Emergency access is about continuity, not sharing passwords
A business can lose control of critical systems when an owner is unavailable, an employee leaves, a phone is lost, an administrator account is locked, a provider relationship fails or a cyber incident interrupts normal access.
The answer is not an unsecured spreadsheet of passwords. Emergency access is a documented and tested way for the right authorized people to find the system owner, start recovery, contact the provider and continue essential work without exposing credentials to everyone.
Identify the systems that would stop the business first
Start with business email and identity administration, then list the domain, website, cloud files, accounting, banking and payment administration, payroll, backup systems, phones or communications, social accounts and essential vendor portals. For each one, record:
- the business owner and backup authorized person;
- the administrator or recovery account;
- the provider and trusted support contact;
- the approved recovery method and where it is documented;
- the information needed to verify ownership; and
- what work must continue if the system is unavailable.
Design the access path with separation of duties
One person should not be the only person who can recover every important account. At the same time, not everyone should receive administrator rights “just in case.” Name a small number of authorized roles, give them only the access they need, and decide in advance who can authorize a recovery or payment-related action.
Where technology supports emergency or break-glass accounts, protect them carefully, document their purpose and monitor their use. Keep recovery contacts and instructions accessible even during an email or cloud outage. The Cyber Centre recommends offline access to incident plans because systems may be unavailable when they are needed most.
Keep the record useful and safe
A practical emergency record includes system names, owners, provider contacts, account-recovery paths, priority order, decision-makers and escalation instructions. It should point to the approved password manager or credential-control process, not contain passwords or one-time codes in plain text.
Review it when a person leaves, a phone number changes, a vendor changes, a new critical system is adopted or business ownership changes. Then test one or two scenarios: can the alternate administrator regain access to email? Can leadership contact the backup provider? Can the team find the current domain registrar?
Common gaps worth fixing now
- The domain, Microsoft 365 tenant or website is registered to one person’s personal email.
- Only one person receives MFA prompts or holds recovery codes.
- A provider has administrator access but the business cannot explain what it owns.
- Financial-release authority, account recovery and technical administration are all concentrated in one person.
- The incident plan is stored only in the system likely to be unavailable.
CyberTECT’s Break Glass Readiness Review focuses on these practical handoffs, account ownership and recovery paths. It is not a substitute for legal authority, banking authority, estate planning or an organization’s own management decisions.
Not sure where you stand? Take the private 3-Minute Break-Glass Readiness Check before deciding whether a fixed-scope review is useful.
Related CyberTECT guidance
- Who Owns Your Business Accounts and Passwords?
- Are Your Business Backups Actually Recoverable?
- Digital Operations Checklist for Small Businesses
Sources and further reading
- Canadian Centre for Cyber Security: Ransomware—how to prevent and recover
- Canadian Centre for Cyber Security: Baseline Cyber Security Controls for Small and Medium Organizations
- Microsoft Entra: Emergency access accounts
CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.