BG Beter Geregeld ICT
Toegangsbeheer · 5 min leestijd · 04 August 2026

Who can actually log in to your systems? An access check in an hour

Who can actually log in to your systems? A straightforward step-by-step plan to tidy things up before the busy autumn season kicks in — in about an hour.

It's early August. The sun is shining, your inbox is (almost) empty, and you might even have a moment to tackle something that usually gets pushed aside. This is the perfect time to take on one specific task that almost nobody does voluntarily: checking who can actually log in to your business systems.

Sounds dull. It is. But it's one of the few things you can do yourself in an hour that will genuinely make your business more secure. Here's a straightforward step-by-step plan.

Why now?

A lot changes over the summer without you noticing. Interns come and go. A supplier was given "temporary" access to your webshop. Someone sent your accountant a new employee's details. And you? You've been on holiday and lost track of it all.

Before autumn arrives — with all its busyness, new projects, and new people — now is the ideal moment to tidy things up. Not with a big IT project, but with a simple list and half an hour of focus.

Step 1: make a list of your systems

Grab a blank sheet or a spreadsheet. Write down everywhere people can log in at your organisation. Think about:

  • Email (Microsoft 365, Google Workspace)
  • Accounting software (Exact, Moneybird, e-Boekhouden, Yuki)
  • Webshop or website (WordPress, Shopify, Lightspeed)
  • Banking (business banking — who shares user rights?)
  • Cloud storage (OneDrive, Google Drive, Dropbox)
  • CRM or planning tools (HubSpot, Pipedrive, Simplicate)
  • Social media and advertising accounts

Don't forget: where your domain name is registered (for example TransIP or Vimexx) and your email marketing tool. These are always overlooked — and they're particularly sensitive.

Step 2: check who has access to each system

Log in and look for "users", "team", "settings", or "admin". In almost every platform you'll find a list of who has accounts. Go through that list carefully and ask three questions for each name:

  1. Does this person still work for us?
  2. Does this person still need access to this system?
  3. Is their permission level still appropriate? (An intern doesn't need admin rights.)

If in doubt: reduce the permissions or disable the account. You can always delete it later. A disabled account can usually be re-enabled within a day if it turns out to be needed after all.

Step 3: pay close attention to external parties

This is where things usually go wrong. External parties — the web developer you used four years ago, a marketing agency, an accountant you no longer work with — often still have access. Ask yourself:

  • Are we still working with this party?
  • Do they have a personal account, or do they share a common password?
  • Was there ever any agreement about what happens when the engagement ends?

If an external agency is still an admin on your WordPress site or Google Ads account, that's a risk. Not because they have bad intentions, but because their security isn't your security. If someone there falls for a phishing attack, your account is exposed too.

Step 4: check shared accounts

Have you come across an "info@" or "admin@" address that four people share with the same password? That's a shared account — both inconvenient and insecure. When someone leaves, everyone has to remember a new password. And you can't trace who did what after the fact.

Where possible: convert shared accounts into personal accounts with individual login credentials. In Microsoft 365, for example, you can use a shared mailbox instead of a shared login account.

Step 5: record what you've done

Save your list. Put a reminder in the calendar to repeat this exercise in six months. Twice a year is enough for most SMBs. For sectors with high staff turnover (hospitality, retail, staffing agencies), more frequent checks are worthwhile.

Extra tip: note down who the "owner" of each system is within your organisation. Who decides who gets access to the webshop? Who handles that for the accounting software? Once that's clear, you won't have to work it out from scratch every time.

What about 2FA?

While you're at it: check whether two-factor authentication (2FA) is enabled on the accounts that really matter. Especially your email, your bank, and your domain name. Without 2FA, a strong password alone is no longer enough — that's simply the reality in 2026.

In short

  • Make a list of all your systems.
  • Go through the users for each system.
  • Be strict about external parties and shared accounts.
  • Enable 2FA wherever possible.
  • Schedule the next check for six months from now.

An hour's work, and you'll start autumn with a clean slate.

If you discover that things are completely out of hand, or you're not confident about making the changes you know need to be made, we carry out these kinds of access checks for SMBs without an in-house IT person. Straightforward, jargon-free, and with a list you can maintain yourself going forward.

Onderwerpen

#mkb #security #toegangsbeheer #2Fa #Access Reviews

Volledige gids: Access Management for SMBs: The Complete Guide (2026)

Dit artikel is onderdeel van onze uitgebreide Toegangsbeheer-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →