The cyber risks nobody talks about: Shared accounts, former employees and forgotten logins
September 4, 2026 The cyber risks nobody talks about: Shared accounts, former employees and forgotten logins
in
Cyber Security ,
Sector Insights
News by Faizan Saqib
When cyber security is discussed, the conversation usually centres around ransomware, phishing emails and increasingly sophisticated cyber criminals. Those threats are real and deserve attention. However, some of the most common cyber security risks facing North West SMEs are often much less dramatic. They sit quietly in the background of day-to-day operations.
A shared mailbox that several employees access. A shared mailbox that several employees access. A Microsoft 365 account belonging to someone who left the business years ago. An old login that nobody wants to delete. A former manager who still has permissions they no longer need. Am employee who's changed role but retained access to systems they no longer use.
These situations are incredibly common and, on the surface, often seem harmless. In reality, they can create significant security risks that many businesses overlook because they've gradually become part of "the ways thing are done".
The challenge isn't usually malicious intent. It's lack of visibility. Many businesses simply don't know exactly who has access to what anymore.
Cyber security risks rarely appear overnight
Very few businesses deliberately create security weaknesses. Most access-related risks develop gradually as businesses grow. A business hired new staff. New software is introduced. Teams change structure. Employees move between departments. Additional Microsoft 365 licenses are added. Temporary permissions are granted to solve immediate problems.
Each individual devision makes sense at the time. The challenge is that access permissions often remain in place long after they are needed. Over months and years, businesses can accumulate dozens of unnecessary permissions, dormant accounts and shared access arrangements that nobody remembers creating. Because these risks develop slowly, they rarely attract attention.
Unlike a phishing attack or data breach, they don't generate immediate warning signs. Instead, they create vulnerabilities that may only become apparent after an incident has already occurred.
The question every SME should be able to answer
There is one simple question that every business leader should be able to answer confidently: Who currently has access to our systems, data and business information?
For many SMEs, the honest answer is "I'm not entirely sure". That uncertainty isn't unusual. As businesses grow, technology environments naturally become more complex. The issue is that uncertainty creates risk.
If a business cannot confidently identify who has access to important systems, it becomes far more difficult to:
-
Protect sensitive information
-
Meet cyber security requirements
-
Manage employee departures effectively
-
Detect unauthorised access
-
Investigate suspicious activity
Cyber security often begins with understanding who holds the digital keys to the business.
Shared accounts can create accountability problems
Shared accounts remain surprisingly common within SMEs. Often they exist for practical reasons. Customer service team may share a mailbox; finance teams may use common accounts to manage invoices; reception teams might have access to shared calendars and communications.
The problem isn't necessarily the mailbox or system itself. The risk arises when multiple people use the same credentials or when nobody actively manages who can access the account. If several employees share the same login, accountability can quickly disappear. If information is deleted, modified or shared externally, it may be difficult to identify who performed the action. If login credentials become compromised, detecting unusual activity becomes more challenging because multiple people are already using the account.
Modern Microsoft 365 environments provide much better ways to manage shared access than sharing usernames and passwords, but many SMEs continue using historic arrangements simply because they have always worked.
Until they don't.
Former employees can remain a security risk without anyone realising
One of the most revealing exercises during a security review is often the simplest. Review evert user account in the business and identify who still works there. Many businesses are surprised by what they find.
Former employees remain active because their email account contains useful information. Old user profiles are retained because they're connected to applications. Someone leaves, but nobody is completely sure what systems they had access to.
Again, these decisions are rarely made carelessly. The intention is usually operational inconvenience. However, user accounts that remain active long after someone leaves the business can become a significant security risk. They may not be monitored regularly; security settings may be outdated; multi-factor authentication may never have been enabled; passwords may not have been changed in years.
The longer dormant accounts remain in place, the harder they often become to manage.
Growth creates complexity
One of the most overlooked aspects of cyber security is that growth often introduces risk.
As businesses expand, they naturally introduce:
-
Additional users
-
New devices
-
More software
-
Cloud applications
-
Temporary permissions
-
External contractors
-
New suppliers and partners
Very few businesses reduce complexity as they grow. Instead, access rights and permissions tend to accumulate. Without regular reviews, it becomes increasingly difficult to maintain visibility over who has access to what. For many North West SMEs, cyber risk is less about sophisticated attackers and more about accumulated complexity.
The challenge isn't a single poor decision. It's hundreds of small decisions made over the years.
Cyber Essentials, cyber insurance and user access reviews
User access management is becoming increasingly important from a governance perspective as well. Businesses pursuing Cyber Essentials certification, reviewing cyber insurance policies or working with larger customers are being asked more questions about access controls and account security.
-
Increasingly, stakeholders want assurance that businesses understand:
-
Who has access to business systems
-
How access is reviewed
-
What happens when employees leave
-
Whether multi-factor authentication is enabled
-
How privileged accounts are managed
Good security isn't just about technology. It's about demonstrating that security processes are understood and followed consistently.
.png?width=1119&height=236&name=Get%20in%20touch%20with%20Apex%20email%20banner%20(29).png)
Five questions worth asking today
Before investing in new security tools, start with a few simple questions:
- Do you know every active account in your business?
- Are former employees removed from all systems promptly?
- Is multi-factor authentication enabled consistently?
- Are shared mailboxes managed securely?
- When was the last time user permissions were formally reviewed?
These aren't technical questions. They're operational questions. And answering them often reveals some of the most effective cyber security improvements a business can make.
Good cyber security starts with visibility
It's easy to focus on the latest cyber security threats because they're the stories that attract headlines. Yet some of the most significant risks facing SMEs come from issues that develop quietly in the background. Shared accounts, forgotten permissions and dormant user profiles rarely seem urgent. However, they can create exactly the kind of visibility gap that cyber criminals look to exploit.
The good news is that they are often among the easiest risks to address.
Before worrying about sophisticated attacks, it's worth making sure you know exactly who has access to the systems, data and information that keep your business running.
Cyber resilience doesn't always begin with new technology. Often it begins with better visibility.
.png?width=1119&height=236&name=Get%20in%20touch%20with%20Apex%20email%20banner%20(28).png)
.png?width=1119&height=236&name=Get%20in%20touch%20with%20Apex%20email%20banner%20(14).png)