clic para entrar
← back to blog
Tech tips for business

Your First Password and Access Policy

Your First Password and Access Policy

During 2021, a wave of ransomware attacks shook companies of all sizes around the world. The headlines went to the big corporations, but the most useful lesson was quiet and very close to any small business: most of those attacks didn’t start with a brilliant hacker breaking into systems, but with something much simpler. A reused password, an access that was never revoked, an account shared among several people. The door was open and no one had noticed.

If your company doesn’t yet have a password and access policy, you’re not alone. Many businesses grow first and organize later, and that’s fine. But there comes a moment when “everyone uses the same email password” stops being practical and becomes a real risk to your data, your processes, and your history. The good news is that getting started doesn’t require an IT department or a huge investment. It requires clarity about one very concrete question: who gets into what, and how to cut off that access quickly when needed.

Start with what you already have: take your access inventory

Before creating rules, it’s worth seeing the whole map. Many small businesses are surprised to discover how many entry doors they have open without remembering it. Spend some time listing, without jargon, everything that requires a password to get in:

  • Email accounts and their forwarding rules. It’s the master keyring: whoever controls the email can recover almost any other password.
  • Business systems. Point of sale, invoicing, online banking, CRM, your website’s admin panel.
  • Social media and marketing tools. They often get “loaned” to suppliers who no longer work with you.
  • Former employees’ access. The classic: the person is gone, but their user account is still alive.
  • Shared accounts. That user “we all use” and whose full password nobody knows.

With that inventory in hand, you’re no longer guessing. You’re making decisions with reliable information, which is exactly where any kind of order should begin.

Diagram of people connected to a company's different systems through access keys
Knowing who gets into what is the first step to closing doors you didn't even know were open.

Simple rules that actually get followed

A policy only works if your team can follow it without getting frustrated. It’s not about demanding impossible-to-remember passwords, but about eliminating the habits that open the door. With a few clear rules you make huge progress:

  • One password per person, not per role. Everyone with their own user account. That way you know who did what and can cut off one access without affecting the others.
  • Long, unique passwords. A phrase that’s easy to remember and hard to guess is worth more than a hieroglyph. And never the same password for two different services.
  • A password manager for the team. Stop jotting them down in notes or in a spreadsheet. A manager stores them encrypted and lets you share without revealing.
  • Two-factor authentication wherever possible. Email and banking allow it at no cost. It’s the difference between a door with one lock and one with two.
  • Access by role. Each person gets into only what they need for their job, no more and no less.

A good access policy isn’t about distrusting your people: it’s about protecting your people and your business from a slip that can happen to anyone.

The most important thing: being able to cut off access quickly

The angle that’s often forgotten isn’t how someone gets in, but how quickly you can close the door. When someone leaves the company, loses their phone, or you suspect a strange move, every hour counts. That’s where an orderly policy proves its worth: if you know exactly what access each person has, revoking it takes minutes, not days of trying to remember “what else did they have access to?”

That’s why access removal should be part of your process, just as onboarding someone new is. A short checklist—disable email, remove from the manager, revoke two-factor, change shared passwords—turns a tense moment into a controlled procedure.

Your policy in three steps

If none of this exists yet in your company, don’t try to solve it all in a day. Break it into short, verifiable goals:

  • This week: take the access inventory and remove what should no longer exist (former employees, old suppliers).
  • This month: enable two-factor on your email and banking, and try a password manager with a small group.
  • As soon as you can: write your policy on a single page, in plain language, and share it with your team. Being short and understandable is worth more than a manual no one reads.

Getting access in order doesn’t have to slow down your operation. At Normandia Web we support small businesses in Mexico in doing it with custom software and simple processes that your team actually adopts, always taking care of your data, your processes, and your history. Security isn’t a luxury for big companies: it’s a way to protect everyone’s work. And as you saw, your first password and access policy starts with something as simple as a list and a clear decision. If you’d like, let’s talk and design it together.

Ready to put it to work in your company?

Tell us what’s costing you time, money or control. We’ll help you figure out where to start.

Start your consultation →