That relationship is the reason to start there rather than with anything that feels more valuable. A password manager, a backup, and a secure customer system all depend on the account that can reset them. Securing email first means everything else is protecting something rather than sitting behind an open door.

The specific actions are short. A password used nowhere else, ideally generated rather than chosen. Two factor authentication enabled, using an authenticator application rather than codes by text where the option exists, because the text method is vulnerable to somebody persuading a mobile provider to move your number. And the recovery details checked, since an old phone number or a personal address you no longer use is a route in.

Understand why this matters more for a business than for a personal account. Compromises at your scale are almost never targeted. They are automated attempts using credentials leaked from unrelated breaches, tried at volume against every service. Unique passwords make that attack fail entirely, and two factor authentication makes it fail even when a password is known.

The second thing to secure is your domain, for a similar reason. It controls where your email is delivered and where your website resolves, which means somebody with access to the registrar can intercept both. Register it in your own name, separate from your hosting, enable whatever transfer lock the registrar offers, and make sure the account is not attached to an email address at the same domain, which is a circular dependency that fails exactly when you need it.

Then the password manager, which is the tool that makes everything else sustainable. The reason unique passwords are rare is that remembering them is impossible, and a manager removes the requirement. It also solves the sharing problem, gives you an inventory of what accounts exist, and supports emergency access so a business does not stop when one person is unreachable.

Backups come next and they are only real once tested. A backup that exists and has never been restored is an assumption rather than a protection, and the failure is discovered at the worst possible moment. Restore one file, confirm it opens, and repeat that annually.

Be realistic about what a first year business actually faces. The threats are opportunistic and automated: credential stuffing, phishing messages that impersonate a supplier or a payment request, and ransomware delivered through an attachment. Those are addressed by unique passwords, two factor authentication, scepticism about unexpected payment instructions, and working backups. Sophisticated attacks are not your problem yet.

Then write down what protects each critical account and check it annually, because security decays quietly. A two factor method tied to a phone you replaced, a backup that stopped running, or access still held by somebody who left are all invisible until they matter, and a short annual review is what turns one time actions into something that remains true.

Be particularly careful with payment instructions arriving by email, because that is the attack most likely to cost a small business real money. A message appearing to come from a supplier with updated bank details is the standard version, and it succeeds because it arrives during a busy period and looks routine. Verify any change to payment details by phone using a number you already had.

Train whoever else works with you on the same few things, since security at this scale is mostly behaviour rather than configuration. Unique passwords, two factor authentication, and scepticism about unexpected requests cover most of what actually happens, and one conversation is sufficient to establish them.