Most business email security advice reads like it was written for a large enterprise security team, but the practices that actually reduce breach risk for a small or mid-size Nepali business are simpler, cheaper, and mostly a matter of consistently applying a short list rather than buying expensive tools.

Two-Factor Authentication, Enforced, Not Optional

A password alone, no matter how strong, is defeated by a single successful phishing attempt or a reused password leaked from an unrelated breach elsewhere. Two-factor authentication (a code from an app, not SMS where avoidable, since SMS can be intercepted) stops the overwhelming majority of account-takeover attempts even after a password is compromised. Every major platform — Google Workspace, Zoho, Microsoft 365, and even cPanel webmail via app-level 2FA where supported — offers this; the practical failure point is making it mandatory for every account rather than optional and quietly skipped.

Phishing Awareness, Repeated Not One-Time

A single onboarding mention of "watch out for phishing" doesn't stick. A short, periodic reminder (quarterly, not annually) covering current tactics — fake invoice attachments, urgent-sounding requests to change bank details, links that look like your own login page but aren't — keeps the awareness fresh enough to actually catch the next attempt, since phishing tactics evolve and a one-time training goes stale.

Least-Privilege Admin Access

Not every staff member who uses email needs admin console access to the whole domain. Limiting who can reset other users' passwords, add new mailboxes, or change domain-wide settings to the smallest necessary group reduces how much damage a single compromised account can do — a compromised regular mailbox is contained; a compromised admin account is a domain-wide incident.

Monitoring Login Alerts

Most platforms offer login alerts for unfamiliar locations or devices, and enabling them (rather than leaving the default settings unreviewed) turns a silent compromise into an immediately visible one. A login alert from an unfamiliar country at 3am is a five-second decision to investigate; without the alert, that same login goes unnoticed for weeks.

Regular Access Review

Former employees' accounts that stay active after they leave are a routinely overlooked risk — a quarterly review of active accounts against current staff, disabling or removing anything that shouldn't still exist, closes a gap that's easy to forget in the day-to-day.

Why Prevention Beats Response Every Time

A prevented compromise costs nothing beyond the modest ongoing discipline above. A successful compromise costs incident response time, potential data exposure, damaged client trust if the attacker used your domain to target your contacts, and the same remediation steps you'd have avoided entirely with 2FA turned on from the start. The math heavily favors prevention.

A Simple Quarterly Security Checklist

  1. Confirm 2FA is enabled on every active account, no exceptions.
  2. Review the active user list against current staff and disable anything unnecessary.
  3. Send a brief phishing-awareness reminder covering any new tactics seen recently.
  4. Check login alert settings are still enabled and going to someone who actually reviews them.

Fifteen minutes a quarter, consistently done, prevents far more than an expensive one-time security audit that then gets forgotten.