BUSINESS ACCOUNT SECURITY · VERIFICATION GUIDANCE

Verify the accounts that run your organization.

Business account security is not only about having strong passwords. Verify who has access, what each account can do, how it can be recovered and whether an unusual request is actually legitimate before it changes money, data, systems or public communications.

Use this sequence: IDENTIFY → VERIFY → LIMIT → REVIEW → RECOVER.

Start with the accounts that could cause the greatest business impact. Then verify the identity of people, applications and requests through established channels, limit access to what is necessary, review access regularly and make sure recovery routes are controlled by the organization.

These controls are also reflected in established cybersecurity guidance for organizations: protect important accounts with strong authentication, avoid unnecessary shared credentials, remove access when roles change or people leave, and restrict privileged access.

What should never be shared?

Never give a caller, colleague, vendor or supposed support agent a password, OTP, PIN, backup code, recovery phrase, private key or other authentication secret simply because they claim to need it for business-account support.

01 · ACCOUNT VERIFICATION

Work through the control chain.

A business account should be verified as a system of access, authentication, recovery and permissions. It is more than a username and password.

Identify the highest-impact accounts

List the accounts that can move money, access sensitive data, reset other accounts, change security settings, manage infrastructure or represent the organization publicly. Protect the accounts with the greatest potential business impact first.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.

Use individual accounts instead of shared passwords

Where the service supports it, give each person their own account. Shared credentials make it harder to know who acted, harder to remove one person's access and easier for a compromised credential to affect everyone.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.

Verify MFA on important accounts

Review the actual account security settings through the official service. Important accounts should have appropriate multi-factor authentication enabled where supported. Treat approval prompts and verification codes as security decisions, not as proof that a caller is genuine.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.

Check recovery methods

Review recovery email addresses, phone numbers, backup codes and other recovery routes. Remove methods the organization no longer controls and make sure recovery information is protected as carefully as the main login.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.

Review active sessions and connected applications

Look for old devices, unfamiliar sessions and applications that still have access. Do not assume that changing a password automatically removes every session or integration.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.

Separate routine access from administrative access

Where practical, avoid using a highly privileged administrator account for ordinary email, browsing or routine work. Limit powerful accounts to the people and tasks that actually require them.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.

Apply least privilege

Give each person or service only the access needed for the job. A person who only needs to read files should not automatically receive permission to delete, export, administer or change security settings.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.

Verify role and offboarding changes

When someone joins, changes role or leaves, verify what access they should have and remove access they no longer need. Do not assume one account change removes access everywhere.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.

Verify unusual support or security requests independently

A message claiming to be from Microsoft, Google, a bank, a hosting company, a payment provider or an IT technician is not proof of identity. Open the official service yourself or use a trusted contact route already known to the organization.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.

Verify payment and beneficiary changes separately

A changed supplier bank account, new beneficiary or urgent payment request should be confirmed through an established channel before approval. Do not use the contact details supplied in the change request as the only proof.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.

Review who can publish or represent the organization

Company social-media, website, domain and communication accounts can create reputational and financial harm when compromised. Limit publishing access and review administrators regularly.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.

Test the recovery path without exposing secrets

Know who is responsible for recovering each high-impact account and where the official recovery process is documented. Never send passwords, OTPs, PINs, backup codes or other secrets to someone who claims they need them to help.
Why does this matter?
The goal is to prevent one compromised credential, session, application or administrator from creating unnecessary access to the organization's money, information or operations.
02 · REAL-WORLD BUSINESS EXAMPLES

Verify before approving or trusting.

These examples turn the account-security principles into decisions that a business owner, manager, finance officer or staff member may actually face.

The Shared Business Password

Situation: A small business uses one shared password for its main email account because several staff members need access. A new staff member asks for the password too.

Safer verification: Move toward individual accounts or controlled delegated access, enable appropriate authentication and stop expanding the shared credential.

The Unexpected Business Administrator

Situation: A business discovers that an unfamiliar person has administrator access to an important cloud service.

Safer verification: Do not assume the account is legitimate because it has an official-looking name. Preserve relevant account information, review the service's official administrator controls and independently verify who should have access.

The Supplier Bank-Account Change

Situation: A supplier emails that its bank account has changed and asks the business to send today's payment to the new account.

Safer verification: Pause the payment and confirm the change using a phone number or other contact method already stored in the business's records.

The CEO Payment Request

Situation: A message that appears to come from a senior executive asks finance to make an urgent payment to a new beneficiary.

Safer verification: Follow the organization's normal payment controls and independently confirm the request with the executive or an established approval channel.

The Fake IT Support Call

Situation: Someone calls claiming to be the company's IT provider and says they need the administrator password and a verification code to fix a security problem.

Safer verification: Do not disclose the secrets. End the call and contact the IT provider through a known official channel.

The Former Employee Still Has Access

Situation: An employee leaves the organization, but their account still appears to have access to email, cloud files or a payment platform.

Safer verification: Use the official administration controls to disable or remove access and review related sessions, delegated access and shared resources.

The Unfamiliar Recovery Email

Situation: The recovery email address on an important business account has changed, but no one on the team recognizes the new address.

Safer verification: Treat the change as a security event. Use the service's official account-security and recovery process and independently verify the responsible administrator.

The New Cloud App Integration

Situation: A staff member is asked to connect an unfamiliar application to the company's cloud storage to make work easier.

Safer verification: Verify the application, its publisher, requested permissions and legitimate business need before granting access. Use the least-permissive option available.

The Social-Media Administrator Request

Situation: A person says they are helping the business with marketing and asks for the password to the company's social-media account.

Safer verification: Do not share the password. Use the platform's official role or delegated-access controls where available and verify the person's role through an established business process.

The Domain Renewal Message

Situation: An email says the company's domain expires today and provides a payment link.

Safer verification: Do not pay through the message. Open the domain registrar's official website or account directly and check the actual renewal status there.

The Emergency Security Upgrade

Situation: A message says the business must install a security tool immediately or its banking and accounting systems will stop working.

Safer verification: Verify the claim through the software vendor, bank or IT provider using independently obtained official contact details before installing anything.

The New Employee Needs Access

Situation: A new employee needs access to customer files and business email on their first day.

Safer verification: Give only the access required for the role, use an individual account and enable the organization's normal authentication and access controls.

High-impact account test

Before you consider an important business account protected, ask:

  1. Which business accounts could cause the greatest harm if compromised?
  2. Does each important user have an individual account rather than a shared password?
  3. Is appropriate MFA enabled on high-impact accounts?
  4. Are recovery methods current and controlled by the organization?
  5. Have active sessions and connected applications been reviewed?
  6. Are administrator privileges limited to people and tasks that need them?
  7. Is there a clear process for joiners, role changes and leavers?
  8. Are unusual support and payment requests independently verified?
  9. Can the organization recover each high-impact account through an official process without sharing secrets?
  10. Who is responsible for reviewing business-account access and security regularly?

A “yes” should mean the control is actually configured and understood. Do not rely merely on someone believing it is in place.

Something unusual happened?

If a business account may already be compromised, stop unsafe activity, preserve useful evidence and use the service's official security or recovery process.

Open First Response Guidance →Return to Module 23 →
VERIFY BEFORE YOU TRUST.

Familiarity, job title, company branding, an urgent request or administrator status is not proof by itself. Verify the access, identity and request through a trusted route before acting.