Small business cyber safety

Protect the Email Account That Can Reset the Whole Business

If one business email account is compromised, a criminal may gain the starting point for invoices, password resets, supplier conversations and access to other core systems.

For many small businesses, email is not just a communication tool. It is the recovery path for accounting software, cloud storage, banking alerts, supplier conversations, website administration, domain renewals and staff access. If a criminal gets control of the wrong mailbox, they may not need to break everything at once. They can use that mailbox to request resets, intercept messages and quietly redirect the next important decision.

Cyber.gov.au warns that if someone gains unauthorised access to, or impersonates, your email account, they can intercept private communications and use business email compromise to target invoices and other financial transactions. That is why the first account to harden is usually not social media or the least-used old portal. It is the email account that can open the rest.

Start with these three mailboxes

  1. The owner or administrator mailbox: the account that receives password resets, domain notices, hosting notices and administrator prompts.
  2. The accounts or invoicing mailbox: any address that receives supplier invoices, payment queries or remittance notices.
  3. The mailbox tied to shared business platforms: the address linked to website tools, Microsoft 365, Google Workspace, booking systems, cloud storage or marketing platforms.

If your business is very small, one mailbox may perform all three jobs. That makes protecting it more urgent, not less.

Why email deserves the strongest protection first

Email often sits at the centre of account recovery. A criminal who controls it may be able to approve password resets, read verification messages and learn how your business works from old conversations. They do not need to attack every service separately if the mailbox already receives the keys.

  • Invoices and bank-detail changes often arrive by email.
  • Password resets for cloud services, shopping accounts, websites and staff tools usually arrive by email.
  • Domain registrar and hosting notices often go to one long-standing business address.
  • Customer and supplier trust can be abused if a criminal replies from the real mailbox or a convincing look-alike.
  • Internal changes such as adding a user, exporting data or changing recovery details may trigger email approvals.

The practical lesson is simple: the mailbox with the most recovery power should have the strongest sign-in protection and the most deliberate review routine.

Map what your main business email can reset

A useful ten-minute exercise is to write down what the primary business mailbox can unlock today. Do not stop at obvious inbox access. List the systems that trust that mailbox as proof of identity.

  • accounting and invoicing platforms;
  • banking alerts and payment-approval workflows;
  • Microsoft 365, Google Workspace or other cloud administration;
  • website hosting, DNS and domain registrar accounts;
  • customer relationship or booking systems;
  • social pages and advertising accounts; and
  • password manager recovery routes or administrator invitations.

This simple inventory turns “start with email” into a practical business exercise. Once you can see the recovery pathways, you can decide which mailbox deserves the strictest rules and which services must not share the same fallback details.

Changing the password may not finish the job

Cyber.gov.au’s recovery guidance makes an important point that many owners miss: after suspicious email activity, you need to review more than the password. A compromised mailbox can stay risky if the attacker has changed recovery details, created forwarding rules or left another access path behind.

Review these items in order:

  1. Recovery details: check recovery email addresses and phone numbers. Cyber.gov.au notes that an attacker may change them so they can regain access later.
  2. Active sessions and remembered devices: sign out of other sessions so an old login is not left open after the password change.
  3. Forwarding rules and filters: Cyber.gov.au’s email-account review guide specifically says to check rules, blocked addresses, forwarding and POP/IMAP settings.
  4. Delegated access and shared mailboxes: confirm no extra user still has inbox access through a role you forgot about.
  5. Connected applications: review which apps and plugins can read or send mail on the account’s behalf.

A password change can be a strong containment step, but it is not always the whole clean-up.

The protection baseline for a small business mailbox

Australian government guidance is consistent on the basics. The strongest starting set for a small business mailbox is still practical and achievable:

  • Use a strong unique password or passphrase, ideally stored in a reputable password manager rather than reused across services.
  • Turn on multi-factor authentication, especially for owner, accounts and administrator mailboxes.
  • Limit administrator access. Cyber.gov.au advises avoiding administrator-level access unless a person genuinely needs it.
  • Give staff only the access they need. business.gov.au’s small-business checklist includes limiting staff access to the systems required for their role.
  • Keep software and devices updated, because inbox security still depends on the device used to reach it.

If a provider offers named user accounts, use them instead of shared credentials. An accounts team can still share a mailbox or workflow, but each authorised person should normally reach it through their own sign-in.

A first-day email hardening checklist

  1. Choose the one mailbox whose compromise would hurt most.
  2. Turn on multi-factor authentication for that account first.
  3. Update the password to a strong unique value and store it safely.
  4. Check recovery email addresses, phone numbers and backup methods.
  5. Review inbox rules, forwarding, POP/IMAP settings and delegated access.
  6. List the services that send resets or approvals to that mailbox.
  7. Move high-consequence services away from old personal addresses where necessary.
  8. Record who should be alerted if suspicious activity appears.

That is a realistic first-day improvement for a microbusiness without waiting for a full IT project.

If you suspect the mailbox has already been misused

Work from business consequences first. If invoices, banking details or customer messages may have been affected, treat it as a broader business incident rather than a private sign-in problem.

  1. Protect money first: if bank details or card details may be exposed, contact your financial institution immediately.
  2. Contain mailbox access: change the password, sign out of sessions and review recovery details.
  3. Check what the attacker changed: review rules, forwarding, blocked addresses, sent mail and administrator actions.
  4. Warn the right people: tell staff, suppliers or customers if they may receive fraudulent requests from your business address.
  5. Report the incident: Cyber.gov.au provides a business-email-compromise recovery path and ReportCyber reporting route.

Do not wait for the mailbox itself to “look hacked”. Cyber.gov.au notes that some businesses first discover compromise only after a contact reports a suspicious message.

Keep the recovery path separate where you can

As the business grows, it helps to reduce single points of failure. That does not mean creating a maze of unused inboxes. It means being deliberate about where the most powerful recovery notices go.

  • avoid using one old personal email account as the fallback for every business service;
  • review whether domain, hosting and cloud-administration notices all land in the same mailbox;
  • keep recovery methods current when staff, contractors or family helpers leave; and
  • document who owns key mailboxes without writing secret values into public procedures.

The goal is not complexity for its own sake. The goal is to stop one compromised mailbox from silently becoming the master key to the business.

Sources and further reading

Frequently asked questions

Is a shared accounts inbox always unsafe?

No. The safer pattern is for authorised staff to reach a shared mailbox through their own named accounts, rather than everyone signing in with one shared password.

What if I cannot harden every business account this week?

Start with the mailbox that receives the most resets, approvals and payment-related messages. Protect the highest-consequence recovery path first, then work down the list.

Related articles

Browse all cyber safety articles