Kit
Start free

Passwords, two-step verification and leavers for small firms

The three account habits that stop most break-ins at a small business: one strong password per account, two-step verification, and removing access when staff leave.

Small team around a laptop in a meeting

Most break-ins at a small business do not involve clever code. They involve a password that was reused from a personal email, a shared login written on the wall behind the counter, or a former employee whose access nobody removed. The fixes are known, they are free, and two national cyber security agencies describe them in almost the same words.

One strong password per account

The UK National Cyber Security Centre's guide for small organisations says each important account needs "a strong password that you don't use for any other account", and that "if you have reused passwords across business-critical accounts, you should change them as soon as possible". The business accounts that matter most are the ones that can move money or reach everything else: the email account that receives password resets, mobile money and bank logins, the point of sale administrator account, and the social media pages that carry the shop's name.

For the password itself, the NCSC suggests "combining three random words to create a password (for example fishapplesing)". Three unrelated words are long enough to resist guessing and easy enough to type on a till keyboard. A password manager removes the need to remember them at all; the agency points to its own guidance on managers and passkeys and says that where passkeys are available you should enable them for business-critical accounts as a priority.

Turn on two-step verification

A password alone is one lock. Two-step verification adds a second: a code from an app, a prompt on a phone or a physical key. The NCSC calls turning on 2SV "one of the most effective ways to protect online accounts when passwords are still in use" and adds that "any type of 2SV is better than none". The US Cybersecurity and Infrastructure Security Agency ranks the methods: physical security keys give "the best protection against phishing", authenticator apps come next, and codes sent by text or email offer "the weakest protection". Its advice to businesses is to turn it on everywhere possible, "beginning with admin accounts, remote access, and staff handling sensitive data".

Start with the email account that would be used to reset every other password. Then mobile money and banking. Then the administrator account of your business software.

Shared logins are not logins

A single till login shared by three cashiers tells you nothing about who made the sale or who gave the discount, and it cannot be revoked for one person without locking out the others. Every member of staff should have their own account, with only the permissions their role needs. The NCSC's device advice says the same about computers: create a separate standard user account for day-to-day work and keep administrator access for when it is needed.

A related habit is signing out. A till left logged in as the manager hands the manager's permissions to whoever is at the counter next.

Leavers, suppliers and contractors

Accounts outlive the people who used them. The NCSC notes that accounts for ex-staff, suppliers or contractors often remain active and says "you should remove or disable the accounts you no longer use", with a tip to "review who has access to important accounts every few months, and remove anyone who no longer needs it". Add this to the leaving checklist alongside the keys and the uniform: email, point of sale, mobile money agent lines, social media, the Wi-Fi password and the alarm code.

Devices carry the accounts

A strong password is undone by a phone with no screen lock. The NCSC recommends "a 6-digit PIN or a strong password to prevent unauthorised people accessing your device", a different one for each device, and keeping devices updated because updates fix "bugs in software that criminals could use to hack your device". Only install apps from official stores.

A one-hour plan

Step Time
Change any reused password on email, money and admin accounts 20 minutes
Turn on two-step verification for those accounts 15 minutes
Give every staff member their own login and remove shared ones 15 minutes
List accounts held by former staff and suppliers; remove them 10 minutes

Diarise the last step for every quarter. Account hygiene is not a project with an end date; it is a habit with a short checklist, and it costs nothing but the hour.

Sources

  1. https://www.ncsc.gov.uk/collection/small-organisations-guide-to-cyber-security/secure-your-important-online-accounts
  2. https://www.ncsc.gov.uk/collection/small-organisations-guide-to-cyber-security/protecting-your-devices
  3. https://www.cisa.gov/secure-our-world/require-multifactor-authentication

Run the whole business from one login.

Point of sale, stock, CRM, accounting free in every plan, payroll and Kit AI. Start on the web today and add the till, the phone app and the desktop app as you grow.

No card needed · 14-day trial