Five plain-language questions that reveal whether your business is an easy target — no technical knowledge required, and nothing here costs money to fix.
Most businesses that get hit were not chosen. They were found — by software scanning thousands of organisations at once, looking for the easiest way in.
The doors attackers use most are the same five every time, and you can check all of them yourself. This checklist is written for business owners, managers and finance teams — not for IT specialists. Each point tells you what is at stake in plain terms, and gives you the exact question to put to whoever handles your technology.
Go through each point and answer honestly. An “I don’t know” is the most valuable answer on the page — it is exactly where your risk is hiding.
Each point below reflects an exposure we see repeatedly across Ghanaian businesses — and each one can be closed without a security budget.
If your domain is not locked down, anyone on the internet can send an email that looks like it came from your company — to your clients, your bank, or your own staff. No hacking required. This is the single most common route to fraudulent invoices and lost payments, and it costs nothing to fix.
“Do we have SPF, DKIM and DMARC set up on our domain — and is DMARC set to reject, not just monitor?”
Passwords leak constantly — usually from somewhere else entirely, then reused on your systems. Two-step verification stops the overwhelming majority of account takeovers. Email is the priority: whoever controls your email can reset everything else.
Is two-step verification switched on for every company email account — especially finance, management, and anyone who can move money?
When an employee’s password is stolen — often from a personal device infected with malware — it ends up bundled and sold in criminal markets. Your business can be fully exposed without a single system of yours being touched. Most companies only find out after the money is gone.
Has anyone ever checked whether your company’s email addresses appear in known data leaks? If nobody has looked, the answer is unknown — not “no”.
Attackers rarely announce themselves. They sit quietly in an email account for weeks, learning how you write and who pays you — then send one convincing message at the right moment. Antivirus does not catch this. Someone has to be watching for the signs.
“If someone logged into our email from another country tonight, what would tell us — and who would see it?”
The most expensive attacks in West Africa right now are not clever code — they are a believable email asking finance to update bank details. If your only check is replying to that email, you are asking the attacker for permission. One phone-call rule prevents nearly all of it, and costs nothing.
Any change to bank or payment details must be confirmed by phone call to a known number — never a number supplied in the email itself.
Count how many points you could answer with a confident “yes”.
This checklist is general guidance for business owners and managers. It is not a substitute for a full security assessment, nor for legal or regulatory advice. Every organisation’s risk is different — if any point above concerns you, speak to a qualified professional about your specific situation.
We run a free Exposure Snapshot — a passive check of what is publicly exposed about your organisation: leaked credentials, email security gaps, and weaknesses visible from the outside. No systems are touched and nothing is attacked. You receive a plain-language summary of what we find and what to do about it.