Protect the email account first, use unique passwords, switch on multi-factor authentication, keep devices updated and test that important files can be restored.

Secure the accounts that unlock everything else

Email accounts are often used to reset passwords for other services, so they deserve special attention. Use a unique password and multi-factor authentication, and check that the recovery phone number and email address still belong to the right person. Do the same for the domain registrar, website hosting and financial accounts.

Use a password manager

Reusing a memorable password turns one breached service into a key for several accounts. A reputable password manager can create and store a different password for each service. Make sure the recovery process is understood and that business access does not depend entirely on one employee’s personal account.

Keep software current

Install security updates for computers, phones, browsers, plugins and website systems. Remove software and accounts that are no longer used. Updates should be planned rather than postponed indefinitely, especially for internet-facing systems such as a website content manager.

Back up the information that matters

Decide which files would stop the business if they disappeared, then keep more than one copy. At least one backup should be separate from the everyday device or shared drive. A backup is only useful if it can be restored, so test a small recovery rather than assuming the green tick means everything is safe.

Pause on unexpected messages

Urgency is a common warning sign. Be cautious when a message asks for a password, payment, account change or document download. Check the sender address carefully and confirm important requests through a known phone number or a new message rather than replying to the suspicious one.

Do not rely on spelling mistakes as the main test. Modern phishing messages can be polished and may refer to real people or current projects.

Know what to do after a mistake

People report problems sooner when the response is calm. If somebody clicks a suspicious link or shares a password, disconnect only what is necessary, change the affected credentials from a trusted device, preserve useful details and contact the relevant provider. Speed matters more than blame.

Keep a short record of key suppliers, account owners and recovery contacts somewhere accessible. Security is not a single product; it is the ability to prevent common problems and recover sensibly when prevention fails.

Back to all Digital Help guides