Skip to main content
Guidance

Using online services safely

How small organisations can reduce the likelihood of cyber attacks when using online ‘cloud’ services.

Page 7 of 10

Protecting your admin accounts

iStock.com/Yevhenii Dubinko

Most services are designed so you can only change important settings and manage other users' accounts by using an administrator (or ‘admin’) account. These admin accounts have access to additional functionality, and are usually held by more technical staff who are responsible for managing the online service (including which users can access it).

It is crucial that you protect these powerful admin accounts against attack. An attacker can access more data (and therefore do more damage) if they successfully compromise an admin account. For example, they can often read all users' emails, delete all users' files and backups, or approve large invoices/transactions.

Admin accounts can also be used to regain control of other user accounts that an attacker has breached. Therefore it’s important that you:

  • protect all admin accounts using 2SV
  • know how to access all your admin accounts so you can recover from a cyber attack

It’s a good idea to have more than one admin account, each managed by a separate person. This means that if one of these accounts is lost or compromised, another one can be used to start cleaning things up, while the first is being recovered.

  • Tip 4: Limit the use of admin accounts

    You should only give admin accounts to the people in your organisation that really need it. If a member of staff leaves your organisation (or changes roles), make sure their account is revoked if it's no longer required. This applies to all accounts, but it is especially important for any admin accounts. This should be done promptly - ideally before they move - in case there's any animosity surrounding their departure or move.


    Every user should have a normal user account for day-to-day use. Staff requiring an admin account should:

    • have an additional admin account created
    • only use their admin account to perform administrative activities
    • use their normal work account for day-to-day activities
  • Tip 5: Add recovery information

    If you lose all access to your admin accounts, you should contact the provider of the online service in the first instance. Make sure that any contact email addresses, company information, phone numbers, and postal addresses associated with the account are kept up to date. This means you can verify yourself with the account provider as the legitimate owner, and recover access.


    If you’re asked to provide a ‘backup’ email address, make sure it’s run by a different provider, and uses a different password. Similarly, if you’re asked to save backup or recovery codes, you should make sure these are stored somewhere safe that you can access even if you lose access to your email account. This can include:

    • making a printed (or written) copy
    • saving them to a separate USB stick

    Whichever method you use, you should store them in safe place that you can access in case of an emergency.

Published

Reviewed

Version

1.0