A second step

A password alone is not enough. When you sign in, you also confirm with your phone, a key or a passkey that it is you.

A key or a passkey

It only works on the real website. A fake login page gets nothing from it.

Weak routes closed

Text messages and voice calls are switched off as a second step once something stronger is in place.

A second way in

At least two emergency accounts with their own keys, for when the regular administrator can no longer get in.

A copy of the vault

A second copy of the password vault that still works when the first one will not open.

Recovery codes apart

Recovery codes and spare keys on paper, kept somewhere other than the accounts they are meant to rescue.

One administrator, first time

Anyone doing this alone and for the first time quickly spends several working days on it. Every choice and every surprise lands with the same person.

With a playbook

An IT provider with a standard setup does the same work in a fraction of that time. The playbook mainly provides decisions that have already been made.

Several administrators

In a larger organisation, administrators work on different parts at the same time. Most of the work then goes into bringing every employee and their devices along.

People take the path of least resistance. So set a strict minimum, and enforce it.

Codes in the vault

The recovery codes are in the password vault they are meant to open, or next to the password. Whoever has the password vault then has both steps.

One phone for everything

The emergency account can only get in with the same phone as the regular admin account. Lose that phone, and both are locked.

Recovery mail in-house

The recovery email address sits in the company's own domain. If the domain goes, the recovery mail goes with it.

Two keys in one drawer

The spare key lies next to the first. A fire or a burglary takes both.

  1. 0%
    Open doorA password only, on an entry plan.
    Protection
    Cost
    Time
    Effort
    Maintenance
  2. 25%
    Lock on the doorA mandatory second step with an app, and recovery codes on paper. Usually costs nothing extra.
    Protection
    Cost
    Time
    Effort
    Maintenance
  3. 50%
    Key and spare keyKeys or passkeys for the administrators, emergency accounts, and text messages switched off. A small purchase, once.
    Protection
    Cost
    Time
    Effort
    Maintenance
  4. 75%
    Access rulesRules that decide who signs in and how, and a password manager for everyone. A licence per user per month.
    Protection
    Cost
    Time
    Effort
    Maintenance
  5. 100%
    Bank vaultKeys for everyone, admin rights only on request and for a limited time, everything demonstrable. The most expensive plan.
    Protection
    Cost
    Time
    Effort
    Maintenance

Indicative. The dots show proportions, not measurements. Time is the setting up, effort the daily work with it, maintenance what it keeps asking afterwards.

Most of the protection comes from the first, cheap steps. Above fifty percent you mainly pay for control and for being able to prove it.

Also decide how someone gets back in after losing their key. That route has to be as strict as the normal sign-in.

Enforce the minimum, and test the safety net.