Account security
Three steps to protect your business accounts
Use unique passwords, a password manager and two-factor authentication to protect business accounts.

A password is a key to part of your business. You would not leave a key in the door or hand copies to people who no longer work with you. Business passwords deserve the same care.
These three steps deal with the most common account problems.
1. Use a password manager
A password manager stores login details in an encrypted vault. It can create long, unique passwords for every account, so you do not have to remember them all.
Choose one password manager for the business. Protect its main account with a strong passphrase and two-factor authentication. If staff share access to an account, use the manager’s sharing feature instead of sending the password through email or chat.
2. Stop reusing passwords
Reusing a password is like cutting the same key for every door. If one service is breached, an attacker can try the exposed email address and password on other services.
Every account should have its own password. Start with email, banking, accounting, domain registration, social media and cloud storage. These accounts often give access to other parts of the business.
3. Turn on two-factor authentication
Two-factor authentication asks for another proof of identity after the password. This may be a code from an authenticator app, a security key or a prompt on a trusted device.
It means a stolen password is not enough on its own. Turn it on first for email and any account that controls money, customer data or other accounts.
Keep access current
Review business accounts when a staff member or supplier leaves. Remove their access, transfer ownership of shared files and change any password that was shared outside the password manager.
Small changes here prevent a surprisingly large number of account problems.