If there is one security measure every small business should implement before anything else, it is two-factor authentication on business email.
Business email accounts are valuable targets because they contain payment instructions, client relationships, supplier details, and confidential records. A compromised business email can be used to commit invoice fraud, impersonate you to clients, access linked accounts, and monitor your communications.
For Microsoft 365 (Outlook): Admin centre → Users → Active users → Multi-factor authentication. For Google Workspace (Gmail): Admin console → Security → 2-step verification.
If you use a personal Gmail or Outlook account for business, log into your account settings and enable 2-Step Verification right now.
When staff have separate business email accounts, ensure all of them have 2FA enabled — a member of staff's account can be just as valuable as the owner's. The pharmacy incident in 2022 began with a single compromised email account that wasn't protected.
Tags