Enforcing two-factor authentication
The single highest-value security change you can make, and it takes ten minutes.
Why it matters more here than elsewhere
A compromised staff account does not just expose one mailbox — it exposes every customer you have ever served, with their contact details, complaints and attachments in one searchable place.
Rolling it out
1. Admin → Security: require two-factor for the administrator role first.
2. Enrol yourself and confirm recovery works before touching anyone else.
3. Give staff a week’s notice, then require it for the staff role.
4. Keep one break-glass administrator account with recovery codes stored offline.
What to expect
Two or three people will lose their authenticator in the first month. Have a documented reset procedure that verifies identity by a channel other than email.