Skip to content
CyberTECTDigital operations control
All resources

Small Business Account Ownership Checklist

A practical owner self-audit to confirm that critical business accounts, recovery methods and vendor contacts remain under business control.

Use this checklist to confirm that your business can control and recover its important accounts. It is an owner-level self-audit, not a password list.

The aim is simple: the business should not lose access because one employee, contractor, IT provider, phone or personal email address is unavailable.

How to use this checklist

Work through the accounts that keep the business operating. For each one, record the business purpose, business-controlled owner email, primary administrator, authorized backup, MFA and recovery method, billing or ownership evidence, vendor authorization status and the next action.

Do not place passwords, backup codes or other secrets in this checklist. Record the approved secure process and the people authorized to use it instead.

Accounts to include

  • Business email and Microsoft 365 or Google Workspace
  • Domain registrar, DNS, website and hosting
  • Accounting, payroll, payment and banking administration
  • Cloud files, password manager and backup console
  • Phone or VoIP, security tools and remote support
  • Core industry software, customer systems, social media and advertising accounts

Account ownership checklist

Check Verified
The account is registered to a business-controlled email address. [ ]
The business can identify the legal account holder and current billing contact. [ ]
A named primary administrator is recorded. [ ]
A named, authorized backup administrator or recovery contact is recorded. [ ]
MFA and recovery methods do not depend on one person’s phone or private email. [ ]
Credentials and recovery information are held in the approved secure process, not in a shared document. [ ]
Vendor support recognizes the owner and authorized alternates. [ ]
Former staff, contractors and unneeded provider access have been reviewed. [ ]
The business can explain what happens if the usual administrator cannot respond for 48 hours. [ ]
The record was reviewed after the latest role, provider or system change. [ ]

Red flags that need attention

  • A critical system is registered to a personal email address.
  • A former employee or former provider is still the only administrator.
  • MFA goes only to one person’s device.
  • The business pays for a service but cannot pass the vendor’s ownership checks.
  • The backup console, password manager or domain registrar has no authorized alternate.
  • A provider has access, but the business has no record of the scope or recovery process.

What to do with gaps

Fix the accounts that would stop operations first: email, domain and DNS, accounting or payment systems, cloud files, backups and key line-of-business software. Use named accounts and least privilege, keep recovery material in approved secure storage and make vendor authorization explicit.

The Canadian Centre for Cyber Security recommends unique individual accounts, least privilege and an account lifecycle process. Its guidance on administrative privileges also notes that organizations using cloud or managed service providers remain responsible for access control and should retain control of credentials and authentication processes.

Turn the list into a recovery plan

A completed checklist tells you where the gaps are. CyberTECT’s Break-Glass Readiness Review helps an owner validate the recovery path, alternate authority, provider contact route and evidence of control without collecting passwords.

Start with the private 3-Minute Break-Glass Readiness Check, or use the Digital Operations Checkup for a broader owner-level review.

Related CyberTECT guidance

Sources and further reading

This article provides general operational cybersecurity information. It is not legal, privacy, insurance, employment, professional-regulatory or incident-response advice.

Using this guidance

CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.

Authoritative sources & further guidance

Examine the official guidance behind this topic.

These links lead to primary government, standards-body or institutional sources. They support the page’s guidance but do not turn a CyberTECT service into legal advice, certification or a complete framework assessment.

Information and authoritative sources last reviewed: July 2026. Edition-specific, regulatory and program details should be checked against the linked official source before use.

Discover more from Cybertect

Subscribe now to keep reading and get access to the full archive.

Continue reading