Doing this with limited resources.
WHAT IS ACHIEVABLE WITHOUT SPECIALIST TOOLS
A list of services and who has access Individual accounts rather than shared ones A password manager Multi-factor authentication everywhere available Prompt removal when people leave Periodic review
WHY THOSE SIX
They address most of the risk at almost no cost.
WHAT TO PRIORITISE FIRST
Multi-factor authentication on email and financial systems.
WHY
It prevents the most common and most damaging compromises.
WHAT TO ESTABLISH
That the business, not an individual, owns every account.
WHY IT MATTERS ACUTELY IN SMALL BUSINESSES
Services set up by one person are lost when they leave.
WHAT TO VERIFY
The registered address on every service Who the administrator is Whether recovery details are under business control
WHAT TO AVOID
One person holding sole administrative access to anything critical.
WHY
Their unavailability blocks the business entirely.
WHAT TO ESTABLISH
A second administrator, or securely held emergency credentials.
WHAT TO KEEP
A record of services, accounts and access, however simple.
WHERE
Somewhere secure and accessible to more than one person.
WHAT TO ESTABLISH ABOUT DEPARTURES
A checklist, used every time.
WHY
Memory fails and departures are frequently abrupt.
WHAT TO DO ABOUT SHARED CREDENTIALS
Reduce them, and change them when anyone leaves.
WHAT TO REVIEW
Access, whenever anyone leaves or changes role.
WHY THOSE MOMENTS
They are when the review is actually necessary and when it is most likely to happen.