When cyber security is discussed, the conversation usually centres around ransomware, phishing emails and increasingly sophisticated cyber criminals. Those threats are real and deserve attention. However, some of the most common cyber security risks facing North West SMEs are often much less dramatic. They sit quietly in the background of day-to-day operations.
A shared mailbox that several employees access. A shared mailbox that several employees access. A Microsoft 365 account belonging to someone who left the business years ago. An old login that nobody wants to delete. A former manager who still has permissions they no longer need. Am employee who's changed role but retained access to systems they no longer use.
These situations are incredibly common and, on the surface, often seem harmless. In reality, they can create significant security risks that many businesses overlook because they've gradually become part of "the ways thing are done".
The challenge isn't usually malicious intent. It's lack of visibility. Many businesses simply don't know exactly who has access to what anymore.
Very few businesses deliberately create security weaknesses. Most access-related risks develop gradually as businesses grow. A business hired new staff. New software is introduced. Teams change structure. Employees move between departments. Additional Microsoft 365 licenses are added. Temporary permissions are granted to solve immediate problems.
Each individual devision makes sense at the time. The challenge is that access permissions often remain in place long after they are needed. Over months and years, businesses can accumulate dozens of unnecessary permissions, dormant accounts and shared access arrangements that nobody remembers creating. Because these risks develop slowly, they rarely attract attention.
Unlike a phishing attack or data breach, they don't generate immediate warning signs. Instead, they create vulnerabilities that may only become apparent after an incident has already occurred.
There is one simple question that every business leader should be able to answer confidently: Who currently has access to our systems, data and business information?
For many SMEs, the honest answer is "I'm not entirely sure". That uncertainty isn't unusual. As businesses grow, technology environments naturally become more complex. The issue is that uncertainty creates risk.
If a business cannot confidently identify who has access to important systems, it becomes far more difficult to:
Protect sensitive information
Meet cyber security requirements
Manage employee departures effectively
Detect unauthorised access
Investigate suspicious activity
Cyber security often begins with understanding who holds the digital keys to the business.
Shared accounts remain surprisingly common within SMEs. Often they exist for practical reasons. Customer service team may share a mailbox; finance teams may use common accounts to manage invoices; reception teams might have access to shared calendars and communications.
The problem isn't necessarily the mailbox or system itself. The risk arises when multiple people use the same credentials or when nobody actively manages who can access the account. If several employees share the same login, accountability can quickly disappear. If information is deleted, modified or shared externally, it may be difficult to identify who performed the action. If login credentials become compromised, detecting unusual activity becomes more challenging because multiple people are already using the account.
Modern Microsoft 365 environments provide much better ways to manage shared access than sharing usernames and passwords, but many SMEs continue using historic arrangements simply because they have always worked.
Until they don't.
One of the most revealing exercises during a security review is often the simplest. Review evert user account in the business and identify who still works there. Many businesses are surprised by what they find.
Former employees remain active because their email account contains useful information. Old user profiles are retained because they're connected to applications. Someone leaves, but nobody is completely sure what systems they had access to.
Again, these decisions are rarely made carelessly. The intention is usually operational inconvenience. However, user accounts that remain active long after someone leaves the business can become a significant security risk. They may not be monitored regularly; security settings may be outdated; multi-factor authentication may never have been enabled; passwords may not have been changed in years.
The longer dormant accounts remain in place, the harder they often become to manage.
One of the most overlooked aspects of cyber security is that growth often introduces risk.
As businesses expand, they naturally introduce:
Additional users
New devices
More software
Cloud applications
Temporary permissions
External contractors
New suppliers and partners
Very few businesses reduce complexity as they grow. Instead, access rights and permissions tend to accumulate. Without regular reviews, it becomes increasingly difficult to maintain visibility over who has access to what. For many North West SMEs, cyber risk is less about sophisticated attackers and more about accumulated complexity.
The challenge isn't a single poor decision. It's hundreds of small decisions made over the years.
User access management is becoming increasingly important from a governance perspective as well. Businesses pursuing Cyber Essentials certification, reviewing cyber insurance policies or working with larger customers are being asked more questions about access controls and account security.
Increasingly, stakeholders want assurance that businesses understand:
Who has access to business systems
How access is reviewed
What happens when employees leave
Whether multi-factor authentication is enabled
How privileged accounts are managed
Good security isn't just about technology. It's about demonstrating that security processes are understood and followed consistently.
Before investing in new security tools, start with a few simple questions:
These aren't technical questions. They're operational questions. And answering them often reveals some of the most effective cyber security improvements a business can make.
It's easy to focus on the latest cyber security threats because they're the stories that attract headlines. Yet some of the most significant risks facing SMEs come from issues that develop quietly in the background. Shared accounts, forgotten permissions and dormant user profiles rarely seem urgent. However, they can create exactly the kind of visibility gap that cyber criminals look to exploit.
The good news is that they are often among the easiest risks to address.
Before worrying about sophisticated attacks, it's worth making sure you know exactly who has access to the systems, data and information that keep your business running.
Cyber resilience doesn't always begin with new technology. Often it begins with better visibility.