High-impact

Enable MFA

Turn on multi-factor authentication for email, file transfer and remote access. It is one of the most common gaps in incident root cause analyses, and it can be updated very quickly.

Why this matters

Multiple incident root cause analyses start with a password that worked when it shouldn't have. A second factor stops that chain at the first link, and it does so for every account at once rather than one system at a time.

You do not need new software. Every mail provider, file transfer service and remote access tool already supports it — this checklist walks you through turning it on in the order that removes the highest risk first.

Enable MFA — checklist

  • List every system that touches content or company email: mail, file transfer, remote access, storage, review platforms, project tools. Note who administers each one.
  • Start with email. It is the account used to reset all the others, so protecting it first limits the damage everywhere else.
  • Turn MFA on for administrators first, confirm it works, then enable it for everyone. Do not leave admins as the exception — they are the accounts worth stealing.
  • Then file transfer and remote access: anything reachable from outside the building, including VPN and any remote desktop.
  • Prefer an authenticator app or a hardware key over SMS codes. Use SMS only where nothing else is offered.
  • Deal with shared mailboxes and service accounts. Give each person their own login where you can; where you cannot, record who holds the credentials, how they are rotated, and monitor its use.
  • Generate recovery codes for each system, store them somewhere the whole team can reach in an emergency, and make sure more than one person can.
  • Tell staff and freelancers before it switches on, with a line on what to expect and who to ask for help.
  • Check enrolment after a week and chase anyone who has not completed it. A rollout at 80 percent leaves the same gap you started with.
  • Add MFA setup to onboarding, so every new starter is covered without anyone remembering to ask.