The Login Nobody Remembers Changing
A client called me last year with an odd problem. Their marketing coordinator had quit six months earlier. But she could still log into the company's Instagram account. She could still see the shared business email inbox. Nobody had noticed, because nobody had changed the password. It was the same password the whole team had used for years — written on a sticky note by the register, then copied into a shared document when they went "digital."
This isn't rare. I see some version of it in almost every small business I work with. One login. One password. Everyone uses it — the owner, the manager, the new hire who started last week. It feels simple. It feels efficient. And it's one of the easiest ways a business can quietly expose itself to risk.
Small businesses are often more exposed here than big companies, not less. Larger companies usually require an extra login step called two-factor authentication. Most small teams still rely on a password alone, which makes a shared login an even bigger opening.
Why Sharing Feels Easier, At Least At First
I understand why teams do this. Setting up separate logins for five people feels like more work than typing one password everyone already knows. Nobody wants to call IT, or a nephew who "does computers," every time someone forgets their credentials.
So the shared password sticks around. It lives on a sticky note, in a group chat, or in a spreadsheet named "Passwords — Do Not Share" that gets shared constantly.
The problem isn't that people are careless. It's that a shared password was never built to hold up under real business use. Every person who knows it is a door into your accounts. And you can't close just one of those doors — changing the password locks out the whole team, including the people who should still have access.
The Real Cost: You Can't Tell Who Did What
Here's the part most owners don't think about until something goes wrong. When five people share one login, your accounts have no memory of who did what.
Say your business Instagram posts something odd at 11 p.m. Or a client email goes out with the wrong price. Or a payment gets approved in your accounting software that nobody signed off on. With a shared password, you can't answer a simple question: who was logged in at the time?
This is the same blind spot I've written about in the hidden risk of one person holding all the keys — except here, it's not one person holding the keys. It's everyone holding the same key, which is almost worse, because no single person feels responsible for it.
And when someone leaves, the risk doesn't leave with them. The password does, in theory — but changing it means resetting it for everyone still working there, so most businesses just don't. That's how a former coordinator kept access to Instagram for six months. Studies on departing employees back this up: most people who leave a job say they could still log into at least one account from their old workplace weeks or months later, simply because nobody thought to change a password that only they were supposed to know.
The Simple Fix: A Password Manager
The good news is that fixing this doesn't require a big IT project. The single best first step is a password manager — a tool like 1Password or Bitwarden that stores every login in one secure, encrypted vault.
Here's what it actually changes day to day:
- Each person gets their own account and their own master password
- The manager can share specific logins with specific people, without anyone actually seeing the password in plain text
- When someone leaves, you remove their access to the vault, instead of resetting every password by hand
- Most small-team plans cost less per month than a couple of coffees
This one change also solves the "who did what" problem, since most password managers keep a simple record of who accessed what, and when.
I had a client picture this as "one filing cabinet with individual keys" instead of "one key everyone copies." That's really all a password manager is. Nobody has to remember eight different logins. They remember one strong password to open their own drawer, and the manager handles the rest.
Give Everyone Their Own Login, and Turn On Two-Factor
The second fix matters just as much: stop using one shared login for a tool whenever that tool allows individual accounts. Email, accounting software, your CRM, even social media scheduling tools like Buffer or Hootsuite, mostly let you add team members with their own sign-in.
Pair that with two-factor authentication, often shortened to "2FA" or "MFA." It just means that after typing a password, you confirm it's really you with a quick code sent to your phone or an app. It adds about ten seconds to logging in. In exchange, even if a password leaks, a stranger can't get into the account without also having your phone.
This habit closes a gap I also see when I talk about how businesses protect the data behind their systems — a strong password is only half the lock. Two-factor is the other half.
How to Start Without Disrupting Your Whole Team
You don't need to fix everything this week. I usually tell clients to start small and build momentum:
- Pick your riskiest account first — usually email, banking, or whatever holds customer payment information.
- Set up a password manager and move that one account into it. Give each person their own login for it.
- Turn on two-factor authentication for that account.
- Repeat for the next account — social media, then your CRM, then everything else — over the next month or two.
There's no need to announce a company-wide "security overhaul." Just quietly make each tool safer, one at a time, as part of normal work. Most employees barely notice the change, other than a slightly different login screen.
The sticky note by the register, the shared document, the one password everyone knows — none of it is a personal failing. It's just what happens when a business grows faster than its habits do. The fix isn't complicated or expensive. It just needs a starting point.