25 Feb Absence makes the threat grow stronger!
Annual leave. Sick days. Maternity cover. Temporary contractors. Resignations.
All completely normal. All part of running a healthy business.
What’s not always obvious? The IT risk that quietly tags along.
Because most security issues in SMEs don’t start with a Hollywood-style hacker in a dark room.
They start with:
- An account that wasn’t removed
- A password shared “just for now”
- A contractor who still has access three months later
- A leaver whose email is still live
- Someone covering a role who suddenly has access to far more than they should
It’s rarely dramatic. It’s usually just… busy.
When teams are juggling workloads and trying to keep things moving, IT housekeeping can slip down the list. And that’s exactly when small access gaps appear.
Those small gaps are what attackers look for.
Periods of change — staff leaving, joining, or covering — are when:
- Permissions get messy
- Access builds up
- Nobody’s quite sure who can see what
And that uncertainty creates risk.
The good news? This isn’t about buying more software.
It’s about simple, consistent processes:
- Clear joiner, mover, leaver checklists
- Regular access reviews
- Removing permissions that aren’t needed
- Monitoring unusual account behaviour
- Making sure ex-staff accounts are properly closed
And ideally, having someone keeping an eye on things 24/7 — not just during office hours.
The Real Business Impact
If access isn’t managed properly, you increase the risk of:
- Data leaks (accidental or deliberate)
- Email compromise
- Ransomware spreading through shared accounts
- Compliance problems
- Disruption when ownership of files or systems isn’t clear
For growing SMEs, this becomes harder to manage as the team expands.
The more people you add, the more important structured access control becomes.
What Good Access Control Looks Like
The good news is that fixing this isn’t complicated.
Here are five practical steps every SME should follow:
1. Never Share Logins
Every team member — including temporary staff — should have their own account. Shared passwords remove accountability and make monitoring impossible.
2. Use “Least Privilege” Access
Staff should only have access to what they genuinely need. Not everything “just in case”.
3. Set Expiry Dates for Temporary Accounts
If someone is covering maternity leave for six months, set the account to expire automatically. That way, nothing lingers.
4. Disable Access Immediately When Someone Leaves
On their final day:
- Disable Microsoft 365
- Remove VPN access
- Transfer mailbox ownership
- Check shared folders
Waiting even a few days increases risk.
5. Monitor for Unusual Activity
This is where many SMEs struggle.
It’s one thing to set permissions. It’s another to know if something suspicious is happening.
That’s why more businesses are implementing 24/7 monitoring through managed detection and response (MDR). It provides continuous oversight — especially valuable during staffing transitions.
Why Cloud Systems Make This Easier
If your systems are cloud-managed (for example, Microsoft 365), access can be controlled centrally.
That means:
- Permissions can be changed instantly
- Accounts can be disabled remotely
- Activity can be reviewed
- Multi-factor authentication can be enforced
It removes reliance on individual devices or on-premise servers.
For busy SMEs, this creates structure without complexity.
A Simple Question to Ask Yourself
If someone left your business tomorrow:
- Would you know exactly what systems they can access?
- Could you disable everything within minutes?
- Are you confident nothing would be missed?
If the answer isn’t a clear yes, it may be time for a review.
At WTS Systems, we help businesses put simple, practical controls in place — without making things overly technical or disruptive.
If you’d like us to review your current setup and highlight any gaps, just get in touch.