High-impact
Enable MFA
Turn on multi-factor authentication for email, file transfer and remote access. It is one of the most common gaps in incident root cause analyses, and it can be updated very quickly.
Why this matters
Multiple incident root cause analyses start with a password that worked when it shouldn't have. A second factor stops that chain at the first link, and it does so for every account at once rather than one system at a time.
You do not need new software. Every mail provider, file transfer service and remote access tool already supports it — this checklist walks you through turning it on in the order that removes the highest risk first.
Enable MFA — checklist
- List every system that touches content or company email: mail, file transfer, remote access, storage, review platforms, project tools. Note who administers each one.
- Start with email. It is the account used to reset all the others, so protecting it first limits the damage everywhere else.
- Turn MFA on for administrators first, confirm it works, then enable it for everyone. Do not leave admins as the exception — they are the accounts worth stealing.
- Then file transfer and remote access: anything reachable from outside the building, including VPN and any remote desktop.
- Prefer an authenticator app or a hardware key over SMS codes. Use SMS only where nothing else is offered.
- Deal with shared mailboxes and service accounts. Give each person their own login where you can; where you cannot, record who holds the credentials, how they are rotated, and monitor its use.
- Generate recovery codes for each system, store them somewhere the whole team can reach in an emergency, and make sure more than one person can.
- Tell staff and freelancers before it switches on, with a line on what to expect and who to ask for help.
- Check enrolment after a week and chase anyone who has not completed it. A rollout at 80 percent leaves the same gap you started with.
- Add MFA setup to onboarding, so every new starter is covered without anyone remembering to ask.
Keep going
If this one helped, try another.
Consider these suggestions for what to do next. They either address the same gaps, or are logical next steps.
High-impact
Check for leaked passwords
Free breach-lookup services tell you which of your company addresses appear in known password dumps. Anything that shows up needs changing today.
Fix itThis weekOpen →
Tells you which accounts to start with.
High-impact
Stop account sharing
Replace shared and default logins with individual accounts, so activity is traceable to a person and access ends when they do.
Fix itThis weekOpen →
The other half of the MFA job.
High-impact
Reduce access
Give each person access only to the systems and projects their current work requires, review it when their role changes, and remove it the day they leave.
Fix itThis weekOpen →
Same afternoon, same admin screen.
Gap Analysis
Find Your Gaps
The free TPN Questionnaire measures your current practices against the MPA Content Security Best Practices, giving you a clear picture of your gaps and a route to closing them.
Fix itThis quarterOpen →
Tells you which fix matters most for you.