PROTECT · ACCESS & PASSWORDS
Access & Passwords — Who Can Get Into Your Business Systems?
Passwords matter, but the bigger question is access: who can get into your systems, what can they do and do they still need that permission?
Accounts are digital keys
An account can provide access to email, customer information, finance systems, cloud storage and administration tools. Some accounts open one door. Others can open almost everything.
That is why access security is about more than telling people to choose better passwords.
Give people the access they need — not every access they might need
People should have enough access to do their jobs without accumulating unnecessary permissions. Extra access creates extra consequences if an account is compromised or misused.
This is especially important for administrator accounts, finance systems and services containing sensitive or valuable information.
Access changes when the business changes
People join, move roles, work with suppliers and eventually leave. Permissions that were correct six months ago may no longer make sense.
A simple joiner, mover and leaver process helps the business create access when it is needed, adjust it when responsibilities change and remove it promptly when it is no longer required.
Make passwords harder to misuse
Important accounts should use strong, unique passwords rather than reusing the same password across services. A password manager can help people create and store unique credentials without relying on memory.
Where available and appropriate, multi-factor authentication adds another barrier so that a stolen password alone may not be enough to enter the account.
Shared accounts hide responsibility
When several people use the same login, it becomes harder to know who did what, remove one person’s access or investigate unusual activity. Individual accounts are usually easier to control and review.
BOI ACTION
Review access to one important system.
Choose email, finance, cloud storage or another service the business depends on. Look at the current users and ask: Does each person still need access? Does anyone have more permission than their role requires? Are there old, shared or unexplained accounts?
Record anything that needs to change and give the action an owner.
A useful question for the business
If an important account were compromised today, how much of the business could somebody reach?
Don’t assume. Check.
An account that exists is not necessarily an account that should exist. Review access deliberately, particularly when people and responsibilities change.
NOT SURE WHERE TO START?
Take the 15-Minute Business Security Check
Ten straightforward questions will help you identify three priorities for sensible action.
Useful guidance
Final publication QA will verify current UK-first account, password and access-control guidance and supporting authoritative sources.
Continue exploring
Strong passwords are useful, but important accounts need another layer when a password is stolen.
Explore the Cyber Security Guides →
Found something that may be outdated or incorrect? Let us know.
Better Decisions. Stronger Organisations.
Understand what matters. Take sensible action. Check whether it worked.