Know which accounts control the business
List email, domain, hosting, payment and administrative accounts with their owners. Remove access that is no longer needed and use separate named accounts where supported. CISA’s small-business guidance recommends strong passwords and multifactor authentication; recovery arrangements also need to be available when a key staff member is absent.
Rehearse a lost administrator account
Suppose the only person who controls the domain and hosting loses access to their phone. The website may still be running, but the business cannot renew services or respond to an incident. Test recovery before this becomes urgent.
| Control | Practical evidence |
|---|---|
| Business-owned administrator access | A second authorised person can reach the provider account |
| Recovery materials | Recovery codes are stored securely and retrieval is tested |
| Restorable backups | A recent backup restores into isolation and sample records reconcile |
Check maintenance and recovery
Identify who updates devices, applications and dependencies. Confirm that backups cover the records the business cannot afford to lose and test a restoration. A backup stored behind the same compromised account may not provide the independence you expect, so examine access and recovery together.
Prepare the first incident actions
Keep a contact list, a way to preserve useful evidence and an agreed route to technical and legal support. Decide who can disable an account or pause a service. During a personal-data incident, assess the facts and applicable obligations with the responsible advisers rather than relying on a generic checklist as a legal conclusion.
Before you proceed
- Review privileged access and account recovery.
- Test restoration and record who maintains each system.
- Keep incident contacts available outside the affected system.



