Login security for small businesses: a practical plan
Protect your team's accounts with SSO, mandatory MFA and a team password manager. A short plan with offboarding, admin rules and a note on NIS2 for small firms.
Login securityPublished
A small business can cover most login risk with four habits: mandatory multi-factor authentication, a team password manager, single sign-on where your tools support it and a tidy routine for people joining and leaving. Add stronger, phishing-resistant sign-in for administrators and finance, and keep a written list of who has access to what.
Why logins are the main target
Attackers rarely break complicated systems when a stolen or guessed password will do. A reused password, a phished email login or an old employee account that was never closed is the usual way in. These are habits you can fix without a large budget.
The five-part plan
1. Take inventory
List every business account: email, accounting, banking, cloud storage, CRM, social media, domain registrar and website admin. Note who owns each, who has access and whether MFA is on. You cannot protect what you have not listed.
2. Require MFA everywhere it matters
Make two-factor or multi-factor authentication mandatory, starting with email, the admin consoles, the domain registrar and banking. Move administrators and finance staff to phishing-resistant MFA, meaning passkeys or hardware security keys. Treat SMS codes as a fallback, not the plan.
3. Give the team a password manager
A business plan gives each person a private vault, shared vaults for team logins, an admin console and an audit trail. Our review of password managers for business compares options. Pair it with the habits in strong passwords in 2026: long, unique, and no forced rotation.
4. Add single sign-on when you grow
Single sign-on lets staff sign in to many tools through one identity provider you control, so MFA and access rules live in one place. Common standards behind it are SAML and OpenID Connect, and SCIM automates creating and removing accounts. Not every small tool supports SSO on its cheapest plan, so check the pricing page before you plan around it.
5. Offboard people properly
A leaver checklist should cover: disable the SSO or primary account, rotate shared passwords, remove them from shared vaults, revoke tokens and devices, transfer ownership of documents and forward mail where appropriate. Do the reverse for new joiners, giving access by role rather than by request.
Admin and access rules
- Keep admin accounts separate from daily accounts, and use as few as you need.
- Give least privilege: people see only what their job needs.
- Name a backup administrator and store break-glass credentials offline, so a lost phone does not lock the company out. The ideas in account recovery apply to business accounts too.
- Review access twice a year, and when roles change.
- Avoid shared logins. Where unavoidable, put them in a shared vault and note who uses them.
What about NIS2?
The EU’s NIS2 directive (Directive (EU) 2022/2555) sets cybersecurity risk-management duties for entities in listed sectors. Article 21 names the use of multi-factor or continuous authentication among the measures. In general it targets medium and large entities in those sectors, with some exceptions regardless of size, so many small businesses are not directly in scope, though they can face requirements as suppliers to customers who are. Member states implement the directive through national law, and the details and deadlines differ, so check your national authority or an adviser (status as of October 2026). Even if you are out of scope, the measures above are a sensible baseline. This page is general information, not legal advice.
A 30-day starter plan
| Week | Do |
|---|---|
| 1 | Inventory accounts, secure email and domain registrar with MFA |
| 2 | Roll out the team password manager, replace reused passwords |
| 3 | Move admins and finance to passkeys or security keys |
| 4 | Write the onboarding and offboarding checklist, set up recovery |
Training without scare tactics
Short, regular examples work better than long courses: one real phishing message each quarter, a reminder to check the sender and web address, and a clear way to report a suspicious email without blame.
Typical small-business mistakes
- One shared email login for the whole team. It cannot be protected with personal MFA and cannot show who did what.
- The owner is the only administrator. If they lose their phone, nobody can recover the accounts.
- Old accounts of former staff. They stay active for years because no one owns the offboarding task.
- MFA on some tools but not on email. Email resets everything else, so it comes first.
- Passwords in spreadsheets or chat. They are searchable, copied around and impossible to revoke.
Contractors, agencies and freelancers
External people need access too, and they are a frequent weak spot. Give them their own accounts instead of your login, restrict them to what the project needs and set an end date. Agencies that manage your website, advertising or domain should use your tools’ delegated-access features, so you can remove them with one click.
Devices and remote work
Login security does not stop at the account. Keep laptops and phones encrypted and updated, use a screen lock and have a plan for lost devices, including remote sign-out. If people use private devices for work, agree minimum rules, such as a passcode, updates and a separate work profile where available.
Where to learn more
Single sign-on and the standards behind it are explained in our pieces on SAML and SCIM. For the consumer side of the same ideas, see our guides to passkeys and account recovery.
Bottom line
Enforce MFA, give the team a password manager, centralise sign-in as you grow and offboard cleanly. These steps are affordable, and they remove most of the everyday ways accounts are lost.
Frequently asked questions
What is the most important login control for a small company?
Mandatory multi-factor authentication on email, the admin consoles of your cloud tools, banking and anything that holds customer data. Pair it with a team password manager so that strong, unique passwords are practical.
Do I need single sign-on with a small team?
Not at the start. A password manager and MFA go a long way. SSO becomes worth it when you have many tools and staff changes, because one central login makes MFA, access reviews and offboarding easier.
Does NIS2 apply to my small business?
The directive generally covers medium and large entities in sectors it lists, plus a few categories regardless of size. Many small businesses are not directly covered, but they can be affected as suppliers to covered customers. National laws differ, so check with your national authority or an adviser.
How do I handle shared accounts like social media or a company bank login?
Avoid shared personal logins. Where a shared account is unavoidable, store its credentials in a shared vault, protect it with MFA tied to a business device or security key and log who has access.
More in Login security
Account recovery: how to plan it before you need it
Locked out of Google, Apple or your email? Set up recovery options, backup codes and a trusted contact now, and test them, so a lost phone is an annoyance.
Account security for the whole family: a practical guide
Keep a household safe online: a shared password manager, 2FA for everyone, child accounts, help for parents and a simple plan if someone loses access.
Backup codes: what they are and where to keep them
Backup codes get you into an account when your phone or authenticator is gone. Learn how to generate them, where to store them safely and when to replace them.
Data breach: what to do now, step by step
Your email was in a breach? Check Have I Been Pwned or the HPI Identity Leak Checker, change the right passwords, switch on 2FA and watch for follow-up scams.
Fingerprint and face login: how safe is biometrics?
Fingerprint and face unlock are convenient and, used on your own device, quite safe. Learn how they work, where they fall short and how to set them up sensibly.
Hardware security keys explained: how they work
A hardware security key is a small device that proves it is you. Learn how FIDO2 keys work, what to look for, how to set one up and why you need a spare.