Who still knows
your company password?
Maybe two people. Maybe ten. Or perhaps nobody is entirely sure anymore. A shared password that has been passed between employees for years can become a much bigger security problem than it first appears.
Who still knows your company password?
Maybe the answer is two people.
Maybe ten.
Or perhaps nobody is entirely sure anymore.
One of the more common security weaknesses in small and medium-sized businesses is not a sophisticated cyberattack.
It is something much simpler:
the same password being used by several people for years.
The Wi-Fi password.
An administrator account.
Hosting.
The router.
Social media.
A shared mailbox.
A business application.
Somebody created the password, sent it to a colleague and from that point onward it was simply passed along.
The problem starts when nobody knows exactly who still has it.
A shared password means you do not really have individual users
If five people sign in using:
admin
and all know the same password, the system technically knows that admin performed an action.
But it does not know which person did it.
If somebody:
- changes a setting
- deletes information
- changes a configuration
- downloads a file
- creates another user
it may later be impossible to determine reliably who performed the action.
That is not only a security problem.
It is also a system management problem.
What happens when an employee leaves?
This is where shared passwords become particularly uncomfortable.
You disable:
- Microsoft 365
- VPN
- company email
- the user's computer access
and assume access has been closed.
But what if that person also knows:
- the firewall administrator password
- the WordPress administrator account
- the hosting login
- the Wi-Fi password
- the domain registrar login
- a shared business application account
Disabling their personal account changes none of those things.
They still know the credentials.
That is why an employee departure can require changing several shared passwords — and sometimes nobody has a complete list of what those passwords are. That is also why it matters to have a clear process for what IT should do when an employee leaves.
“But we are only a small team”
That is one of the most common reasons shared accounts appear.
Three people work together.
Everybody trusts one another.
Creating one account feels easier.
The problem is that companies rarely stay at three people forever.
Over time you may add:
- new employees
- external contractors
- students
- agencies
- service providers
- web developers
- accounting partners
- temporary workers
A password that originally belonged to two people can be known by ten people several years later.
And nobody has a complete record of who received it.
The worst passwords are the ones “nobody is allowed to change”
Older IT environments often contain at least one account or dependency like this.
For example:
“Do not change that password because we do not know what uses it.”
That is a strong sign of technical debt.
The credential may be used by:
- an old service
- a printer
- an application
- a backup script
- network equipment
- an automation
The dependencies were never documented, so the account became almost untouchable.
At that point, the security problem is no longer just the password.
The bigger problem is that nobody has a complete picture of the system.
An administrator account should not be your everyday account
Another common practice is for an administrator to use the same account for:
- web browsing
- everyday work
- system administration
That unnecessarily increases risk.
Administrative privileges should be used when they are actually required.
For everyday work, the user should have a standard account and use a separate administrative identity for privileged tasks.
That reduces the chance that a single incident automatically receives the highest level of access.
Passwords in Excel are not a password manager
Many companies have something like:
passwords.xlsx
or:
passwords.docx
Sometimes the file is even stored on a shared network drive.
That is better than nobody knowing the passwords, but it is not a good access-management system.
A proper password manager allows much better control:
- each user has their own account
- access can be added and removed
- the password itself does not need to be sent in a message
- it is possible to track who has access
- strong, unique passwords can be used
- an employee leaving does not require reconstructing every credential
The important difference is that you share access rather than simply sharing the password.
Using one password for several services is an even bigger problem
For example, using the same password for:
- hosting
- cloud services
- router administration
- social media
If one of those services is compromised, an attacker gains a very good credential to try against the others.
Every important account should therefore have its own password.
Not variations such as:
Company2026!
Company2026!mail
Company2026!hosting
but genuinely separate passwords.
MFA does not replace good access management
Multi-factor authentication is extremely useful.
But it does not fix badly organised user accounts.
If five people use the same account, an obvious question appears:
Whose second factor is it?
Does one person receive every code?
Does everybody use the same device?
Is the code forwarded through chat?
That is a sign the account itself probably needs restructuring.
MFA works best when each user has an individual identity.
How to perform a quick access audit
You do not need a large security project to perform the first review.
Create a table with these columns:
| System | User account | Who has access | MFA | Owner |
|---|---|---|---|---|
| Microsoft 365 | marko@company.com | Marko | Yes | IT |
| Hosting | admin | Marko, Ivan | Yes | IT |
| Router | admin | ? | No | ? |
| WordPress | admin | Marko, Ivan | No | Marketing |
| CRM | individual accounts | Sales | Yes | Sales |
Very quickly, the problematic areas become visible.
Pay particular attention to accounts where the answer to:
“Who has access?”
is effectively:
“We are not sure.”
Red flags
If you recognise several of these, a broader review is worth doing:
- several people use the same administrator account
- passwords are sent through WhatsApp or email
- former employees once knew shared passwords
- the same password is used across several systems
- administrator accounts do not use MFA
- nobody knows who owns a particular service
- access rights are not documented
- a password cannot be changed because nobody knows what depends on it
- critical passwords are stored in Excel or Word files
- external contractors use the same accounts as employees
One item does not automatically mean the environment is unsafe.
Several of these warning signs together are a good reason to review and organise access systematically.
What would I fix first?
You do not need to solve everything in one day.
Start in order.
1. List the critical systems
Start with:
- cloud services
- firewall
- VPN
- hosting
- domains
- servers
- backup
- business applications
2. Determine who has access
If you cannot answer that question, that is the first problem.
3. Introduce individual user accounts
Wherever the system supports them.
4. Enable MFA
Prioritise:
- administrator accounts
- cloud services
- VPN
- hosting
- critical business services
5. Store shared secrets in a password manager
Not in chat.
Not in Excel.
Not on a note under a keyboard.
6. Define an offboarding process
When somebody leaves the company, there should be a clear list of the access that must be removed.
The most important question is not how strong the password is
A 30-character password does not solve much if twelve people know it.
Good access management means that at any point you can answer three questions:
Who has access?
What do they have access to?
Why do they still have it?
If the answer to any of those is “probably”, the environment is worth reviewing.
Quick check
Choose just one critical system in your company.
For example:
- hosting
- Microsoft 365
- firewall
- backup
Now try to answer, without guessing:
“Who can sign in to it today?”
If you cannot determine that within a few minutes, you have just found the first place worth cleaning up.
Sources and further reading
- NIST — How Do I Create a Good Password? NIST guidance on long and unique passwords, password managers and multifactor authentication.
- NIST SP 800-63B — Authentication and Authenticator Management NIST's technical requirements and guidance for passwords, authenticators, password managers and authentication management.
- CISA — Require Multifactor Authentication CISA guidance for deploying MFA across business accounts, especially administrative access, email, file storage and remote access.
Related service
Cybersecurity and IT system security
Review of user and administrator access, multi-factor authentication, security configuration, documentation and reduction of unnecessary privileges across business IT environments.
Cyber security and penetration testingDealing with a problem like this?
Describe the situation and we will suggest the first sensible step. If it can be solved without us, we will tell you that too.