basicsec.org · Guides

Accounts and backups for a small volunteer group

Published October 5, 2026 · Independent editorial guide

Small groups often begin with one laptop, one shared folder and a password everyone knows. That may feel convenient until a volunteer leaves, the laptop fails or a suspicious message arrives. A manageable security plan starts by identifying the accounts, devices and files the group actually relies on. It should make everyday work clearer as well as reduce avoidable risk.

The BasicSec introduction supplies the site's historical home-and-small-office context. This is a new editorial checklist, not an update written by the original book's author.

Give people their own access

Use individual accounts where the service supports them. Assign only the access each role needs and choose an owner who can remove it when responsibilities change. Keep recovery arrangements with authorized people rather than in a public document. The FTC's small-business cybersecurity guidance recommends software updates, backups and multi-factor authentication as part of protecting information.

For a volunteer project, define the role first. The volunteer-project brief helps separate the work to be done from the personal information an organizer might otherwise collect unnecessarily. A public event notice and a private participant list should not automatically have the same audience.

Keep shared equipment within its limits

Record who maintains each device and whether its operating system and important software are supported. Apply appropriate updates through the vendor's normal process. Do not assume an old workstation is suitable for sensitive online work because it still starts successfully. The used-workstation reuse checklist considers support, compatibility and data handling before a machine is reassigned.

Test a backup by restoring a sample

Choose an ordinary project file and restore a copy to a separate location. Confirm that an authorized person can open it and that the version is the expected one. A completed backup job does not by itself prove a usable recovery. Document the steps, protect the backup's access and consider how the group would work if its main device were unavailable.

Prepare for changes and suspicious messages

Keep a short handover checklist for departing volunteers: review permissions, transfer relevant work to the authorized owner and update recovery contacts as necessary. If a message asks for a password or urgent payment, verify it through an independently known channel. Do not use contact details supplied only by the questionable message.

Record what happened and follow the service provider's account-recovery instructions if access is compromised. For incidents involving personal information, seek qualified advice about the relevant response obligations. The useful goal is a group that knows who owns its work and how to recover it, rather than a checklist nobody has tried.