Name a primary reviewer and a backup. Choose one or two bounded tasks, such as updating a reconciliation from provided statements or preparing an accounts-receivable aging follow-up list. Assemble the current procedure, redacted examples, file locations, deadline, expected output, and escalation contacts.
Create named accounts with least-privilege access; do not send shared passwords through chat or email. Enable multifactor authentication where supported and decide how sensitive records may be downloaded, stored, and deleted. CISA provides general guidance on multifactor authentication. The company should apply its own security and retention requirements.