Verify the accounts that run your organization.
Business account security is not only about having strong passwords. Verify who has access, what each account can do, how it can be recovered and whether an unusual request is actually legitimate before it changes money, data, systems or public communications.
Start with the accounts that could cause the greatest business impact. Then verify the identity of people, applications and requests through established channels, limit access to what is necessary, review access regularly and make sure recovery routes are controlled by the organization.
These controls are also reflected in established cybersecurity guidance for organizations: protect important accounts with strong authentication, avoid unnecessary shared credentials, remove access when roles change or people leave, and restrict privileged access.
What should never be shared?
Never give a caller, colleague, vendor or supposed support agent a password, OTP, PIN, backup code, recovery phrase, private key or other authentication secret simply because they claim to need it for business-account support.
Work through the control chain.
A business account should be verified as a system of access, authentication, recovery and permissions. It is more than a username and password.
Use individual accounts instead of shared passwords
Why does this matter?
Verify MFA on important accounts
Why does this matter?
Check recovery methods
Why does this matter?
Review active sessions and connected applications
Why does this matter?
Separate routine access from administrative access
Why does this matter?
Apply least privilege
Why does this matter?
Verify role and offboarding changes
Why does this matter?
Verify unusual support or security requests independently
Why does this matter?
Verify payment and beneficiary changes separately
Why does this matter?
Review who can publish or represent the organization
Why does this matter?
Test the recovery path without exposing secrets
Why does this matter?
Verify before approving or trusting.
These examples turn the account-security principles into decisions that a business owner, manager, finance officer or staff member may actually face.
The Shared Business Password
Situation: A small business uses one shared password for its main email account because several staff members need access. A new staff member asks for the password too.
Safer verification: Move toward individual accounts or controlled delegated access, enable appropriate authentication and stop expanding the shared credential.
The Unexpected Business Administrator
Situation: A business discovers that an unfamiliar person has administrator access to an important cloud service.
Safer verification: Do not assume the account is legitimate because it has an official-looking name. Preserve relevant account information, review the service's official administrator controls and independently verify who should have access.
The Supplier Bank-Account Change
Situation: A supplier emails that its bank account has changed and asks the business to send today's payment to the new account.
Safer verification: Pause the payment and confirm the change using a phone number or other contact method already stored in the business's records.
The CEO Payment Request
Situation: A message that appears to come from a senior executive asks finance to make an urgent payment to a new beneficiary.
Safer verification: Follow the organization's normal payment controls and independently confirm the request with the executive or an established approval channel.
The Fake IT Support Call
Situation: Someone calls claiming to be the company's IT provider and says they need the administrator password and a verification code to fix a security problem.
Safer verification: Do not disclose the secrets. End the call and contact the IT provider through a known official channel.
The Former Employee Still Has Access
Situation: An employee leaves the organization, but their account still appears to have access to email, cloud files or a payment platform.
Safer verification: Use the official administration controls to disable or remove access and review related sessions, delegated access and shared resources.
The Unfamiliar Recovery Email
Situation: The recovery email address on an important business account has changed, but no one on the team recognizes the new address.
Safer verification: Treat the change as a security event. Use the service's official account-security and recovery process and independently verify the responsible administrator.
The New Cloud App Integration
Situation: A staff member is asked to connect an unfamiliar application to the company's cloud storage to make work easier.
Safer verification: Verify the application, its publisher, requested permissions and legitimate business need before granting access. Use the least-permissive option available.
The Social-Media Administrator Request
Situation: A person says they are helping the business with marketing and asks for the password to the company's social-media account.
Safer verification: Do not share the password. Use the platform's official role or delegated-access controls where available and verify the person's role through an established business process.
The Domain Renewal Message
Situation: An email says the company's domain expires today and provides a payment link.
Safer verification: Do not pay through the message. Open the domain registrar's official website or account directly and check the actual renewal status there.
The Emergency Security Upgrade
Situation: A message says the business must install a security tool immediately or its banking and accounting systems will stop working.
Safer verification: Verify the claim through the software vendor, bank or IT provider using independently obtained official contact details before installing anything.
The New Employee Needs Access
Situation: A new employee needs access to customer files and business email on their first day.
Safer verification: Give only the access required for the role, use an individual account and enable the organization's normal authentication and access controls.
Before you consider an important business account protected, ask:
- Which business accounts could cause the greatest harm if compromised?
- Does each important user have an individual account rather than a shared password?
- Is appropriate MFA enabled on high-impact accounts?
- Are recovery methods current and controlled by the organization?
- Have active sessions and connected applications been reviewed?
- Are administrator privileges limited to people and tasks that need them?
- Is there a clear process for joiners, role changes and leavers?
- Are unusual support and payment requests independently verified?
- Can the organization recover each high-impact account through an official process without sharing secrets?
- Who is responsible for reviewing business-account access and security regularly?
A “yes” should mean the control is actually configured and understood. Do not rely merely on someone believing it is in place.
If a business account may already be compromised, stop unsafe activity, preserve useful evidence and use the service's official security or recovery process.
Open First Response Guidance →Return to Module 23 →Familiarity, job title, company branding, an urgent request or administrator status is not proof by itself. Verify the access, identity and request through a trusted route before acting.
