Five account security questions worth asking this week
Your business runs through accounts: email, shared files, bookkeeping, and the tools your team uses every day. A useful security conversation starts with knowing who can get in and what happens when something changes.
1. Is multifactor authentication turned on?
Multifactor authentication adds another check when someone signs in. Start with email, administrator accounts, and systems that contain important business information. CISA recommends phishing-resistant methods where available.
Ask your IT partner which methods your tools support and how people recover access when a device is lost. Enrollment and recovery both need a clear owner.
2. Does each person have their own login?
Individual accounts make it easier to assign access and remove it when someone leaves. If a shared login is unavoidable, document why, who uses it, and how it is protected. Avoid sending passwords around in email or chat.
3. Who has administrator access?
An administrator can often change settings or grant other people access. Review that list and make sure elevated permissions match a current business need. Daily work should not automatically require the same access used to administer a system.
4. What happens when someone leaves?
Use a checklist that covers email, cloud applications, remote access, shared passwords, and company devices. Decide what needs to be retained or transferred before an account is removed. Give the checklist an owner so it doesn’t depend on someone remembering every system.
5. How does the team report something suspicious?
Make the reporting path easy to find. A suspicious sign-in notice or unexpected payment request should reach the right person quickly. Encourage people to ask before acting and to report mistakes promptly.
Purple Bunny can help review account access and turn these questions into a manageable plan for your business. Start with the systems your team depends on most.