Business path
8 min read
Rolling out MFA and backups with a small team
Two protections that cover most of the danger
Two habits protect a small business against most of what goes wrong online. The first, multi-factor authentication (MFA), stops a stolen password from being enough to break into your accounts. The second, backups, means that even if data is lost, deleted, or locked up, you still have a copy.
This lesson is a runbook you can follow with a few staff. You do not need to be technical. You will roll out MFA one account at a time, then set up backups you have genuinely tested. Take it in the two parts below and do not rush to finish both in one sitting.
Part one: rolling out MFA
Multi-factor authentication (MFA) adds a second step to logging in, usually a code on your phone, so that a stolen password alone is never enough to get in. Rolling it out across a small team is not hard if you go in order.
Step 1: list the accounts that matter
Before touching any settings, write a short list of the accounts that would actually hurt you if someone broke in. For most small businesses that means:
- Email, especially the main address that other accounts reset to
- Banking and payments
- Anything holding customer data, such as your bookings, your shop admin, or your contact lists
You do not need to protect every login you have ever made. Focus on the handful that carry real weight.
Step 2: enable MFA one account at a time
Turn MFA on for one account, confirm you can still log in with the new second step, and only then move to the next. Doing them one at a time, rather than all at once, means that if something feels confusing you can sort it out before it affects anything else.
Start with email, because it is the account that can reset all the others.
Step 3: save the recovery codes offline
When you switch on MFA, most services offer a set of recovery codes: one-time backup codes that get you in if you ever lose your phone. Do not skip this. Without them, a lost or broken phone can lock you out of your own account.
Save the recovery codes somewhere safe and offline, such as written down and kept in a locked drawer, not in the same inbox they are meant to protect.
Step 4: help each staff member set up their own
MFA only closes the door if everyone uses it. Sit with each staff member and help them turn it on for their own logins to the accounts that matter. It takes a few minutes per person and it means that a single stolen password, from any one of you, is never enough on its own.
Keep the tone helpful, not policing. You are handing the team a lock for their own front door, not adding a chore.
Part two: backups you can trust
A backup is simply a spare copy of your important data, kept somewhere separate, so that a lost device, a mistake, or an attack does not erase your records.
Step 1: decide what genuinely must be backed up
You do not need to back up everything. Decide what you truly could not run the business without: your customer records, your bookings, your accounts and invoices, the files your work depends on. That short list is what matters.
Step 2: keep more than one copy, in more than one place
Here is the simplest way to think about it. Keep more than one copy of anything important, and make sure at least one of those copies is not sitting on the same device as the original.
If your only copy lives on the shop laptop, then the day that laptop is stolen, dropped, or locked up, the copy goes with it. A second copy kept somewhere else, on a separate drive or a reputable online service, survives when the main device does not. More than one place is the whole idea.
Step 3: automate it if you can
A backup you have to remember to run is a backup that will eventually be forgotten. If your tool can run backups on a schedule by itself, turn that on. The best backup is the one that keeps happening without anyone thinking about it.
Step 4: test a restore before you need one
This is the step people skip, and it is the one that matters most. A backup is only real once you have restored from it. Pick a file, restore it from your backup, and open it. If it opens cleanly, your backup works. If it does not, you have just learned that on a calm afternoon instead of on your worst day.
Put a reminder in your calendar to test a restore every few months. Data changes, tools change, and a backup that worked last year is not proof it works today.
Warning
Two classic failures turn a backup into a false sense of safety. The first is never testing the restore, so you only discover the backup was empty or broken on the day you desperately need it. The second is keeping your only backup connected to the very machine it is meant to protect, so when that machine is stolen or locked up, the backup is taken or locked with it. Test your restores, and keep at least one copy separate.
Putting it together
Work through the accounts that matter and turn on MFA one at a time, saving the recovery codes offline and helping each staff member do the same. Then decide what must be backed up, keep more than one copy with at least one kept separately, automate it, and test a restore so you know it works. Neither part needs a technical background, only an afternoon and the willingness to go step by step. Together they mean that a stolen password will not open your accounts, and a bad day will not erase your business.
Found something unclear, outdated or improvable? Suggest an improvement