Who still knows
your company password?

Maybe two people. Maybe ten. Or perhaps nobody is entirely sure anymore. A shared password that has been passed between employees for years can become a much bigger security problem than it first appears.

Published Reading time 6 min All guides

Who still knows your company password?

Maybe the answer is two people.

Maybe ten.

Or perhaps nobody is entirely sure anymore.

One of the more common security weaknesses in small and medium-sized businesses is not a sophisticated cyberattack.

It is something much simpler:

the same password being used by several people for years.

The Wi-Fi password.

An administrator account.

Hosting.

The router.

Social media.

A shared mailbox.

A business application.

Somebody created the password, sent it to a colleague and from that point onward it was simply passed along.

The problem starts when nobody knows exactly who still has it.

A shared password means you do not really have individual users

If five people sign in using:

admin

and all know the same password, the system technically knows that admin performed an action.

But it does not know which person did it.

If somebody:

  • changes a setting
  • deletes information
  • changes a configuration
  • downloads a file
  • creates another user

it may later be impossible to determine reliably who performed the action.

That is not only a security problem.

It is also a system management problem.

What happens when an employee leaves?

This is where shared passwords become particularly uncomfortable.

You disable:

  • Microsoft 365
  • VPN
  • company email
  • the user's computer access

and assume access has been closed.

But what if that person also knows:

  • the firewall administrator password
  • the WordPress administrator account
  • the hosting login
  • the Wi-Fi password
  • the domain registrar login
  • a shared business application account

Disabling their personal account changes none of those things.

They still know the credentials.

That is why an employee departure can require changing several shared passwords — and sometimes nobody has a complete list of what those passwords are. That is also why it matters to have a clear process for what IT should do when an employee leaves.

“But we are only a small team”

That is one of the most common reasons shared accounts appear.

Three people work together.

Everybody trusts one another.

Creating one account feels easier.

The problem is that companies rarely stay at three people forever.

Over time you may add:

  • new employees
  • external contractors
  • students
  • agencies
  • service providers
  • web developers
  • accounting partners
  • temporary workers

A password that originally belonged to two people can be known by ten people several years later.

And nobody has a complete record of who received it.

The worst passwords are the ones “nobody is allowed to change”

Older IT environments often contain at least one account or dependency like this.

For example:

“Do not change that password because we do not know what uses it.”

That is a strong sign of technical debt.

The credential may be used by:

  • an old service
  • a printer
  • an application
  • a backup script
  • network equipment
  • an automation

The dependencies were never documented, so the account became almost untouchable.

At that point, the security problem is no longer just the password.

The bigger problem is that nobody has a complete picture of the system.

An administrator account should not be your everyday account

Another common practice is for an administrator to use the same account for:

  • email
  • web browsing
  • everyday work
  • system administration

That unnecessarily increases risk.

Administrative privileges should be used when they are actually required.

For everyday work, the user should have a standard account and use a separate administrative identity for privileged tasks.

That reduces the chance that a single incident automatically receives the highest level of access.

Passwords in Excel are not a password manager

Many companies have something like:

passwords.xlsx

or:

passwords.docx

Sometimes the file is even stored on a shared network drive.

That is better than nobody knowing the passwords, but it is not a good access-management system.

A proper password manager allows much better control:

  • each user has their own account
  • access can be added and removed
  • the password itself does not need to be sent in a message
  • it is possible to track who has access
  • strong, unique passwords can be used
  • an employee leaving does not require reconstructing every credential

The important difference is that you share access rather than simply sharing the password.

Using one password for several services is an even bigger problem

For example, using the same password for:

  • hosting
  • email
  • cloud services
  • router administration
  • social media

If one of those services is compromised, an attacker gains a very good credential to try against the others.

Every important account should therefore have its own password.

Not variations such as:

Company2026!

Company2026!mail

Company2026!hosting

but genuinely separate passwords.

MFA does not replace good access management

Multi-factor authentication is extremely useful.

But it does not fix badly organised user accounts.

If five people use the same account, an obvious question appears:

Whose second factor is it?

Does one person receive every code?

Does everybody use the same device?

Is the code forwarded through chat?

That is a sign the account itself probably needs restructuring.

MFA works best when each user has an individual identity.

How to perform a quick access audit

You do not need a large security project to perform the first review.

Create a table with these columns:

System User account Who has access MFA Owner
Microsoft 365 marko@company.com Marko Yes IT
Hosting admin Marko, Ivan Yes IT
Router admin ? No ?
WordPress admin Marko, Ivan No Marketing
CRM individual accounts Sales Yes Sales

Very quickly, the problematic areas become visible.

Pay particular attention to accounts where the answer to:

“Who has access?”

is effectively:

“We are not sure.”

Red flags

If you recognise several of these, a broader review is worth doing:

  • several people use the same administrator account
  • passwords are sent through WhatsApp or email
  • former employees once knew shared passwords
  • the same password is used across several systems
  • administrator accounts do not use MFA
  • nobody knows who owns a particular service
  • access rights are not documented
  • a password cannot be changed because nobody knows what depends on it
  • critical passwords are stored in Excel or Word files
  • external contractors use the same accounts as employees

One item does not automatically mean the environment is unsafe.

Several of these warning signs together are a good reason to review and organise access systematically.

What would I fix first?

You do not need to solve everything in one day.

Start in order.

1. List the critical systems

Start with:

  • cloud services
  • email
  • firewall
  • VPN
  • hosting
  • domains
  • servers
  • backup
  • business applications

2. Determine who has access

If you cannot answer that question, that is the first problem.

3. Introduce individual user accounts

Wherever the system supports them.

4. Enable MFA

Prioritise:

  • administrator accounts
  • email
  • cloud services
  • VPN
  • hosting
  • critical business services

5. Store shared secrets in a password manager

Not in chat.

Not in Excel.

Not on a note under a keyboard.

6. Define an offboarding process

When somebody leaves the company, there should be a clear list of the access that must be removed.

The most important question is not how strong the password is

A 30-character password does not solve much if twelve people know it.

Good access management means that at any point you can answer three questions:

Who has access?

What do they have access to?

Why do they still have it?

If the answer to any of those is “probably”, the environment is worth reviewing.

Quick check

Choose just one critical system in your company.

For example:

  • hosting
  • Microsoft 365
  • firewall
  • backup

Now try to answer, without guessing:

“Who can sign in to it today?”

If you cannot determine that within a few minutes, you have just found the first place worth cleaning up.

Sources and further reading

Related service

Cybersecurity and IT system security

Review of user and administrator access, multi-factor authentication, security configuration, documentation and reduction of unnecessary privileges across business IT environments.

Cyber security and penetration testing

Dealing with a problem like this?

Describe the situation and we will suggest the first sensible step. If it can be solved without us, we will tell you that too.

Book a conversation