Securing email in a small business in one afternoon

Four steps that close the most common ways in, written for people without an IT department.

Most breaches I get called in to do not start with anything advanced. They start with a reused password and an alert nobody read.

The order below is the one I work in at a business with between five and fifty employees. It takes an afternoon.

Two-factor on everything, management included

Exceptions are the most common reason two-factor fails. I have seen three businesses where everyone had it except the managing director, because it was inconvenient. In two of them, that was the account that got used.

Use an app, not SMS. SMS beats nothing, but it can be taken over by someone who calls your mobile operator and claims to be you.

The order, if you only have an hour

  1. Turn on two-factor for everyone, including yourself.
  2. Remove exceptions that were made “temporarily”.
  3. Turn off legacy sign-in, which bypasses two-factor.
  4. Set an alert for sign-ins from a new country, to one named person.

None of this makes you invulnerable. It makes you a worse target than almost everyone else your size, and in practice that is what decides the outcome.

About this article

Reviewed by
The editorial desk
Published
25. July 2026
Type
Guide
Reading time
1 min read
Use of AI
Not used.

Report this article Request a correction

Noen har bruk for det du vet.

Det trenger ikke å være en stor sak. En forklaring, en erfaring, en advarsel du selv skulle hatt. Det er nok til å begynne.

Opprett skribentkonto