Skip to content
CyberTECTDigital operations control
All resources

How to Set Up Emergency Access for Critical Business Systems

Emergency access is not a shared password spreadsheet. It is a tested, controlled way for authorized people to regain access when an owner, employee, device or provider is unavailable.

Emergency access is about continuity, not sharing passwords

A business can lose control of critical systems when an owner is unavailable, an employee leaves, a phone is lost, an administrator account is locked, a provider relationship fails or a cyber incident interrupts normal access.

The answer is not an unsecured spreadsheet of passwords. Emergency access is a documented and tested way for the right authorized people to find the system owner, start recovery, contact the provider and continue essential work without exposing credentials to everyone.

Identify the systems that would stop the business first

Start with business email and identity administration, then list the domain, website, cloud files, accounting, banking and payment administration, payroll, backup systems, phones or communications, social accounts and essential vendor portals. For each one, record:

  • the business owner and backup authorized person;
  • the administrator or recovery account;
  • the provider and trusted support contact;
  • the approved recovery method and where it is documented;
  • the information needed to verify ownership; and
  • what work must continue if the system is unavailable.

Design the access path with separation of duties

One person should not be the only person who can recover every important account. At the same time, not everyone should receive administrator rights “just in case.” Name a small number of authorized roles, give them only the access they need, and decide in advance who can authorize a recovery or payment-related action.

Where technology supports emergency or break-glass accounts, protect them carefully, document their purpose and monitor their use. Keep recovery contacts and instructions accessible even during an email or cloud outage. The Cyber Centre recommends offline access to incident plans because systems may be unavailable when they are needed most.

Keep the record useful and safe

A practical emergency record includes system names, owners, provider contacts, account-recovery paths, priority order, decision-makers and escalation instructions. It should point to the approved password manager or credential-control process, not contain passwords or one-time codes in plain text.

Review it when a person leaves, a phone number changes, a vendor changes, a new critical system is adopted or business ownership changes. Then test one or two scenarios: can the alternate administrator regain access to email? Can leadership contact the backup provider? Can the team find the current domain registrar?

Common gaps worth fixing now

  • The domain, Microsoft 365 tenant or website is registered to one person’s personal email.
  • Only one person receives MFA prompts or holds recovery codes.
  • A provider has administrator access but the business cannot explain what it owns.
  • Financial-release authority, account recovery and technical administration are all concentrated in one person.
  • The incident plan is stored only in the system likely to be unavailable.

CyberTECT’s Break Glass Readiness Review focuses on these practical handoffs, account ownership and recovery paths. It is not a substitute for legal authority, banking authority, estate planning or an organization’s own management decisions.

Not sure where you stand? Take the private 3-Minute Break-Glass Readiness Check before deciding whether a fixed-scope review is useful.

Related CyberTECT guidance

Sources and further reading

Using this guidance

CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.

Authoritative sources & further guidance

Examine the official guidance behind this topic.

These links lead to primary government, standards-body or institutional sources. They support the page’s guidance but do not turn a CyberTECT service into legal advice, certification or a complete framework assessment.

Information and authoritative sources last reviewed: July 2026. Edition-specific, regulatory and program details should be checked against the linked official source before use.

Discover more from Cybertect

Subscribe now to keep reading and get access to the full archive.

Continue reading