This guide provides an operating framework, not legal, financial, safety, medical, licensing, or regulatory advice. Adapt it to your business and local requirements.
Inventory business-critical accounts
List email, field service, accounting, payments, file storage, website, and domain accounts. Record the owner, recovery method, and who should retain access when a staff member leaves.
Require strong authentication
Use unique passwords stored in a reputable password manager and enable multi-factor authentication wherever available. Avoid shared credentials because they prevent meaningful access control.
Limit access by role
Technicians, dispatchers, office staff, and external bookkeepers do not need identical permissions. Grant the minimum access required and review it when responsibilities change.
Prepare for suspicious messages
Train staff to pause when messages request credentials, payment changes, urgent downloads, or unusual account actions. Verify sensitive requests through a known, separate contact method.
Back up and test recovery
Identify the records required to resume scheduling and customer communication. Maintain protected backups and periodically restore a sample so recovery is more than an assumption.