Email and payment-related communication
Phishing and account compromise can affect vendor, owner, resident, and finance workflows. Review the controls around identity and verify sensitive requests through a separate, trusted communication path.
- Use strong sign-in protection and multi-factor authentication where supported.
- Establish a verification step for payment, wire, banking, or vendor-detail changes.
- Make it easy for staff to report suspicious email and account activity.
- Limit who can approve or change banking details, vendor records, forwarding rules, and other high-impact settings.
Access changes and shared credentials
Former employee access and shared accounts create avoidable uncertainty when nobody owns the cleanup process. Treat access review as a recurring operating task and as part of every role change.
- Use named accounts where practical and review privileged access regularly.
- Remove departing employee access promptly through a documented process.
- Track shared mailboxes, vendor portals, remote access, and shared credentials that need ownership.
- Review stale guest users, recovery methods, administrator roles, and multi-factor authentication devices.
Devices, backups, and recovery
A security incident can become an operational outage if devices and recovery responsibilities are unclear. Teams should know whom to contact, what to isolate, and which business functions need to recover first.
- Keep device security and update practices current.
- Monitor backup status and plan restore testing where the selected tool supports it.
- Document the people, vendors, and systems involved in an incident response decision.
- Walk through a realistic lost-device, compromised-account, or unavailable-file scenario before an incident occurs.
Questions to ask
Does this checklist make a company compliant?+
No. This is practical IT guidance, not legal, regulatory, or compliance advice. Specific requirements should be reviewed with the appropriate advisors.
What is the first security area to review?+
Start with user accounts, sign-in protection, former employee access, shared credentials, and email workflows that involve financial or vendor information.
How often should these risks be reviewed?+
Review them on a regular schedule and after meaningful changes such as an acquisition, new office, leadership change, software migration, security event, or employee departure.
Request an IT review
