Small Business Data Security: Protecting Passwords & Access
Losing access to digital accounts can seriously disrupt your business and compromise data security. Understand key log-ins to track, how to reduce cyber security risks and what to do if you do lose access.
The risks of losing track of log-ins and passwords
Secure digital access management is crucial for businesses of all sizes. Imagine a staff member leaves suddenly and you realise that no one else in the business knows some key passwords.
Small and medium-sized enterprises (SMEs) may have simpler needs than larger companies. However, they still face data security risks if they manage their digital accounts poorly.
Having the right security measures in place is crucial. Yet almost a third of SMEs have no cyber security at all.
Many small businesses think they’re too small to attract the interest of hackers. However, 50% of small businesses and 67% of medium businesses reported at least one cyber security attack within the last 12 months. Hackers know that SMEs are likely to be less prepared for an attack, so there is a higher chance of success.
We explain why securing your digital accounts is so important and the key ones to track. We help you understand the risks of losing access, including the worst case scenarios. We also offer tips on the best ways to protect your business’s log-ins, plus what to do if you do lose access.
Common SME data security risks
- Shared credentials – everyone using the same single log-in
- No offboarding process when someone leaves the business
- Insecure password storage – e.g. sticky notes!
- Poor understanding of GDPR obligations
The true cost of poor data security for small businesses
Average cost per cyber
security incident
Average GDPR fine
for SMEs
Average cost of cleaning
up a data breach
Why good digital access management is vital
Data & Cyber Security
Cyber security is one of the biggest risks for modern businesses and SMEs are often more vulnerable to cyber threats. They’re less likely to have full-time IT support or be able to weather the costs of fixing issues.
Modern cyber criminals use a wide range of tactics. Your company’s sensitive information could be targeted by phishing, malware (malicious software), identity theft or other scams that compromise your accounts and passwords. 85% of all businesses have experienced phishing attacks and SME employees often aren’t trained to spot cyber security scams.
Attackers may try to steal data or prevent you from gaining access to vital systems. Ransomware attacks have become increasingly common. After gaining access, data and files are remotely encrypted. The attackers then demand money to restore access. On average, it takes 35.5 hours from first access to ransomware deployment.
You could also become a victim of a data leak or unauthorised access. You could be targeted by former employees – or even dissatisfied current ones. The average cost of clearing up a data breach is over £25,000 for small businesses. These are real risks that you need to mitigate.
Legal compliance and data protection
GDPR legislation was brought in to make businesses more accountable for protecting and processing personal data. You should have conducted a GDPR risk assessment so you can understand your vulnerabilities. Part of complying with GDPR also means you should be continually monitoring and adapting your data management.
You can’t afford to ignore factors like digital access that have the potential to lead to data breaches. This puts your own and your customers’ data at risk. Without suitable safeguards in place, you could be liable for significant GDPR fines. These can be up to €20 million or 4% of global turnover, which can have a huge impact on a business.
Think you’re too small to be prosecuted? In recent years, GDPR enforcement has increasingly started to focus on SMEs. 40% of enforcement action was made up of SMEs in 2025, increasing from 25% in 2024. The average SME fine was £85,000, with the most common failure being poor cyber security leading to data breaches.
Business continuity
Losing access is, quite bluntly, a pain in the neck. Being unable to log-in to your social media accounts or tools like Canva for a short while can be frustrating enough. But being locked out of important business assets like your website and emails can bring your business to a standstill. Recovering lost access can be tricky, costing you time and money.
Your company’s reputation
You can’t buy a reputation. Your customers’ trust can be the hardest thing to recover if you experience issues with digital access control. Failing to respond to customer queries or problems and being unable to process orders all impact your reputation.
Whether it’s a cyber attack or poor handling of personal data, cyber security issues have a measurable impact on your customers. 47% of organisations report considerable challenges in attracting new customers after a cyber attack. 43% lost customers and 38% experienced bad publicity for their business.
Clarity and control
Knowing who has access to what makes day-to-day business easier. If the person who normally updates the website is on holiday and you suddenly need an urgent change, you should know who can do it. If someone leaves the business, you need to know what account access to update.
This can often become a bigger issue when businesses start to grow. If your company goes from 2-3 people to 10-15, it might have been easy to check with 1-2 people but now you have to check with 10+…
How to protect your business’s cyber security
Only give as much access as needed
The more people with access, the higher the risk. Many systems enable you to choose the type of access you grant to different people. Role-based access can help ensure that only certain staff can edit files. Different types of permissions can also be useful if you need to give someone temporary access.
For instance, for Facebook pages, Moderators can post to pages and respond to comments. However, only Admins have overall control over a page. Google Drive offers 4 levels of access: Owner (stored on their drive), Editor (organise, add and edit files), Commenter (add comments to documents) and Viewer (just view). You can set these at both folder and document level.
The meaning of these different access types varies across platforms, so make sure you understand what each one means.
Ensure key people have ‘owner’ privileges
If an agency or freelancer has set up accounts for you, they may have set themselves up with account ‘owner’ privileges. This can be challenging if you stop working with them and need to make changes. You may find you only have something like ‘editor’ access and can do almost everything, but not quite.
This isn’t usually done with any bad intent. It’s often simply because when someone is setting up accounts they will need to click on confirmation emails. They will have used their own email address because they have access to those emails. This makes setting up easier and quicker.
Ideally, they should set up the accounts alongside you so you have ownership from the start. If that’s not possible, make sure they transfer ownership to you at some point.
Manage shared data access securely
Password management systems
Password managers help you keep track of passwords, as well as ensuring secure passwords. You create a master password for your account, which gives you access to your password ‘vault’.
Most password managers work automatically: when you log in somewhere for the first time, the manager offers to save your details to the vault. Next time you log in, it can add the details automatically.
- LastPass
- 1Password
- NordPass
Explore some of the best password managers for businesses.
2 factor authentication
2 factor authentication (often abbreviated to 2FA) gives your accounts an extra layer of security. It’s optional for some things but increasingly it’s being made compulsory. It’s recommended you use it to protect your data security more effectively.
As well as using a password, you will usually be sent a code (either to your phone or your email) and enter that to log in.
Use specific business accounts – not personal ones
It’s common for people who started as sole traders to use their personal email account and phone number for their businesses. But it’s an added data security risk: if your personal account is compromised, then your business will be as well.
It may have simply seemed easier initially, especially if your early clients were personal referrals. Yet you probably only have one personal account and use it for everything, from your utility bills to your social media accounts. If you don’t already, start making everything separate to reduce your risk.
Train staff on data security
How confident are you that your staff could spot a fake email that’s designed to look like it’s from the managing director? And did you know that 9 in 10 data breaches are caused by human error?
Only a third of small businesses provided staff training on cybersecurity in the last 12 months. Yet it’s the most common preventative measure that businesses take after a data breach.
It’s important to keep training and awareness around data security up to date. This shouldn’t be a one-off – it’s an ongoing part of keeping your business and its assets secure. This should cover:
- Understanding legal requirements
- How to identify and report potential breaches
- How to handle subject rights requests correctly
- Specific risks related to their role
Have a review schedule
Set calendar reminders to review your company’s different types of digital access every 3-6 months. This will help you keep on top of everything.
You should keep an access log that lists:
- Accounts or platforms
- Who has access
- Level of access
- When this was last reviewed or updated
- When it should be reviewed next
Additional key times to review access:
- A confirmed data breach or some suspicious activity
- Merging or restructuring the business
- Adding a new platform or account type
- When someone leaves your business
- When you switch marketing agencies
- When you change developer or web designer
- Changing hosting provider or domain registrar
Prepare for emergencies
Have at least two trusted people with full access to vital account log-ins in case of an emergency.
If someone left your business with immediate effect, you need to know you still have crucial account access. Unpleasant as the subject may be, planning for a key person’s sudden death, illness or accident is also important. In difficult circumstances, recovering access can add extra stress, as well as being time consuming.
Some platforms have processes in place for handling a deceased person’s account. However, this is another reason for using company email addresses. They make it far easier to pass on control if needed.
Check for data breaches
Use your review schedule to check if your data may have appeared in any breaches. You can use HaveIBeenPwned to see if personal data like email addresses and passwords have been compromised in any data breaches.
Who can help small businesses if you lose access to crucial accounts?
Us! We’ve compiled a list of key log-ins and passwords to track for data security, with tips on how to get access back. However, we understand that the processes can sometimes be difficult to navigate if you’re unfamiliar with them. Sometimes, it can feel like you’re hitting a brick wall just trying to speak to a real person. If you’re struggling, get in touch with us – we’ve helped numerous clients get back into various accounts over the years. We’re used to troubleshooting issues and often know the quickest way to get your access back.
Key Log-Ins & Passwords To Track
Jump to:
Website and hosting
- Domain (GoDaddy, 123 Reg, Squarespace)
- Hosting
- CMS (WordPress, Wix etc.)
Review frequency
Quarterly
What’s the risk?
– Single log-in for multiple systems
– Credentials known only to web designer or developer
– Expired domain or DNS hijack
What’s the worst that could happen?
– Your website goes down or gets hijacked
– Domain lost or redirected
– Loss of online reputation and sales
I’ve lost access! How do I get it back?
– Contact host or registrar with proof of domain ownership
– Request account recovery via WHOIS contact email
– Maintain shared documentation of log-in and DNS details securely
Email and communication
- Email system
- Newsletters (e.g. MailChimp)
Review frequency
Every 6 months
What’s the risk?
– Single accounts lost
– 2FA linked to personal phones
– Former staff retaining access
What’s the worst that could happen?
– Business emails inaccessible
– Files and backups locked
– Client communications halted
I’ve lost access! How do I get it back?
– Contact platform support with proof of ownership (e.g. domain registration, business ID)
– Verify domain ownership via DNS
– Set up secondary admin accounts and recovery emails going forward
- GTM
- GA4
- Google Ads
- Search Console
- Google My Business
- Google Drive
Review frequency
Quarterly
What’s the risk?
– Account owner leaves
– Billing info inaccessible
– Poor role management
What’s the worst that could happen?
– Campaigns paused
– Ad spend wasted
– Files and backups locked
I’ve lost access! How do I get it back?
– Contact ad platform support (use billing records and company proof)
– Transfer ownership to new admin
– Store billing and campaign info in a shared encrypted location
Social media accounts
- Facebook Page
- Meta Business Manager
- Insta
- Twitter/X
- TikTok
- YouTube
Review frequency
Quarterly
What’s the risk?
– Managed via personal profiles
– No shared admin roles
– 2FA device is lost
What’s the worst that could happen?
– Brand hijacking and malicious posts
– Unable to update or communicate with customers
– Permanent account access loss
I’ve lost access! How do I get it back?
– Use the platform’s recovery form process
– Reclaim pages through a linked business email
– Always have two admins per platform and enable Business Manager tools where possible
CRMs & databases
- HubSport
- Salesforce
Review frequency
Quarterly
What’s the risk?
– Shared logins with ex-staff
– No audit of user permissions
– Weak passwords
What’s the worst that could happen?
– Data theft (customer emails, leads)
– Breach of GDPR or client confidentiality
– Loss of pipeline visibility
I’ve lost access! How do I get it back?
– Use recovery channels like email verification
– Immediately reset all user passwords
– Enable 2FA and restrict IP access if possible
E-commerce & payment tools
- Shopify
- WooCommerce
- PayPal
Review frequency
Quarterly
What’s the risk?
– Admin leaves with credentials
– 2FA linked to personal phone
– API keys exposed
What’s the worst that could happen?
– Store offline or hacked
– Payments frozen
– Customer trust loss
I’ve lost access! How do I get it back?
– Contact support with proof of ownership (bank account, ID, business registration)
– Transfer admin access
– Set up shared secure credentials via password manager
Accounting & HR tools
- QuickBooks
- Sage
- BrightHR
Review frequency
Quarterly
What’s the risk?
– Password or 2FA tied to one user
– Login stored locally only
– No recovery setup
What’s the worst that could happen?
– Inability to run payroll or issue invoices
– Missed tax deadlines
– Financial data exposure
I’ve lost access! How do I get it back?
– Contact provider for account recovery
– Verify company identity (bank statement, tax ID)
– Set up dual admins and secure 2FA-based access
Are you looking for a marketing agency to partner with?
You might also like
You’ve probably noticed how hard it is to get people to fill in forms or pick up the phone these days. Everyone wants instant replies, or to share pictures and drawings quickly.
How to Add WhatsApp or SMS to Your Google Business Profile (with Working Examples) Want customers to message you directly from Google Search or Maps? You can now add WhatsApp or text messaging (SMS) to Read more...
If you run a business, you know how important it is to respond to potential customers quickly. But when messages come in from WhatsApp, Facebook Messenger, Instagram, and other platforms, it’s easy to lose track. Read more...