Technology · medium risk
Passwords and multi-factor authentication for a small team
Reduce account takeover risk with unique credentials, password management and stronger sign-in controls.
Protect email first
Email is commonly the reset route for other services. If it is compromised, an attacker may be able to take over banking, accounting, domains and customer communications.
Do this now
- Choose a reputable password manager and create a separate account for each person.
- Replace reused passwords on email, finance, domain, website, social and cloud accounts.
- Turn on multi-factor authentication, preferring stronger app, passkey or security-key methods where supported.
- Store recovery codes somewhere protected and separate from the signed-in device.
- Create two trusted administrators for business-critical services where appropriate; do not share one login.
- Test the recovery process before an emergency.
- Remove access and rotate shared secrets immediately when roles change.
What good looks like
Passwords are unique and generated, the password manager itself is strongly protected, recovery does not depend on one phone, and the business can identify who changed a critical setting.
Common mistakes
- Sharing passwords in chat or email.
- Using SMS as the only protection where stronger options exist.
- Saving recovery codes inside the same account they recover.
- Giving everyday users permanent administrator access.
- Keeping former collaborators on billing, domain or social accounts.
When to get help
Get support if accounts have already been compromised, sign-in logs are unfamiliar or the business cannot regain control of its primary email or domain. Use the provider's official recovery route and preserve evidence.
Keep in your roadmap
Maintain an account register containing service, owner, administrators, MFA method, recovery location and last access review—never the passwords themselves.
