Most small-business breaches don’t start with a brilliant hacker. They start with one weak password someone set two years ago and forgot. The mailbox that sends your invoices. The login to your hosting panel. The shared CRM account still used by a person who left in the spring. The question of how to protect your passwords and access sounds boring right up until the morning someone sends your clients fake payment details in your name — and they pay.

This article isn’t theory. It’s a checklist you can act on. Work through it once, calmly, and you’ll close 90% of what actually costs money and reputation. Here it is, point by point, most important first.

Two-factor auth where the money and data live

A password is “something you know.” It can be seen, guessed, phished out of you, or pulled from a leaked database of some other site where you reused it. A second factor (2FA) is “something you have” — a code in an authenticator app on your phone. Even if the password is stolen, no one gets in without that second factor.

Turn on 2FA first where the consequences are most expensive:

  • the owner’s and accountant’s email, both work and personal (email is the master key — password resets everywhere run through it);
  • online banking and any payment portals;
  • your domain and hosting panels — take these over and someone owns your whole site and mail;
  • social media and ad accounts that spend money;
  • CRM, accounting, and document storage.

One detail that matters: an authenticator app is safer than SMS. A SIM card can be reissued to a scammer with forged documents, and the code lands with them. And always save your backup recovery codes somewhere safe — otherwise losing your phone turns into losing access to your own business.

A password manager instead of a notebook and the same password everywhere

No human can invent and memorize two dozen different strong passwords. So in reality everyone does one of two things: reuses one or two favorite passwords everywhere, or keeps a list in a file, a chat, or on a sticky note under the keyboard. Both are exactly the hole your business leaks through.

The real answer to how to protect your passwords and access is a password manager. It’s an encrypted vault you unlock with one master password (plus a second factor), and it generates and fills in a unique, long password for every service. What that gives you in practice:

  • every account has its own password, so a leak on one site doesn’t drag the rest down with it;
  • nobody has to remember passwords — so they stop writing them in chats and on notes;
  • in a team you can grant access to a needed password without showing the person the password itself, and revoke it anytime;
  • you can see where your passwords are weak, old, or reused — and what to fix first.

The vault’s master password must be long and unique — one you use nowhere else. It’s the single password you actually have to remember.

One account, one person — no shared logins

The most common hidden trap in small business is shared accounts. One “for everyone” mailbox login. A CRM login three people know. The till password in a group chat. The problem isn’t only that such a password spreads fast. It’s that you lose accountability: when something gets deleted, a client database is leaked, or money goes to the wrong place — you can’t tell who did it.

The rule is simple: every employee gets their own named access. Then you can see who did what, disable one person without changing everyone else’s passwords, and give each person exactly the rights their job needs. A sales manager doesn’t need access to server settings. An accountant doesn’t need admin rights in the ad account. The fewer excess privileges, the smaller the surface for mistakes and abuse.

Cut off former staff — the same day

This is the point that “catches fire” most often, because it gets forgotten in the rush. Someone leaves — and their access stays alive. Email, CRM, shared drives, chats, the keys to the admin panel. Months later you sometimes discover a former employee can still see the client database, or worse, an outsider got in through their long-abandoned account.

Make revoking access a mandatory part of every offboarding — on the very day the person finishes:

  • block or delete their named accounts across all services;
  • change passwords wherever they might have known a shared login (and while you’re at it, retire shared logins as a category);
  • revoke their access in the password manager and to shared drives;
  • check whether any mailbox, domain, payment portal, or ad account is tied to them personally — and move it to the company.

The same applies to contractors and freelancers you once gave access “just this once.” Keep a simple list — who has access to what, and why. Review it once a quarter and remove what’s no longer needed. It’s fifteen minutes that saves you from the most expensive surprises.

Email and domain are the foundation — guard them separately

Another principle owners underrate: email and domain aren’t just “services on a list.” They’re the foundation everything else rests on. Password recovery for every account runs through your email. Control of your domain lets someone redirect your site and mail to themselves. So these two things deserve the strongest protection — a unique password, mandatory second factor, named access only for those who genuinely need it, and no shared login at all.

Separately, make sure the domain and hosting account is registered to the company or the owner personally — not to some contractor who once “helped with the website.” Otherwise, at the worst moment, you’ll find the key to your business is in someone else’s hands.

The checklist in short

Go through it and honestly mark what’s already done:

  • 2FA is on for email, banking, domain/hosting, social media, and key services;
  • backup recovery codes are saved somewhere safe;
  • all passwords live in a password manager, each unique, the master password reused nowhere;
  • no shared accounts — everyone has named access with the minimum rights they need;
  • revoking access is built into offboarding and happens the same day;
  • there’s a “who has access to what” list, reviewed once a quarter;
  • email and domain are registered to the company and protected most strongly.

If most of these are still blank, that’s a normal starting point — and the order to close them is exactly this: email and money first, everything else after.

At LPF we’ve been building and maintaining digital systems for Ukrainian businesses on our own infrastructure since 2018, so getting passwords and access in order is routine work for us. If you’d like someone to walk this checklist with you and close the gaps without stopping the business — start with a short conversation, and we’ll point out where to begin in your specific case.