A stolen password should not be enough to take control of your business email, domain or website. Two-step verification adds another check when you sign in, helping protect accounts when a password is exposed.
Start with the accounts that control everything else
Prioritise email, domain registration, hosting and administrator accounts. Email is especially important because password-reset messages often arrive there. Give each person their own account where the service supports it, rather than circulating one shared administrator password.
Use the strongest supported sign-in method you can maintain
Services may offer security keys, passkeys, authenticator apps or codes sent through other channels. Follow the provider’s setup instructions and use an option your team can use reliably. Never approve an unexpected sign-in request or share a verification code with someone who contacts you.
Prepare for losing a device
Store recovery codes securely and document an appropriate recovery process. Check that recovery email addresses and phone numbers are current. Do not make one employee’s personal device the only way the business can regain access to an essential service.
Keep the rest of the account secure
- Use unique passwords and a reputable password manager.
- Remove access promptly when someone leaves.
- Keep devices and applications updated.
- Check suspicious messages through a known contact route before acting.
Two-step verification reduces risk, but it is not protection against every attack. Treat it as part of ordinary account management, with recovery arrangements that have been checked rather than assumed. The NCSC’s two-step verification guidance explains the setup and recovery considerations.
