Use this checklist to confirm that your business can control and recover its important accounts. It is an owner-level self-audit, not a password list.
The aim is simple: the business should not lose access because one employee, contractor, IT provider, phone or personal email address is unavailable.
How to use this checklist
Work through the accounts that keep the business operating. For each one, record the business purpose, business-controlled owner email, primary administrator, authorized backup, MFA and recovery method, billing or ownership evidence, vendor authorization status and the next action.
Do not place passwords, backup codes or other secrets in this checklist. Record the approved secure process and the people authorized to use it instead.
Accounts to include
- Business email and Microsoft 365 or Google Workspace
- Domain registrar, DNS, website and hosting
- Accounting, payroll, payment and banking administration
- Cloud files, password manager and backup console
- Phone or VoIP, security tools and remote support
- Core industry software, customer systems, social media and advertising accounts
Account ownership checklist
| Check | Verified |
|---|---|
| The account is registered to a business-controlled email address. | [ ] |
| The business can identify the legal account holder and current billing contact. | [ ] |
| A named primary administrator is recorded. | [ ] |
| A named, authorized backup administrator or recovery contact is recorded. | [ ] |
| MFA and recovery methods do not depend on one person’s phone or private email. | [ ] |
| Credentials and recovery information are held in the approved secure process, not in a shared document. | [ ] |
| Vendor support recognizes the owner and authorized alternates. | [ ] |
| Former staff, contractors and unneeded provider access have been reviewed. | [ ] |
| The business can explain what happens if the usual administrator cannot respond for 48 hours. | [ ] |
| The record was reviewed after the latest role, provider or system change. | [ ] |
Red flags that need attention
- A critical system is registered to a personal email address.
- A former employee or former provider is still the only administrator.
- MFA goes only to one person’s device.
- The business pays for a service but cannot pass the vendor’s ownership checks.
- The backup console, password manager or domain registrar has no authorized alternate.
- A provider has access, but the business has no record of the scope or recovery process.
What to do with gaps
Fix the accounts that would stop operations first: email, domain and DNS, accounting or payment systems, cloud files, backups and key line-of-business software. Use named accounts and least privilege, keep recovery material in approved secure storage and make vendor authorization explicit.
The Canadian Centre for Cyber Security recommends unique individual accounts, least privilege and an account lifecycle process. Its guidance on administrative privileges also notes that organizations using cloud or managed service providers remain responsible for access control and should retain control of credentials and authentication processes.
Turn the list into a recovery plan
A completed checklist tells you where the gaps are. CyberTECT’s Break-Glass Readiness Review helps an owner validate the recovery path, alternate authority, provider contact route and evidence of control without collecting passwords.
Start with the private 3-Minute Break-Glass Readiness Check, or use the Digital Operations Checkup for a broader owner-level review.
Related CyberTECT guidance
- Who Owns Your Business Accounts and Passwords?
- What Happens If the Person Who Manages Your Accounts Leaves or Is Unavailable?
- How to Set Up Emergency Access for Critical Business Systems
- Digital Operations Control Check
Sources and further reading
- Canadian Centre for Cyber Security: Implement access control and authorization
- Canadian Centre for Cyber Security: Managing and controlling administrative privileges
This article provides general operational cybersecurity information. It is not legal, privacy, insurance, employment, professional-regulatory or incident-response advice.
CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.