You're reading The SME Security Brief, practical IT, cyber security and technology advice for Irish and UK businesses. No jargon. No scare tactics. Just what you need to know, every week.

If someone forwarded this to you, you can subscribe at thesmesecuritybrief.com.

THIS WEEK'S THREAT 🔴

The person who left six months ago can probably still log in.

When most business owners think about cyber threats, they picture an external attacker. Someone trying to break in from the outside. And yes, that is a real risk. But the threats that actually cause the most damage in small businesses are far closer to home.

The employee who left on bad terms and still has access to the shared drive. The contractor whose Microsoft 365 account was never deactivated. The manager who left three months ago and whose laptop is sitting in a drawer at home, still connected to company systems. The current member of staff who uses the same password for everything and just clicked a link in a suspicious email.

None of these people are necessarily malicious. The ex employee might never log back in. The contractor might have moved on and forgotten the account exists. But the access is still there, and that means the risk is still there.

In a large organisation, IT has processes for this. There are offboarding checklists, automated account deprovisioning, device management systems. In a small business, offboarding often means handing back a key fob and hoping for the best.

The reality is that most SMEs have no idea how many active accounts they have, who has access to what, or when those accounts were last used. That is not a criticism, it is just the truth. Nobody set out to create this problem. It built up gradually, one account at a time, one leaver at a time.

The good news is that fixing it does not require a big budget or an IT team. It requires a process and about an afternoon of work.

What you should do this week:

  1. Make a list of everyone who has left your business in the last two years. Then check whether their Microsoft 365 accounts, email addresses, and any shared system access have been fully removed.

  2. If you use a shared password for anything, assume anyone who has ever worked for you still has it. Change it.

  3. The tip section below gives you a full leaver checklist to work through.

THIS WEEK'S TIP 💡

The leaver checklist every SME should have but almost none do.

When someone leaves your business, the clock starts immediately. Every day their access remains active is a day the risk exists. This is the checklist that should be completed on the last day of employment, not the week after.

Microsoft 365 and email
Disable the account in the Microsoft 365 Admin Centre on the last day. Do not delete it immediately, as you may need to access the mailbox, but disable it so they cannot log in. Set up an out-of-office or redirect the mailbox to a manager. Remove them from any distribution groups or shared mailboxes. Check if they had admin privileges and remove those first.

Devices
If they had a company device, retrieve it and wipe it before reassigning. If they used a personal device for work, any company data or email on that device is now outside your control. This is why a mobile device management policy matters, but at minimum, remove their account from any systems you can.

Shared passwords and accounts
Any shared account they had access to needs its password changed immediately. This includes social media accounts, shared email addresses, supplier portals, accounting software, and any other system where a single password is used by multiple people. Yes, all of them.

Cloud storage and file access
Check SharePoint, OneDrive, and any other cloud storage for files that were shared directly with their personal email address. Remove external sharing where possible. If they had access to Google Drive, Dropbox, or similar, revoke that access too.

Third party systems
Think through every system the person used. CRM, accounting software, project management tools, HR systems, supplier portals, banking platforms. Each one needs to be checked and access removed. Write this list down now, before you need it in a hurry.

VPN and remote access
If they had VPN access or any form of remote access to your network, revoke it on their last day. This is often the most overlooked step and one of the most dangerous to miss.

THIS WEEK'S TOOL 🛠️

How to audit your Microsoft 365 accounts right now.

Microsoft 365 is where most SME business happens, and it is also where forgotten access causes the most damage. Here is how to check what you actually have.

Check active users
In the Microsoft 365 Admin Centre, go to Users, then Active Users. This shows every account that currently exists. Look for anyone who should not be there, former staff, contractors, old test accounts. If you do not recognise a name, investigate it.

Check last sign-in date
This is the most useful column in that list. Sort by last sign-in date and look for accounts that have not been used in months. An account with no recent activity belonging to someone who left is a clear indicator that offboarding did not happen properly.

Check guest accounts
Go to Users, then Guest Users. These are external accounts that have been granted access to your Microsoft 365 environment, often through SharePoint or Teams. It is extremely common for this list to include people who worked with the business years ago and whose access was never removed.

Check admin accounts
Go to Roles, then Role Assignments. This shows everyone with elevated admin privileges. There should be as few admin accounts as possible, and every one of them should be active, named, and belonging to someone who genuinely needs that level of access.

Check enrolled devices
In the Microsoft Entra ID admin centre, under Devices, you can see every device that is registered to your tenant. If a former employee's laptop, phone, or tablet is still listed, it still has some level of connection to your environment. Remove any devices belonging to people who have left.

If this audit throws up accounts or devices you were not expecting, that is not unusual. Most businesses find things they did not know were there. The important thing is to deal with them now rather than waiting to find out the hard way.

QUICK COMPLIANCE CHECKLIST

Five questions to ask about your current team and recent leavers:

  1. Do you have a written offboarding checklist that is completed on the last day of employment for every leaver?

  2. Have all Microsoft 365 accounts for former staff been disabled or deleted?

  3. Have shared passwords been changed after every departure?

  4. Do you know which third party systems each member of your team has access to?

  5. Have you checked your Microsoft 365 guest user list in the last six months?

BEFORE YOU GO

The insider threat is not usually a disgruntled ex employee planning revenge. It is an account that nobody got around to closing. A shared password that never got changed. A personal device that went home with someone and never came back.

These are not dramatic security failures. They are the kind of thing that happens in every busy small business, when the priority is keeping the lights on and offboarding falls to the bottom of the list.

But the access does not care about your priorities. It stays open until someone closes it.

Take the afternoon. Run the audit. Build the checklist. It is one of the most valuable things you can do for the security of your business this week.

See you next week.

  • The SME Security Brief

Finding these useful? Forward it to a business owner who would benefit. It takes two seconds and could save them a serious headache.

You're receiving this because you subscribed at thesmesecuritybrief.com. To unsubscribe, click here.

If you find this newsletter useful and want to show your support, you can buy me a coffee. It genuinely means a lot and keeps this going. No pressure at all.