Small Business Security
What to Do If a Former Employee Knows a Business Password
If a former employee knows a shared business password, the account should be treated as exposed. This guide explains how small businesses can rotate credentials, review access, and move toward individual accounts.
Treat shared business passwords as exposed
If a former employee knows a business password, change it immediately and review account access. This is especially urgent for email, payment tools, social media, cloud storage, website hosting, accounting, payroll, customer lists, and admin accounts.
You do not need to assume bad intent. The issue is that a person who no longer needs access still knows a credential. That creates unnecessary risk for the business and customers.
The better long-term fix is to stop sharing passwords and use individual accounts with roles and MFA wherever possible.
Why shared passwords create business risk
Shared passwords make it hard to know who did what, hard to revoke one person, and easy for old access to persist. If the password is reused across services, one departure can require many changes.
CISA recommends MFA and account security practices for small and medium businesses. Individual accounts and MFA make access easier to manage.
Shared passwords are especially risky when sent by email, text, chat, or stored in shared documents.
- No clear audit trail.
- Difficult offboarding.
- Password reuse across tools.
- Saved sessions on old devices.
- Former access to customer data.
- Risk of accidental or intentional misuse.
Identify every affected account
List the accounts the former employee could access. Include obvious tools and hidden dependencies: email aliases, domain registrar, hosting, Stripe or payment dashboards, social media, ad accounts, analytics, file storage, CRM, and support inboxes.
If the account stores customer data, payment information, or credentials, prioritize it first.
Rotate passwords and revoke sessions
Change affected passwords from a trusted admin account. Use unique passwords and store them in a business password manager. Sign out all sessions where possible.
Remove saved devices, app passwords, API tokens, and connected apps the former employee used.
- Change shared passwords.
- Revoke sessions.
- Remove devices.
- Rotate API keys where needed.
- Remove connected apps.
- Update recovery email and phone.
Move to individual access
Create separate user accounts with the minimum role needed. Disable the former employee's account instead of changing a shared password every time someone leaves.
Use MFA for admin accounts and high-value tools.
Review email and forwarding
Check shared inboxes for delegates, forwarding rules, filters, and connected apps. Unknown rules can leak customer messages or hide alerts.
Microsoft guidance for compromised mailboxes highlights rules and forwarding as important review points.
Check customer and financial exposure
If customer data, invoices, payment tools, or bank details may have been exposed, document what happened and consult appropriate legal, security, or compliance support.
Do not make claims to customers without facts. Preserve logs where available.
Create an offboarding checklist
Use a repeatable checklist for future departures: disable accounts, rotate shared secrets, collect devices, revoke sessions, remove groups, update recovery methods, and review admin logs.
The goal is controlled access, not emergency cleanup every time.
Frequently asked questions
Do I need to change passwords if the employee left on good terms?
Yes for shared passwords. Offboarding is about access control, not accusing anyone.
Should every employee have a separate account?
Wherever possible, yes. Individual accounts make revocation and audit trails much cleaner.
Should I rotate API keys too?
Yes if the former employee had access to them or systems where they were stored.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
