Opens in a new tab

Protect business accounts with two-step verification

Published: 13 June 2019
Topic: Website Care

A stolen password should not be enough to take control of your business email, domain or website. Two-step verification adds another check when you sign in, helping protect accounts when a password is exposed.

Start with the accounts that control everything else

Prioritise email, domain registration, hosting and administrator accounts. Email is especially important because password-reset messages often arrive there. Give each person their own account where the service supports it, rather than circulating one shared administrator password.

Use the strongest supported sign-in method you can maintain

Services may offer security keys, passkeys, authenticator apps or codes sent through other channels. Follow the provider’s setup instructions and use an option your team can use reliably. Never approve an unexpected sign-in request or share a verification code with someone who contacts you.

Prepare for losing a device

Store recovery codes securely and document an appropriate recovery process. Check that recovery email addresses and phone numbers are current. Do not make one employee’s personal device the only way the business can regain access to an essential service.

Keep the rest of the account secure

  • Use unique passwords and a reputable password manager.
  • Remove access promptly when someone leaves.
  • Keep devices and applications updated.
  • Check suspicious messages through a known contact route before acting.

Two-step verification reduces risk, but it is not protection against every attack. Treat it as part of ordinary account management, with recovery arrangements that have been checked rather than assumed. The NCSC’s two-step verification guidance explains the setup and recovery considerations.

Twofactor
Back to Growth Hub