1. Start with email

Set a long, unique password and enable multi-factor authentication (MFA). Review recovery email addresses, phone numbers, forwarding rules, signed-in devices, and recent activity. Remove anything unfamiliar.

2. Use a password manager

Choose a reputable password manager and protect it with a memorable master passphrase that you use nowhere else. Let it generate a different random password for every account. Do not keep the only copy of recovery codes inside the account they recover.

3. Turn on MFA

Security keys and passkeys offer strong protection. Authenticator apps are also good. Text messages are better than no MFA, though phone-number theft makes them less robust. Never approve an unexpected prompt; attackers sometimes send repeated prompts hoping you tap yes.

4. Protect the highest-impact accounts

  1. Email and password manager
  2. Banking, payroll, and payment services
  3. Domain registrar, website, and cloud administrator accounts
  4. File storage, accounting, and customer systems
  5. Social media and everyday applications

5. Separate administrators from daily work

Small businesses should give each person their own account. Use administrative privileges only when needed, remove former staff promptly, and avoid shared logins. Keep at least two trusted administrators so one lost account cannot lock out the business.

If you think an account was compromised

From a known-clean device, change the password, sign out other sessions, check MFA methods and recovery details, remove suspicious forwarding rules or connected apps, and notify the service provider. For financial accounts, call the number on an official statement or card.

Never share a one-time code. A legitimate support person should not ask you to read them an MFA or password-reset code.