Know which accounts control the business

List email, domain, hosting, payment and administrative accounts with their owners. Remove access that is no longer needed and use separate named accounts where supported. CISA’s small-business guidance recommends strong passwords and multifactor authentication; recovery arrangements also need to be available when a key staff member is absent.

Rehearse a lost administrator account

Suppose the only person who controls the domain and hosting loses access to their phone. The website may still be running, but the business cannot renew services or respond to an incident. Test recovery before this becomes urgent.

Rehearse a lost administrator account
ControlPractical evidence
Business-owned administrator accessA second authorised person can reach the provider account
Recovery materialsRecovery codes are stored securely and retrieval is tested
Restorable backupsA recent backup restores into isolation and sample records reconcile

Check maintenance and recovery

Identify who updates devices, applications and dependencies. Confirm that backups cover the records the business cannot afford to lose and test a restoration. A backup stored behind the same compromised account may not provide the independence you expect, so examine access and recovery together.

Prepare the first incident actions

Keep a contact list, a way to preserve useful evidence and an agreed route to technical and legal support. Decide who can disable an account or pause a service. During a personal-data incident, assess the facts and applicable obligations with the responsible advisers rather than relying on a generic checklist as a legal conclusion.

Before you proceed

  • Review privileged access and account recovery.
  • Test restoration and record who maintains each system.
  • Keep incident contacts available outside the affected system.

Sources & further reading

Put this into practice