Cybersecurity That Works: Protect Your Accounts, Verify Requests, and Prepare to Recover

Strong cybersecurity starts with repeatable business processes. Learn how to protect accounts, verify payment requests, maintain systems, and prepare to recover from attacks.

A message arrives from a familiar vendor asking your finance team to update its banking details. The branding looks right. The language sounds professional. There is even a plausible explanation: the vendor has changed banks.

The decisive question is not whether someone can spot a suspicious phrase. It is whether your business has a process that requires independent verification before money moves.

That distinction captures what effective cybersecurity looks like. Security tools matter, but they work best when supported by clear responsibilities, repeatable decisions, and tested recovery procedures. A business cannot purchase its way out of every cyber risk. It can make common attacks harder to execute and reduce the damage when something goes wrong.

For business owners and leaders, the priorities are practical: protect important accounts, stop trusting unexpected requests at face value, maintain systems, and prove that critical operations can recover.

Make Cybersecurity a Business Discipline

Cybersecurity protects more than computers. It protects the information, services, relationships, and revenue your organization depends on. That makes it a leadership responsibility, even when technical work is delegated to an internal team or outside provider.

NIST’s small-business cybersecurity guidance provides a useful foundation: understand your risks, implement protections, and improve continuously. Begin by identifying what would most disrupt your business if it became unavailable, exposed, or manipulated.

  • Important accounts: Email, banking, payroll, cloud storage, and administrator access.
  • Critical information: Customer records, contracts, financial data, and intellectual property.
  • Essential services: The systems needed to serve customers, communicate, and collect payments.
  • Responsible people: Whoever owns account security, updates, backups, and incident coordination.

Keep this inventory manageable. Its purpose is to help you prioritize, not produce a document nobody uses. Include outside providers, and clarify which security tasks they perform versus which remain your responsibility.

Cybersecurity becomes more effective when every important safeguard has an owner and a way to verify that it works.

Protect Accounts with Stronger Authentication

A stolen password should not be enough to enter your business. Multifactor authentication, or MFA, adds protection beyond a password. Enable it wherever available, starting with email, financial services, remote access, and administrator accounts.

However, MFA methods are not equally resistant to attack. A criminal can build a fake login page that captures both a password and a one-time code. Text-message authentication also carries risks associated with control of the phone number.

NIST’s MFA guidance explains why phishing-resistant authentication deserves special attention. Options such as FIDO/WebAuthn security keys and supported passkeys bind authentication to the legitimate service, making them resistant to credential-stealing websites.

Choose Protection That Fits the Account

Use phishing-resistant options where supported, particularly for sensitive and administrator accounts. Where they are unavailable, another supported MFA method is generally preferable to leaving an account protected only by a password.

Do not assume every passkey deployment automatically satisfies your organization’s MFA requirements. Implementation, device protection, account recovery, and applicable policies still matter.

Practical action: Review the security settings of your important accounts. Record available authentication options, enable appropriate protection, and secure recovery methods. Store recovery codes safely—not in an exposed document beside the password they are meant to protect.

Use Unique Passwords Without Relying on Memory

When a service still requires a password, use a long, unique one. Reusing credentials creates a chain reaction: exposure at one service can give attackers a starting point at others.

A password manager makes unique passwords practical. It can generate and store credentials so employees do not have to invent memorable variations or keep passwords in spreadsheets. NIST’s password guidance supports using password managers and strong passwords rather than relying on reuse.

Protect the password manager itself with a strong master password and MFA where supported. For business use, establish rules for sharing credentials, recovering access, and removing access when employees leave.

Practical action: Replace reused passwords on sensitive accounts first, then work through the remaining accounts. Avoid shared administrator credentials where individual accounts are available; individual access makes permissions and accountability easier to manage.

Verify Requests Before Sharing Information or Sending Money

Phishing defense should not depend on employees finding spelling mistakes. Fraudulent messages can be polished, accurately branded, and built around real business relationships. AI-generated writing and convincing voice impersonation make appearance and familiarity even less reliable.

The stronger defense is a verification process. The FTC’s small-business cybersecurity guidance recommends independently visiting account websites and using known, trusted phone numbers to confirm suspicious requests. It also recommends policies requiring confirmation of emailed wire-transfer requests.

Build Verification into the Workflow

Suppose a supplier requests a change to its payment destination. The employee handling the request should contact the supplier using a number already held in approved records—not the number included in the message. Any required payment approvals should still apply after verification.

  • Unexpected login request: Open the service through a trusted bookmark or independently entered address.
  • Changed payment instructions: Confirm through a separate, trusted channel before changing records or transferring funds.
  • Sensitive-information request: Verify the requester’s identity, authority, and business need.
  • Urgent executive instruction: Follow the established approval process, even when the message demands secrecy or speed.

Give employees a clear reporting channel and permission to pause. Treat prompt reporting as useful risk reduction, including when someone has already clicked a link or shared information.

Keep Software Current—and Prove Backups Work

Assign Responsibility for Updates

Software vulnerabilities do not disappear because a device still appears to work. Enable automatic updates where appropriate, and assign responsibility for maintaining business applications, operating systems, browsers, phones, and network equipment.

Some business systems require testing or scheduled maintenance before updates. That is a reason to manage the process, not leave it open-ended. Track exceptions and replace unsupported software that no longer receives security fixes.

Limit administrator access to people who need it. An employee performing routine work should not have unrestricted control simply because it is convenient.

Test Recovery, Not Just Backup Completion

A successful backup notification does not prove that your business can recover. Backups may be incomplete, corrupted, inaccessible, or reachable by the same attacker who compromises production systems.

Maintain protected backups of critical data, including offline or appropriately isolated copies. Encrypt backups where appropriate, protect their access credentials, and ensure recovery does not depend entirely on the environment you may need to rebuild.

Practical example: Restore a sample customer record, an important shared folder, and relevant application data into a safe test environment. Confirm that the information is complete, readable, and usable. Document how long restoration takes and what dependencies are required.

Compare those results with business needs. If operations depend on a system returning quickly, a backup that takes too long to restore leaves a meaningful gap. Cloud storage and synchronization are not automatically substitutes for a recoverable backup.

Decide How to Respond Before an Incident Occurs

During an incident, confusion consumes time. Prepare a short response plan that identifies who receives reports, who coordinates technical assistance, who authorizes business decisions, and how employees will communicate if normal email is unavailable.

Include contacts for relevant service providers, legal counsel, and insurers where applicable. Identify essential operations and practical alternatives if systems must remain offline. Keep an accessible copy of the plan outside the systems it covers.

For suspected ransomware, the FTC advises disconnecting infected devices from the network without powering them down, because shutdown can destroy useful investigative information. Involve qualified technical responders promptly rather than improvising cleanup or deleting evidence.

Rehearse the plan with a realistic scenario: an employee reports a compromised email account, followed by suspicious payment requests. Who secures the account? Who checks related access? Who contacts the bank if money moved? Who determines whether notification obligations apply?

A discussion like this exposes gaps before an emergency does. Update the plan when systems, providers, or responsibilities change.

A Practical Cybersecurity Checklist

Use this checklist to turn priorities into accountable work:

  • Identify critical accounts, information, systems, and service providers.
  • Enable MFA and prioritize phishing-resistant options for sensitive access.
  • Replace reused passwords and secure the password manager.
  • Review permissions and remove unnecessary or departed-user access.
  • Require independent verification of payment changes and sensitive requests.
  • Publish a simple way to report suspicious activity.
  • Assign ownership for updates and track unsupported systems.
  • Protect backups and test whether important data can be restored.
  • Document incident contacts, decision-makers, and continuity procedures.
  • Rehearse the response plan and correct the gaps it reveals.

Start Small, Then Make Improvement Routine

No single control guarantees protection from every breach. The goal is to reduce avoidable risk and build a business that can respond effectively when prevention falls short.

Start with one important account, one verification rule, and one recovery test. Then assign owners and repeat. Put cybersecurity on the operating agenda, review what is working, and address what is not. Consistent follow-through turns security from a collection of tools into a dependable business practice.

Browse all insights · Contact Bart McDonough