Every business runs on a set of digital keys: the logins to its email, its bank, its website, its accounting, its social accounts, the domain that its address depends on. In a small business these keys very often live with one person - the founder, the owner, the one technical member of staff - held in their memory, their personal password manager, or their private email. Day to day this is invisible and works fine. The risk it carries only appears at a single moment: the day that person is suddenly unreachable, through illness, a falling-out, an accident, or simply leaving, and takes the only copy of the keys with them. What was a convenient arrangement becomes a business locked out of itself.
The consequences of that lockout are more severe than people expect, because so much hangs off those credentials. Without access to the domain and its associated email, a business can lose control of its own web address and the messages that flow to it. Without the logins to critical accounts, it cannot pay bills, reach customers, or recover other passwords - since password resets are often sent to an email account that is itself locked. Recovering an account when the one person who set it up is gone can range from difficult to effectively impossible, particularly where a provider's identity checks are built around that individual. A business can find itself unable to prove it owns its own essential accounts, watching its operations seize up over keys it thought it had.
The reason this risk persists is that the convenient arrangement actively hides it. When everything is held by one trusted, present, capable person, there is no visible problem to solve and no obvious moment to solve it. Writing down who holds what, and arranging for someone else to be able to reach it in an emergency, feels like bureaucracy for a problem that does not exist - until it very much exists and there is no longer anyone able to fix it. The single keyholder is usually the most trusted person in the business, which is precisely why nobody questions the concentration until it is too late to unwind.
The remedy is unglamorous and cheap: know what the critical accounts are, make sure access to them does not depend on a single person, and set up a way for the business to recover its own keys if that person cannot help. In practice that means an inventory of the important logins and where recovery for each one points, at least one other trusted person or a secure sealed arrangement able to reach them when genuinely needed, and using recovery contacts and account settings that belong to the business rather than solely to an individual. This is succession planning for the parts of a business that have no physical form, and it deserves the same seriousness as any other key-person risk - because the day it is needed, there is no way to create it retroactively.