survives a password change.

For each account, look at where a reset would be sent and confirm the business controls it.

Check the recovery phone number is current, since these are set once and numbers change.

Check any recovery codes exist somewhere the business can reach, and regenerate them if anybody who left may have seen them.

And check connected applications, which retain access without a password and are invisible in a user list.

Those four checks take a few minutes per account and cover the failures a password audit alone misses.

Write down what you found

Since the record is most of the value.

One page listing each account, who has access, whether two-step is on, and where the recovery goes.

That page is what makes next year's audit short, and it is also what somebody needs if you are unavailable.

Keep it somewhere the business controls and somewhere reachable without the systems it describes, which usually means printed as well as stored.

Do not put the passwords on it, since it is a map rather than a key.

Check what has been in a breach

A ten-minute addition that finds problems the four questions do not.

Free services let you enter an email address and see whether it appears in known data breaches, which most business addresses do.

That matters where a password was reused, since a credential exposed elsewhere is tried against everything.

Check the addresses your important accounts use, and treat any hit as a reason to change that password everywhere it was used rather than only where it leaked.

Most password managers now flag reused and exposed credentials automatically, which turns this into a report rather than an exercise.

The counter-case

An audit is not a substitute for the basics.

A business with unique passwords, two-step on the important accounts, and a password manager has very little to find and could reasonably skip this.

Doing it annually is also the minimum, and the events that actually create exposure are people leaving and suppliers finishing, which happen at other times.

And an hour spent here is an hour not spent on backups, which matter more if you had to choose.

Do the six accounts, the four questions, and start with whoever left this year.

The hour

  1. List the six accounts that matter.
  2. Remove anybody who left this year.
  3. Change credentials they knew.
  4. Check each password is unique.
  5. Turn on two-step where it is off.
  6. Check recovery addresses and numbers.
  7. Write the one-page record.

Step three is the one most often skipped, since removing somebody's account feels complete and a shared password they knew is unchanged and still working.

Getting a team to adopt the main protection is covered in two-factor for a team that resists it.


Frequently asked questions

Why do this before a break?

Because it needs an uninterrupted hour and never gets one, the year's changes are visible now, and it is better done before a period when nobody is watching the systems.

Which accounts should I cover?

Email, the registrar, hosting and the site, payment and accounting, the business listing, and anything holding customer data. Six or eight covers most small businesses.

What are the four questions?

Who has access and do they still need it, is the password unique, is two-step on and where do codes go, and could somebody else get in if you were unavailable.

Where does the real exposure sit?

With people who left. Removing their account is the obvious part; shared passwords they knew, recovery addresses, and application passwords all survive it.

What does an audit usually surface?

Shared credentials known to everybody, which cannot be revoked individually, show who did what, and are usually the oldest passwords in the business.

What should I write down?

One page per account: who has access, whether two-step is on, and where recovery goes. Not the passwords, since it is a map rather than a key.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Somebody left this year?

Change the shared passwords they knew, not just their own account. That is the step people skip.

Start a Conversation