For small businesses, securing email accounts is crucial for protecting sensitive information and maintaining client trust. Cyber threats are constantly evolving, and a compromised email can lead to data breaches, reputational damage, and financial loss. This guide offers practical tips for enhancing email security, helping small business owners safeguard their communications and maintain a secure digital environment. By taking proactive steps, you can reduce risks, protect your business’s reputation, and keep your email accounts secure and resilient.
Guidance Note: accounts mentioned in this document relate to Gmail, Apple and Outlook, however similar measures will be available for other email accounts you may use.
Some of the main concerns of small businesses who engage IDCARE are business email compromise and false invoicing fraud.
Business Email Compromise is a targeted cyberattack where a threat actor gains access to a company’s email account to impersonate employees, executives,or vendors. Threat actors often use this access to manipulate financial transactions, redirect payments, or steal sensitive information. Small businesses can be particularly vulnerable to BEC due to potentially less robust security measures.
False invoicing fraud occurs when a threat actor sends fake invoices that appear legitimate, tricking businesses or customers into making payments to fraudulent accounts. Cybercriminals may compromise vendor accounts or spoof their email addresses to closely resemble trusted suppliers.
Additionally, we see that a compromised email account carries many other risks which may allow an attacker the ability to:
Spread scam messaging or malware to your contacts;
Obtain password reset codes to other online accounts, such as social media, allowing for account takeover events;
Create fraudulent online accounts;
Aid in social engineering of call centre employees when seeking information from your financial services provider or other organisations (such as superannuation or telecommunications providers);
Automatically forward any received email to a different address.
The steps outlined in this document will help your business to mitigate these risks in relation to email account security.
IDCARE highly recommends you also understand any exposures your business email address may have had by visiting haveibeenpwned.com and changing any associated passwords that appear to be breached.
Forwarding Rules
Check your email forwarding settings regularly. Unauthorised changes could indicate a breach.
Gmail:
Please see Google’s guidance regarding email forwarding rules. Note that you will likely need to login via a web-browser, as forwarding rules do not seem to be available directly via the mobile app.
Outlook (incl @hotmail.com @live.com @outlook.com):
Please see Microsoft’s guidance regarding email forwarding rules. Note that you will likely need to login via a web-browser, as forwarding rules donot seem to be available directly via the settings page of the mobile app.
iCloud (Apple Mail):
Please see Apple’s guidance regarding email forwarding rules.
Multi-Factor Authentication (MFA)
MFA adds an extra layer of security, requiring a second factor beyond your password. Set this up to reduce unauthorised access risks.
Gmail: Go to Security > 2-Step Verification and follow the setup steps to use SMS, an authenticator app, or a security key. Please also see Google’s guidance online.
Outlook: Visit Security > Additional Security Options > Set Up MFA. Please also see Microsoft’s guidance online.
Apple Mail: Enable two-factor authentication through your Apple ID at appleid.apple.com under Security. Please also see Apple’s guidance online.
Password Resets
Ensure that your password is strong and unique, and update it regularly, especially if you suspect your account has been compromised.
Again, we recommend you visit haveibeenpwned.com to understand if your email address has been involved in any known online data breaches.
Gmail: Access Security > Password to change your password. Please also see Google’s guidance online.
Outlook: Go to Security > Password Security to update. Please also see Microsoft’s guidance online.
Apple Mail: Update your Apple ID password at appleid.apple.com under Sign-In & Security. Please also see Apple’s guidance online.
Backup Emails
Keep your recovery email updated to help recover access to your account if you get locked out.
If you lose access to your password, or find yourself unable to login, a recovery email allows you to receive a one-time-password (OTP) which will aid in regaining access to your account.
Gmail: Go to Security > Ways we can verify it’s you > Recovery Email. Please also see Google’s guidance online.
Outlook: In Account Settings, set or update your backup email. Additionally, check the ACSC’s reference material for helpful information in relation to any Outlook, M365, Live, Hotmail & MSN security settings.
Apple Mail: Update recovery information through your AppleID settings. Please also see Apple’s guidance online.
Signed-In Devices
Regularly review devices signed into your email to spot suspicious activity.
Gmail: Visit Security > Your Devices to view and remove unfamiliar devices. Please also see Google’s guidance online.
Outlook: Check My Microsoft Account > Devices and remove any that you don’t recognise. Please also see Microsoft’s guidance online.
Apple Mail: On appleid.apple.com, under Devices, review and manage all linked devices. Please also see Apple’s guidance online.
1. Recent Activity:
Gmail: Visit Security > Recent Security Events to identify unusual logins. Please also see Google’s guidance online.
Outlook: Check Security > Recent Activity for unfamiliar access points. Please also see Microsoft’s guidance online.
AppleMail: On appleid.apple.com, review the last login locations and devices.
2. Review Security Settings:
Ensure MFA is enabled, that recovery methods are correct, and there are no unauthorised forwarding rules.
If suspicious activity is detected, reset your password immediately and notify your contacts of the potential breach.
3. Linked online accounts.
If you believe your email has been accessed, you should immediately review the online accounts associated with it. An attacker may have reset one of the passwords to these accounts and deleted any evidence of the password reset email sent to you.
Be vigilant and be sure to check your social media, business website, online banking, government accounts (including ATO and myGov), superannuation, insurance and any other accounts you believe the email is associated with.
Changes made may be subtle (such as a change in contact details associated with your myGov) or overt (such as scam posts made to your social media accounts),or you may be locked out of these accounts altogether.
If you do believe any of the above has occurred, feel free to contact IDCARE for assistance.
Identity Care Australia & New Zealand Ltd (IDCARE) provides identity and cyber security incident response services (the Services) in accordance with the following disclaimer of service:
Mon - Fri: 8am - 5pm AEST
QLD: 07 3555 5900
ACT & NSW: 02 8999 3356
VIC: 03 7018 2366
NT, SA & WA : 08 7078 7741
Mon - Fri: 10am - 7pm NZST
AKL: 09 884 4440
IDCARE as a registered charity does not ask individuals to donate or pay for our front line services. We are not a charity that can receive tax deductible donations.
We rely on organisations that care enough about you to care about us to keep our charitable service going. Proudly these organisations are displayed above and on our Subscriber Organisations page.
If you are asked for payment from someone claiming to be from IDCARE, please report this to us using our Report Phishing email.
IDCARE has access to the Department of Home Affairs Free Interpreting Service, delivered by the Translating and Interpreting Service (TIS National). Access to the Free Interpreting Service is provided to assist you to communicate with non-English speaking people who hold a Medicare card. Please note that the service does not extend to New Zealand citizens or residents who do not hold an Australian Medicare card, or to tourists, overseas students or people on temporary work visas.
New Zealand Relay provides services to help Deaf, hearing impaired, speech impaired, Deafblind and standard phone users communicate with their peers.
A TTY user connects to New Zealand Relay via a toll-free number and types their conversation to a Relay Assistant (RA) who then reads out the typed message to a standard phone user (hearing person).
The RA relays the hearing person's spoken words by typing them back to the Textphone (TTY) User.
The National Relay Service (NRS) is an Australian government initiative that allows people who are deaf, hard of hearing and/or have a speech impairment to make and receive phone calls.
The NRS is available 24 hours a day, every day and relays more than a million calls each year throughout Australia.
ABN 84 164 038 966
IDCARE acknowledges and Respects the traditional custodians of the land on which we operate across Australia and New Zealand.
This website may contain names, images and voices of deceased Aboriginal, Torres Strait Islander and Māori peoples.