Skip to content

A one-hour digital-safety reset

Start with the accounts that can unlock money, identity, customers, or recovery.

A small business does not need a giant security program to make the next useful move. Name the critical accounts, close one access gap, and practice one recovery step.

01

Circle the critical accounts

Begin with business email, the domain registrar, banking and payments, payroll, finance, website, cloud administration, password manager, customer systems, and any account that can reset another. Do not put passwords or recovery codes into this site.

  • Who is the accountable business owner?
  • Which business-controlled administrator can help if that person is unavailable?
  • Which recovery email, device, or support route is current?
  • What stops if the account is unavailable for one business day?
02

Fix one ordinary weakness

Choose one visible improvement: turn on MFA for an administrator, remove a former worker, replace a personal recovery inbox, update an unsupported device, verify a backup, or write the bank-detail change rule. Small repeatable controls beat a long plan nobody uses.

03

Practice the uncomfortable step

Recover a low-risk account, restore a safe file sample, verify a fictional payment change, or run a 20-minute incident tabletop. Record what failed, who owns the correction, and the next test date.

04

Know when general guidance stops

Active compromise, missing money, ransomware, exposed personal or regulated data, legal notice questions, disputed access, and uncertain evidence need prompt fact-specific help. This library is not an incident-response service or security assessment.

Monthly field note

Get practical guidance in your inbox.

Monthly plain-language guidance for account ownership, recovery practice, device safety, and incident readiness.
Required