Here is a scene that plays out in small businesses every week. Someone notices something wrong with an email account. A rule was created that nobody set up, or a message went out that nobody wrote. The owner reacts the right way and resets the password. Everyone exhales. The problem feels solved.
Sometimes it is solved. Sometimes it is not, and the reason is a piece of plumbing most business owners have never heard of: the session token. If an attacker holds a live token, the password reset changes nothing, and they are still inside the account while you believe you have closed the door.
What a session token really is
When you log in to your email or your bank and clear the multifactor prompt, the service does not ask you to log in again for every click. It hands your browser a token, a small piece of data that says "this person already proved who they are." Every action after that rides on the token, not on your password. This is why you stay logged in for days without retyping anything.
The token is convenience, and it is also the prize. If someone steals that token, they do not need your password and they do not need your phone. To the service, the stolen token looks exactly like you, already authenticated. No login screen appears. The multifactor prompt never fires, because from the system's point of view the login already happened.
Why this is worth your attention right now
Two things put session tokens in the news this month. Researchers demonstrated a practical way to lift an active session straight out of a running browser on a compromised computer. Separately, the most common malware aimed at small businesses, the class known as infostealers, is built to grab exactly these tokens, along with saved passwords and browser cookies, and ship them to the attacker in seconds.
The uncomfortable part is what this does to the reflex we all trust. Resetting a password is the right first move, but on its own it invalidates the password, not the session that is already open. The attacker who holds a live token can keep working right through the reset. You have to end the session, not just change the credential.
Why the usual defenses do not catch it
Multifactor authentication is one of the highest-value controls a small business can turn on, and it should be on everywhere. But multifactor protects the moment of login. A stolen session token represents a login that already succeeded, so the attacker is standing on the far side of the prompt you are counting on. The token is proof that the multifactor step is behind them, not ahead of them.
That is not an argument against multifactor. It is an argument for adding a second idea next to it: assume a session can be stolen, and make a stolen session short-lived and easy to cancel.
The four controls that shut it down
None of these require enterprise budget. They are settings and habits.
Shorten how long a session stays valid on the accounts that matter. Email, banking, payroll, and your cloud administrator account do not need to stay logged in for weeks. A shorter session lifetime means a stolen token expires sooner and is worth less to the person who took it.
Make sure you can revoke a session, not only reset a password. In business email and cloud platforms this is usually a "sign out everywhere" or "revoke all sessions" button. After any scare, use it. Resetting the password and forcing every session to sign out is the combination that removes an attacker who is already inside.
Prefer phishing-resistant sign-in for the accounts that matter. A passkey or a hardware security key binds the login to the real website and to your device, which takes the fake login page and much of the token-theft playbook off the table for that account. Start with email and finance, the two accounts an attacker wants most.
Protect the computer, because that is where tokens are stolen. Infostealers take tokens off an already-infected machine. Keep the operating system and browser patched, remove browser extensions you do not need and trust, and treat any "install this to continue" prompt on a random website as hostile. A clean endpoint is where session security begins.
Where this sits in NIST 800-171 and CMMC
For defense contractors and any business working toward the Cybersecurity Maturity Model Certification (CMMC), this is not a side topic. It lives in two of the control families in National Institute of Standards and Technology Special Publication 800-171: Identification and Authentication, and Access Control. Session termination, session limits, and strong authentication are named expectations, not extras. Being able to explain how you end a session, and how quickly, is exactly the kind of thing an assessor asks about and a prime contractor increasingly wants to see.
What to do this week
Open your business email and your cloud platform admin settings and find two things: where you set session length, and where you force a full sign-out across all devices. If you cannot find the sign-out-everywhere control, that is the gap to close first, because it is the button you will want the day something looks wrong. Then turn on a passkey or hardware key for your email and your bank.
The mental shift is small and it matters. The goal is no longer only to keep the password secret. It is to make a stolen session short-lived and revocable, so a theft is worth less and you can undo it fast.
Adams Cloud and Cybersecurity LLC helps small businesses in San Diego County and across California tighten identity and access controls, document them in the form auditors and primes want to see, and prepare for CMMC and NIST 800-171. If you would like a free thirty minute conversation about session and identity security for your business, reach me at thabiti@adamscloudcyber.com.
Adams Cloud and Cybersecurity LLC. Service-Disabled Veteran-Owned Small Business. CISSP, CCSP, CCP, Security+ certified. Practical cybersecurity advisory for small business.
Want your identity and access controls tightened and documented?
Adams Cloud helps small businesses in San Diego County and across California shorten sessions, enable phishing-resistant sign-in, and document identity controls in the form auditors and prime contractors want to see.
Book a free thirty minute consultation