Three separate incidents this week reveal a single, critical vulnerability across UK small businesses: access management. Microsoft Threat Intelligence has confirmed an active campaign exploiting Teams external collaboration to impersonate IT helpdesk staff, tricking employees into installing remote access tools that deploy malicious payloads. Meanwhile, new analysis shows that resetting passwords after infostealer compromise leaves authenticated session tokens active, allowing attackers continued access for days. A separate case study documents a terminated employee retaining elevated access long enough to cause hundreds of thousands in damages, purely because no formal offboarding checklist existed. The technical controls to prevent all three scenarios are available and documented. What is missing is operational discipline: caller verification before granting remote access, session revocation alongside password resets, and comprehensive leaver access audits. This episode provides specific, actionable guidance for small businesses without dedicated security teams, walking through the configuration changes, staff briefings, and process checklists required to close these gaps before they are exploited.