1. Start with email
Set a long, unique password and enable multi-factor authentication (MFA). Review recovery email addresses, phone numbers, forwarding rules, signed-in devices, and recent activity. Remove anything unfamiliar.
2. Use a password manager
Choose a reputable password manager and protect it with a memorable master passphrase that you use nowhere else. Let it generate a different random password for every account. Do not keep the only copy of recovery codes inside the account they recover.
3. Turn on MFA
Security keys and passkeys offer strong protection. Authenticator apps are also good. Text messages are better than no MFA, though phone-number theft makes them less robust. Never approve an unexpected prompt; attackers sometimes send repeated prompts hoping you tap yes.
4. Protect the highest-impact accounts
- Email and password manager
- Banking, payroll, and payment services
- Domain registrar, website, and cloud administrator accounts
- File storage, accounting, and customer systems
- Social media and everyday applications
5. Separate administrators from daily work
Small businesses should give each person their own account. Use administrative privileges only when needed, remove former staff promptly, and avoid shared logins. Keep at least two trusted administrators so one lost account cannot lock out the business.
If you think an account was compromised
From a known-clean device, change the password, sign out other sessions, check MFA methods and recovery details, remove suspicious forwarding rules or connected apps, and notify the service provider. For financial accounts, call the number on an official statement or card.