Think about everyone who has ever touched your website. The designer who built it. The agency you used for a year. A freelancer who fixed one thing. The office manager who left. Now ask yourself how many of them could still log in today. For most small businesses, the honest answer is "I don't know."
Every old login is an unlocked door you forgot about. Once a year, and every time someone leaves, list every account tied to your website, remove anyone who no longer needs access, change shared passwords and turn on two-step verification. It's a boring job, and it closes some of the easiest ways in.
Why old access is a real risk
Most people picture website attacks as clever hacking. A lot of the time it's simpler than that. Someone gets hold of a password that still works. Maybe it was reused on another site that leaked, maybe it was written on a sticky note, maybe it belonged to a former employee whose email got broken into.
Old access also causes trouble without any bad actor at all. A former vendor logs in to "help" and changes something. An ex-employee still gets your form leads in their inbox. Someone holds the only admin login and won't answer your calls. I see this a lot: nobody did anything wrong, the access just never got cleaned up.
The places your website's keys hide
Your website isn't one account. It's a handful of accounts, and each one has its own list of people who can get in.
- Website admin. The login for WordPress or whatever your site runs on. Look for admin accounts nobody recognizes, generic ones like "admin" or "webmaster," and former staff.
- Hosting. The company whose server your site lives on. This account can change or delete everything.
- Domain registrar. Where your domain name is registered. Whoever controls this controls where your website and email point.
- DNS. The settings that point your domain at your website and email. Sometimes it's at the registrar, sometimes somewhere else.
- Email admin. The admin panel for your business email. It can create inboxes, reset passwords and read settings for everyone.
- Analytics and Search Console. Google Analytics and Google Search Console, the free tools that show your traffic and search problems. Former agencies often still have access.
- Google Business Profile. Your Maps listing. Check the list of owners and managers.
- Everything else. Form tools, your CRM, ad accounts, social profiles and any plugin that has its own login.
Turn on two-step verification everywhere you can
Two-step verification, also called multifactor authentication or MFA, means a password alone isn't enough to log in. You also confirm it's you with a code from an app, a security key or a prompt on your phone.
CISA, the federal agency that works on cybersecurity, explains that "When you enable MFA in your online services (like email), you must provide a combination of two or more authenticators to verify your identity before the service grants you access." Its plain summary: "Users who enable MFA are significantly less likely to get hacked." Less likely isn't never. It's still one of the best trades of five minutes you can make.
Start with the accounts that control the most: your email admin, your domain registrar and your hosting. If someone takes over your email, they can reset the passwords to almost everything else.
The access cleanup checklist
Set aside an hour. Work through each account in the list above.
- Write down every account tied to your website and who the owner is. The owner should be your business.
- For each one, open the list of users. Remove anyone who no longer works with you.
- For vendors you still use, give them their own login with only the access they need, not the owner login.
- Replace shared logins with individual ones, so you can see who did what and remove one person without locking out everyone.
- Change any password that was ever shared by email, text or sticky note.
- Delete admin accounts nobody can explain. If you're nervous, ask your developer before deleting, but don't leave them sitting there.
- Turn on two-step verification on every account that offers it.
- Make sure recovery emails and phone numbers belong to you, not a former employee or vendor.
- Store the logins in a password manager your business controls, not in someone's personal notes.
- Put the next review on your calendar.
If you find accounts in someone else's name, like a domain registered to your old agency, don't panic. Read who should own your website for how to get each piece moved into your name.
How to offboard someone properly
The cleanup above is the big annual version. The small version happens every time someone leaves, whether it's an employee, a freelancer or an agency.
- Remove their accounts on the same day their work ends, not when you get around to it.
- Change any password they knew that you can't remove, like a shared login.
- Check where your form leads and site alerts are sent, and take their address off.
- Move any account where they're the owner or the recovery contact into your business's name.
- Ask vendors for a list of everything they had access to. A good one will send it without fuss.
Doing it yourself
You can do this cleanup yourself, and I'd encourage every owner to do it at least once so you know what you have. It takes an afternoon the first time and less after that.
The hard parts are practical. You need to find every account, and some are buried in old emails. You need to get into each one, which may mean recovering passwords that belong to people who left. And you need to know which accounts are safe to delete. Removing the wrong user, or the wrong plugin login, can break a form or an integration. If that happens, you're the one working out what broke.
Keep the keys in your hands
When we build and host a site, the domain and DNS are documented in the client's name, so you can see who controls what. Our care plan handles updates and security patches, and our hosting runs on servers we manage. We also set up email properly, including SPF, DKIM and DMARC, the records that help prove your messages really come from you.
None of that makes a site immune to trouble. It does mean you always know who has the keys.
If you'd like help cleaning up access and keeping it clean, ask us about a care plan.



