Somebody quits, you throw a small goodbye lunch, and life moves on. Six months later that person can still log into your store's admin panel, your email marketing tool, and the shared Dropbox with your customer exports. Nobody did anything wrong on purpose — nobody did anything at all. That's the problem.
The account nobody closed
Old accounts are perfect for attackers because no one is watching them. The person who owned the login isn't checking for strange activity, and you've forgotten it exists. If that ex-employee reuses passwords and gets caught in an unrelated breach, their still-active credentials to your systems go up for sale with them.
It doesn't require malice from the former employee. Most damage from stale accounts comes from third parties who compromise them — the departed staffer never knows their old login was the way in.
Shared passwords make it worse
Many small teams run on one shared login for the website, one for social media, one for the payment dashboard. When a person leaves, revoking their access means changing every shared password — and telling everyone else the new one. In practice, this step gets skipped because it's annoying. A password manager with individual accounts fixes this permanently: you remove one person, everyone else keeps working.
Contractors are employees too
The freelance developer who fixed your checkout in 2023 may still have FTP access, a database password, and an admin account named after their agency. Contractors accumulate deeper access than employees — they're often handed the keys to everything to get a job done fast — and they're almost never offboarded because there's no HR moment to trigger it.
The 20-minute offboarding checklist
- Disable their accounts on the website, hosting panel, email, and payment tools — disable first, delete after 30 days
- Rotate any password they shared: Wi-Fi, social media, hosting root, API keys
- Remove their email forwarding rules and recovery addresses from shared accounts
- Check for personal devices with saved sessions — force a logout everywhere the tool allows
- Search your admin user list for names you don't recognize while you're in there
Make it a habit, not a memory test
Write the checklist down and run it the day someone leaves, on good terms or bad. Then, twice a year, review every account with access to your site and ask one question per name: does this person still work here, and do they still need this? Access should expire the way milk does — on a date, not when someone finally smells a problem.
Trust Guard's ongoing monitoring watches your site for the unexpected changes a misused old account leaves behind, so a forgotten login doesn't get to become a quiet breach.
Comments
No comments yet. Be the first to share your thoughts!