Access, Passwords and Accounts
The cheapest dependency to fix and the one most often left. An afternoon of work removes a category of risk entirely.
Relationships · Procedure
Knowledge takes months to spread. Access takes an afternoon, and it is frequently the thing that actually stops work when somebody is unavailable.
Putting the controls in “Access, Passwords and Accounts” into practice requires ownership that survives absence and can be reviewed without relying on memory. Teams can use the planning resource to see how responsibility and working time are distributed around recurring tasks, while keeping credentials and sensitive records in authorised systems and limiting activity data to a proportionate operational purpose.
For an independent benchmark, compare the local approach with CISA account security guidance; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.
What to find
Accounts registered to a personal email rather than a company one.
Systems where only one person has a login.
Two-factor codes on one person's phone.
Recovery addresses and phone numbers pointing at an individual.
Domain registration and hosting, which is the one that ends businesses.
And physical access: keys, alarm codes, safe combinations.
The domain and hosting case
Worth its own paragraph because the consequences are severe and the situation is common.
A domain registered to a former employee's personal account, or to a web developer who has disappeared, can be extremely difficult to recover.
Check today who owns your domain, who the registrant contact is, and whether the renewal card belongs to somebody still with you.
Fifteen minutes.
The fix
Company accounts for everything, with the organisation as the registrant and a shared recovery address.
A password manager with a shared vault, which solves the majority of this in one step.
Two-factor configured so that more than one person can generate codes, or with recovery codes stored somewhere reachable.
And a documented list of what exists, which is separate from the credentials themselves.
What to avoid
A spreadsheet of passwords in the shared drive, which trades one problem for a worse one.
Sharing one login between several people, which breaks accountability and is prohibited by many suppliers' terms.
And storing recovery codes only with the person whose account they recover.
The inventory
A list of systems, who has access, and what happens if that person is unavailable.
Not the credentials: the map.
Twenty lines for most small organisations, and it makes the gaps obvious immediately.
When somebody leaves
A list of what to revoke, prepared in advance rather than assembled in a hurry.
The same inventory serves both purposes, which is an argument for keeping it current.
And check the recovery addresses, which are routinely missed and which allow a former employee to reset a password months later.
Signing and financial access
Bank mandates, payment approvals, card authority.
These usually require the bank's process and take longer than the rest, which is a reason to start them rather than to defer.
Its own note covers signing authority more fully.
What to check
Who owns your domain, and is their card paying for it?
How many accounts are on a personal email address?
Whose phone holds two-factor for something critical?
And is there a list of what exists, separate from the passwords?
The point
Access takes an afternoon while knowledge takes months, which makes it the first thing to do.
Start with who owns your domain.
Underlying all of this
Everything in this collection reduces to four habits: know where the dependence sits, do the cheap fixes first, use the absences that already happen as rehearsals, and decide deliberately about what remains. None of it requires a framework, a tool or a consultant, and an organisation that does those four things consistently is substantially harder to damage than one with a succession document nobody has read.
The recurring pattern
The recurring pattern across every section here is the same: dependence forms through sensible individual decisions, becomes invisible because it feels like reliability, and is addressed only after it has cost something. The work that prevents that is small, continuous and unglamorous, which is exactly why it gets deferred.
Also in this section
Independent guidance on key-person risk, knowledge transfer and practical continuity for small organisations. External tools are compared as operational support; ownership, rehearsal and human judgement remain essential.