Skip to content

Small-business digital safety

Build one chain the business can still follow under pressure.

Move from ownership and sign-in through verification, maintenance, recovery, and first-hour response. Each link needs an accountable owner and visible evidence.

  1. OWN

    Name business-controlled owners and recovery routes

    Start with the accounts, devices, records, and people whose loss could interrupt money, customers, communications, or operations.

  2. AUTHENTICATE

    Make strong sign-in and recovery repeatable

    Use unique credentials, suitable multifactor authentication, protected recovery, and separate administrative access.

  3. VERIFY

    Break the urgent-request path

    Confirm payment, access, and account changes through a pre-established second channel before acting.

  4. MAINTAIN

    Keep the device and software baseline visible

    Assign owners, supported versions, update expectations, protective settings, and safe retirement steps.

  5. RECOVER

    Produce observed recovery evidence

    Restore a named record safely, check the result, measure the time, record gaps, and assign the next correction.

  6. RESPOND

    Practice the first hour before pressure arrives

    Name the lead, contacts, safe actions, evidence boundary, continuity path, and escalation points.

Field vocabulary

Six definitions make ownership and evidence explicit.

Open the knowledge shelf
01 / FIELD TERM

Critical account ownership

Critical account ownership means the business can name the accountable owner, control its administrators, use business-controlled sign-in and recovery routes, remove obsolete access, and recover the account without depending on one employee, vendor, or personal address.

02 / FIELD TERM

Strong authentication routine

A practical strong-authentication routine combines a unique credential, the strongest suitable multifactor method available, protected recovery routes, separate administrative access, and a repeatable process for enrollment, loss, replacement, and removal.

03 / FIELD TERM

Trusted second channel

A trusted second channel is a separately established way to confirm a sensitive request with the right person, using a known phone number, approved account, or documented process instead of the message, link, caller, or contact details that delivered the request.

04 / FIELD TERM

Maintained device baseline

A maintained device baseline is a current record of business devices, supported software, accountable owners, update expectations, protective settings, important data, and safe replacement or retirement steps.

05 / FIELD TERM

Recovery evidence

Recovery evidence is a dated record that an approved person restored a named business record or configuration from a protected backup into a safe location, checked the result, measured the time, recorded gaps, and assigned the next correction.

06 / FIELD TERM

First-hour incident plan

A first-hour incident plan names who leads, who must be contacted, which safe actions are preapproved, how evidence and continuity are protected, what must not be changed, and when to involve technology, legal, insurance, financial, privacy, communications, or public authorities.

Complete practice sequence

Turn each link into a routine the business can review.

See all guides
01

Own the access

Name an owner for every critical business account

Create a plain inventory for email, domain, banking, payroll, cloud, website, social, and vendor accounts before an emergency exposes an ownership gap.
8 minute safety guide
02

Strengthen sign-in

Make everyday sign-in safer without making work impossible

Use individual accounts, a business password manager, and multi-factor authentication to reduce the damage from reused or stolen passwords.
7 minute safety guide
03

Close known gaps

Keep devices and software current with a visible routine

Turn updates, supported versions, screen locks, encryption, and device retirement into a small operating routine instead of an occasional scramble.
8 minute safety guide
04

Break the scam path

Verify payment and account-change requests on a second channel

Use a short verification script for new bank details, urgent payments, password resets, gift cards, payroll changes, and unusual vendor requests.
7 minute safety guide
05

Practice recovery

Make backups you can actually restore

Identify the records that keep the business operating, protect copies from the same failure, and test a small restore before calling the backup complete.
9 minute safety guide
06

Close the old door

Remove access when people and vendors change

Use one joiner, role-change, departure, and vendor-exit routine so accounts, keys, devices, forwarding rules, and shared access do not survive by accident.
8 minute safety guide
07

Know who calls whom

Write a first-hour incident plan before the first hour

Prepare a short contact and decision card for lost devices, compromised email, suspicious payments, malware, outages, exposed records, and ransomware.
9 minute safety guide

Monthly field note

Get practical guidance in your inbox.

Monthly plain-language guidance for account ownership, recovery practice, device safety, and incident readiness.
Required