On this page
- 01Key takeaways
- 02Why do small teams share passwords?
- 03What are the risks?
- 04What does the NCSC recommend?
- 05How do you fix it?
- 06When is a shared login acceptable?
- 07Which shared logins matter most?
- 08What does a password manager cost and change?
- 09How does this work with an outside team?
- 10What mistakes are most common?
- 11What does this look like in practice?
- 12Password sharing checklist
- 13Next step
- 14Sources and further reading
- 15Frequently asked questions
Key takeaways
Sharing passwords at work happens when several people need one account and nobody has set up proper access. It removes accountability, makes it impossible to revoke one person's access, and leaves the business exposed when someone leaves. Individual logins, a password manager and two-step verification fix it.
- Shared logins mean no record of who did what.
- When 1 person leaves, every shared password should be changed.
- A password manager lets teams share access without revealing passwords.
- Turn on 2-step verification for email and banking first.
Passwords on sticky notes and in spreadsheets? Message us on WhatsApp.
Chat on WhatsApp →Why do small teams share passwords?
Small teams share passwords because it is the quickest way to give someone access. A tool was bought with one licence, a supplier portal allows one login, or the person who set up the account has left. With no one responsible for IT, the workaround becomes the system.
What are the risks?
The risks are loss of accountability and loss of control. If five people use one login, you cannot tell who made a change or a payment. You cannot remove one person's access without changing it for everyone, so in practice it is not changed. Passwords kept in spreadsheets, emails or chat can be read by anyone who gets into those.
- No audit trail for actions.
- Former staff retain access.
- One phishing success exposes everyone.
- Two-step verification is hard to use, so it gets switched off.
What does the NCSC recommend?
The National Cyber Security Centre publishes password guidance for organisations. It encourages reducing reliance on passwords, using password managers, and turning on two-step verification for important accounts, starting with email. Its Small Business Guide gives a short version suitable for firms with no IT staff.
How do you fix it?
Fix it in order of risk, starting with the accounts that would hurt most if misused.
- List every shared login and who uses it.
- Give individual accounts wherever the service allows.
- Put the remaining shared ones in a business password manager.
- Turn on two-step verification for email, banking and admin accounts.
- Change shared passwords whenever someone leaves.
- Keep two administrators on every critical system.
When is a shared login acceptable?
A shared login is acceptable when a service truly offers only one account, provided the password is stored in a password manager, access is limited to those who need it and it is changed when anyone leaves. It should be the exception and it should be recorded.
Which shared logins matter most?
Rank shared logins by what someone could do with them.
- Email: resets every other account.
- Online banking and payment platforms.
- Website and domain administration.
- Social media accounts.
- Accounting, payroll and CRM systems.
- Supplier portals holding payment details.
What does a password manager cost and change?
Business password managers typically cost a few pounds per user per month. For that, each person has one strong password to remember, shared logins sit in a vault with access granted by name, and removing someone takes a click. Staff stop keeping passwords in notebooks and spreadsheets because the manager fills them in automatically. For a team of ten the yearly cost is usually a few hundred pounds.
How does this work with an outside team?
Giving an outside team access should follow the same rules, more strictly. Each person should have a named account with only the permissions the task needs, two-step verification should be on, and activity should be logged. Avoid handing over a shared admin password. A provider who asks for individual, limited access is showing you how they treat security.
What mistakes are most common?
The usual mistakes are reusing one password across several systems, leaving former staff and old suppliers with access, registering business accounts to a personal email address and having a single administrator. Each is quick to fix, and together they account for most of the avoidable risk in a small business's logins.
What does this look like in practice?
A pattern we see in audits: one admin account for the website, shared by three people and a former agency, with a password unchanged for years. Nobody knows who last logged in. Setting up individual accounts takes less than an hour.
Password sharing checklist
Do this over a fortnight.
- Inventory shared logins.
- Create individual accounts where possible.
- Adopt a password manager.
- Enable two-step verification.
- Remove former staff and suppliers.
- Add a leaver step to change shared passwords.
Next step
If you are planning to give an outside team access to your systems, tell us what they would need. We will explain how role-based access and logging work in a 30-minute call.
Message us on WhatsApp about secure access for a managed team, or book a 30-minute consultation.
Chat on WhatsApp →Sources and further reading
- Password administration for system owners · National Cyber Security Centre
- Small Business Guide: cyber security · National Cyber Security Centre
- Cyber Essentials overview · National Cyber Security Centre
Frequently asked questions
Is it illegal to share passwords at work?
Not in itself, but it may breach a software licence or a supplier's terms, and it can undermine your duty under UK data protection law to keep personal data secure. It also makes it hard to show who accessed what if something goes wrong. Check the terms of the services you use.
What is the safest way to share a login?
Use a business password manager. It lets you grant and revoke access per person, often without revealing the password itself, and keeps a record. Never share passwords by email, chat or spreadsheet. Set one up before the next person joins or leaves. Most managers also flag weak or reused passwords.
Should every employee have their own login?
Yes, wherever the service allows it. Individual logins give an audit trail, let you set permissions by role and let you remove one person without disrupting everyone else. The extra licence cost is usually small compared with the risk. Budget for the extra licences.
What should I do about passwords when someone leaves?
Disable their individual accounts on their last day, change any shared passwords they knew, remove them from the password manager and check for accounts registered to their personal email. Build this into your leaver process. Do it the same day.
Written by

Global Bridge Labs (GBL) is a UK–Sri Lanka partner for social media, websites and BPO. Everything here comes from client delivery, not theory.




