Why I Lock Down Two-Factor on Every Account That Touches My Business

Nov 20, 2025By Jay Kells
Jay Kells

Why I Lock Down Two-Factor on Every Account That Touches My Business

I used to think about two-factor authentication the same way most people do, as an extra step for my personal email and maybe my banking app, and not much else. That changed the moment I started running a business where other people's data passed through my accounts, not just my own. A compromised personal account is a bad day. A compromised business account can be a bad day for every client whose details were sitting inside it. That difference in stakes changed which accounts I bother locking down properly, and how strict I am about it.


The Moment the Stakes Stopped Being Just Mine


When it's just your own accounts on the line, it's easy to be a bit relaxed about security, you're the only one who pays for a mistake. That calculation completely changes once a client's contact details, payment history, or case notes are sitting inside a tool you log into. If that account gets compromised, the damage isn't contained to me, it spreads to everyone whose information I was trusted to look after. I didn't fully appreciate this shift until I actually sat down and listed every tool that holds client information, and realised how many of them still only had a password standing between someone else's data and whoever managed to guess or steal that password. That list became my starting point for where two-factor needed to go first.


Every Account That Touches Client Data Gets Priority


Not every account I use for the business carries the same risk, and I've learned to prioritise based on what's actually inside each one rather than locking everything down in a random order. My client management system, my email, and anywhere I store documents or case files went first, because those are the accounts where a breach would expose someone else's personal information, not just mine. Accounts that are more operational, a scheduling tool, a note-taking app with nothing sensitive in it, matter less urgently, though I still get to them eventually. I think this is where a lot of small business owners go wrong, they either lock down everything at once and burn out on the effort, or they never start because the full list feels overwhelming. Sorting by what's actually at risk if that specific account gets breached makes the job manageable and makes sure the most damaging gaps close first.


Shared Logins Are a Bigger Risk Than People Expect


This is the part that surprised me most once I actually looked into it properly. Any account that more than one person logs into, whether that's a shared inbox, a joint social media login, or a tool a contractor also has access to, is inherently riskier than an account only I use, because the number of ways it can be compromised multiplies with every person who has the password. Two-factor becomes even more important here, not less, because it means a leaked or reused password from any one of those people isn't enough on its own to get someone in. I've moved away from truly shared logins wherever the tool allows it, using individual accounts with proper permissions instead, but where a shared login is genuinely unavoidable, two-factor on it is non-negotiable rather than a nice-to-have.


Small business owner's hands reviewing payment processing statements and invoices on a wooden desk with natural light

The Payment and Invoicing Tools I Locked Down First


Money-adjacent accounts get treated with a different level of seriousness entirely, invoicing software, payment processors, anything connected to my business bank account. These are the accounts where a breach doesn't just expose information, it can directly cost money, either mine or a client's if fraudulent invoices go out under my name. I use an authenticator app rather than SMS codes on anything in this category specifically, since SMS-based two-factor has known weaknesses around number porting that I'd rather not rely on when actual money is the thing being protected. I've written separately about the different kinds of two-factor authentication and which one I actually trust, which goes into more detail on why I've moved away from text message codes generally, not just for financial tools.


What I Ask of Anyone I Bring In to Help


As the business has grown, I've occasionally brought in help, a contractor for a specific project, someone temporary covering a task. Every one of those situations comes with the same non-negotiable request now, two-factor gets set up on any account they're given access to before they start using it, no exceptions made for convenience or time pressure. I used to skip this for short-term arrangements, reasoning that a two-week project didn't justify the setup friction, until I realised that a short-term access window is exactly the kind of thing that gets forgotten about and left open long after the actual work is done. Now it's built into how I onboard anyone, however briefly they're involved, and I keep a simple list of who has access to what so nothing lingers past when it's actually needed.


None of this was complicated to set up, and most of it took an afternoon once I actually sat down and worked through the full list of business accounts rather than putting it off. The habit that made it stick wasn't a single big effort though, it was reviewing that list every few months alongside my wider account check-in, catching anything new that had crept in without two-factor turned on yet. If you want a reliable way to keep the accounts protecting this kind of two-factor step consistently, NordPass stores and autofills authenticator codes alongside your passwords, which removes most of the friction that makes people put this off, and my free Safety Toolkit covers the rest of what I'd recommend if you're setting this up for your own business properly. The NCSC's Cyber Essentials guidance is a solid starting point if you want a wider framework for locking down a small business beyond just two-factor.