The Post-it was on the lower right corner of Begoña's monitor. It was yellow, slightly faded, with corners curled by the years. Written on it, in blue pen and small handwriting, was a word and a number: Warehouse2018. Underneath, in brackets: "(the supplier's)".
Begoña didn't remember who had put it there. It had been there before she joined. When she asked, her colleagues shrugged. It was the login to the aluminium supplier's website. Three people shared it: Begoña, who placed the small orders; Domingo, the workshop guy, who placed the big ones; and David, who had left two years ago for another company, but who when he was there was the one who used it most.
Domingo, in the workshop, had the same password written in a black-cover notebook he kept in his overalls pocket. When someone needed to get in and Begoña wasn't there, Domingo took out the notebook, read the password out loud and went back to the workshop. Sometimes he read it out to someone who wasn't from the company. A courier, for example. The courier needed to check a reference. Domingo read it out. The courier logged in from his phone.
That was a normal day in a company that was working well.
What David did when he logged in
David left in March two years ago. He went to a bigger company, in Alicante. He left on good terms, no bad words, he even left a box of chocolates in the office on the day of his farewell.
The supplier login was still active. Nobody thought about removing it. To remove it you had to call the supplier, identify yourself, wait for a technician to look at it, wait for confirmation. It was a twenty-minute phone call. And what for, anyway, since David wasn't going to log in.
David kept logging in.
Not with bad intentions. David now worked in a company that also bought aluminium. And he knew the prices his old company was getting. And prices changed by client, by volume, by history. David, every now and then, logged in with Warehouse2018 and looked at the prices. He compared. He learned. He applied.
He didn't steal. He didn't copy. He just looked. And the data he saw, he used in his new company.
Nobody at David's old company knew any of this. Not Begoña. Not Domingo. The manager, even less. The company's prices had been known to a competitor for two years, without anyone having done anything wrong, without anyone having betrayed anyone. A door had simply been left open.
The day it was discovered
It was discovered by accident. The salesman at David's old company — not Begoña, another one, the one with the big clients — lost three tenders in a row against David's new company. Three tenders in six months. The competitor's prices were always slightly lower. Not much. Just enough.
The manager, without quite knowing why, asked the external IT guy — a young man who came in one day a week — to look at the supplier logins. The young man took half an afternoon. He came back with a list on a sheet of paper. Twelve active accounts. Of the twelve, four belonged to people who no longer worked at the company. One was David's.
—Can you tell when they've been logging in?
—Yes.
The young man opened a panel. On David's account, the last login was eleven days ago.
The manager sat staring at the screen. He didn't say anything. He closed the laptop.
That night, at home, he added up in his head what could have been three tenders lost at slightly lower prices. About one hundred and forty thousand euros. He didn't sleep well.
What it costs not to keep access in order
The cost of not controlling who logs into your company tools isn't just the extreme case — the ex-employee looking at prices from the competing company. It's smaller, more continuous things that happen every day without anyone noticing.
Every uncontrolled access is an unlocked door. Small companies tend to think they're too small to be anyone's target. That's true and not true.
The courier Domingo reads the password out to, and who one day writes it down too, just in case. The intern who leaves and whose email nobody closes, and who keeps receiving order notifications for months. The shared account three people use, of which nobody knows who did what, when, or why. The software vendor who has had access to the company's system for five years because "he was the one who installed it", and is still active.
They're not the target of a hacker who'll steal their data to sell on the internet. They're the target, unintentionally, of the ex-employee, the curious supplier, the courier who one day became a competitor.
What gets done, when someone decides to do it
The manager called the IT guy on a Tuesday. He told him two things.
First: clean it up. One account per person. Each with their own password. No shared ones. When a person leaves, it gets closed. One sheet, in a visible place, listing all the accounts, all the people and the date of the last change.
Second: figure out how to keep this from getting forgotten. Because the problem wasn't that nobody had cared. The problem was that there was no place where caring could turn into action. There were good intentions. There was no process.
The IT guy did the first part in two weeks. The second part took three months: a small internal tool, custom-built, where the manager could see, once a month, all active accounts, who used them, when they had last been used. If someone left the company, a checkbox. The accounts closed automatically. If they had been unused for three months, they appeared in red.
It wasn't spectacular. It wasn't a tool you could show off at a trade fair. It was a tool that prevented problems that would never happen. Which is, probably, the kind of tool that's hardest to justify and, at the same time, most necessary.
Begoña, one morning
Begoña arrived one morning and saw that the Post-it was gone. The IT guy had taken it off the previous Friday. In its place there was a small printed slip, with the company logo, and a short sentence:
Your access is yours. Don't share it. If you need help, ask here.
Begoña stood looking at it. She thought about the yellow Post-it, about David, about the years the three of them had been typing Warehouse2018. She thought she had a new password, just hers, that the system had asked her to change and that she had written on another Post-it, at home, in a drawer.
Something had changed. Something hadn't.
Begoña turned on her computer. She started her day.
The doors nobody checks
Shared passwords, accounts left open when someone leaves, suppliers with eternal access, interns with permissions nobody reviews: every uncontrolled access is an unlocked door. You're not robbed by a hacker. You're robbed by a curious ex-colleague, a well-meaning supplier, a courier who jotted down a password on his phone.
A small internal tool that shows you, on a screen, who has access to what and when they last used it isn't spectacular. It's one of the hardest things to justify and, at the same time, one of the most necessary: it prevents problems that, if it works, will never happen.
How many people can log into your systems today and no longer work with you?
If in your company there's no place where you can see who has access to what, the answer to that question is "I don't know". Let's start by seeing it.
Let's talk about your access