iCoreHosting Service Access & IT Governance Guide (SME Edition)

iCoreHosting Service Access & IT Governance Guide (SME Edition)

Practical hosting, access, and IT security guidelines for small and medium businesses.

This guide is written specifically for SME companies using iCoreHosting services. Most SMEs do not have a full IT department, and many rely on 1–3 IT staff, outsourced vendors, or developers. Because of this, SMEs face higher risks of losing access, data leaks, or operational breakdown when staff resign or vendors disappear.

This document helps SME owners and IT managers properly manage hosting, domains, DNS, email systems, backups, and access control.


Table of Contents

  1. Introduction & Direction
  2. Why SMEs Need Proper IT Governance
  3. Ownership of Hosting & Domain Accounts
  4. Typical SME IT Structure & Risks
  5. Security Fundamentals for SMEs
  6. Access Control for iCoreHosting Services
  7. Common SME Mistakes
  8. Documentation & Password Management
  9. Malaysia Acts (PDPA, CMA, Computer Crimes Act)
  10. iCoreHosting Responsibilities
  11. Best Practices for SME Owners & IT Staff
  12. Golden Rules for SMEs
  13. IT Resignation & Handover SOP (SME Version)
  14. Conclusion

1. Introduction & Direction

SMEs normally depend on a small IT team or outsourced developers. To avoid losing access to hosting, domains, emails, or servers, SMEs must implement simple but effective governance practices.

This guide ensures that your business:

  • Always owns all hosting and domain assets
  • Prevents access problems during staff resignation
  • Complies with Malaysia’s legal requirements
  • Maintains secure and stable website and email operations

2. Why SMEs Need Proper IT Governance

Unlike large companies, SMEs face unique risks such as:

  • One IT person controlling everything
  • Developers buying domains under personal accounts
  • Passwords stored on WhatsApp
  • No documentation, no backup testing
  • Boss unaware of where things are hosted

Once that person resigns, disappears, or becomes uncooperative — the company can lose everything.


3. Who Should Own iCoreHosting & Domain Accounts

The following MUST always belong to the company:

  • iCoreHosting main account
  • Domain registrar account
  • DNS panel login
  • Server login / root access

Use a company-controlled email, such as:

Never use a staff’s personal Gmail.


4. Typical SME IT Structure & Risks

SME IT Characteristics

  • Small IT team (sometimes only 1 person)
  • Heavy dependence on outsourced developers
  • No security officer or compliance officer
  • Boss may not understand IT systems

Main SME Risks

  • IT person holds all passwords
  • Domain registered under developer’s personal account
  • Hosting paid under staff name
  • Vendor leaves and the company loses access
  • No backup or backup stored incorrectly

5. Security Fundamentals for SMEs

These simple steps dramatically increase SME security:

  • Enable MFA for iCoreHosting, DNS, email admin, cPanel/DirectAdmin.
  • Use password vaults (Bitwarden, KeePass, 1Password).
  • Rotate passwords every 6 months.
  • Whitelist IP where applicable.
  • Limit developer access using sub-accounts.

6. Access Control for iCoreHosting Services

Main Account (Ownership)

  • Company owner or director must have full access.
  • Recovery email must be controlled by the company.

Sub-Accounts

  • IT staff (admin)
  • Assistant IT
  • Developer access (limited)
  • Temporary access for vendors

When IT Staff Resign

  • Reset password immediately
  • Remove sub-logins
  • Check DNS & Email forwarding rules
  • Rotate server/SSH passwords

7. Common SME Mistakes

  • Domains purchased under freelancer’s name
  • Hosting purchased with personal emails
  • Everyone using the same password
  • No backup, or backup stored in same server
  • Not removing access when staff leave
  • Developer keeps control of hosting permanently

8. Documentation & Password Management

Every SME should maintain at least a simple documentation file:

  • Main iCoreHosting login
  • Domain registrar login
  • DNS platform login
  • Server IP + root credentials
  • Email admin login
  • Password vault master key

Boss and IT must both hold a copy.


9. Malaysia Acts (PDPA, CMA, Computer Crimes Act)

PDPA 2010

  • Protect personal data stored on hosting systems.
  • Remove access from ex-staff immediately.
  • Secure customer data and backups.

CMA 1998

  • Company is responsible for content hosted.
  • Illegal or harmful usage is prohibited.

Computer Crimes Act 1997

  • Ex-staff accessing systems after resignation is a crime.

10. iCoreHosting Responsibilities

Infrastructure

  • Reliable datacenter-grade hardware and networking
  • 24/7 server monitoring
  • System-level security maintenance

Security

  • DDoS protection
  • Firewall & malware scanning where applicable

Backups

  • 14-day backup retention for shared hosting

Support

  • Technical support via iCoreHosting Portal

Note: SMEs remain responsible for internal access management, vendor control, and password security.


11. Best Practices for SME Owners & IT Staff

  • Use a company email to register all hosting/domain accounts.
  • Enable MFA everywhere.
  • Use a password vault (free or paid).
  • Boss + IT share master vault key.
  • Never give main login to developers.
  • Regularly check who has access.
  • Backups stored outside the server.
  • Test backup restore at least once a year.

12. Quick Golden Rules for SMEs

Rule SME Requirement
Main account ownership ✔ Must be company-owned
MFA ✔ Strongly recommended
Password vault ✔ Use Bitwarden/KeePass
Developer access ✔ Sub-account only
Backup & restore testing ✔ Once a year
Remove ex-staff access ✔ Immediately

13. IT Resignation & Handover SOP (SME Version)

A. Before Last Day

  • Prepare access list
  • Export passwords from vault
  • Collect hosting, domain, DNS, server credentials

B. Handover Items

  • iCoreHosting login
  • DNS login
  • Domain registrar login
  • Server root access
  • Backup locations
  • System notes

C. After the IT staff leaves

  • Reset all passwords
  • Remove all sub-logins
  • Rotate SSH keys
  • Disable email access

14. Conclusion

SMEs have limited IT resources, but with proper governance, documentation, and access control, they can operate with stability and security similar to large companies. This guide provides simple, practical policies that protect your hosting, domain, emails, and business continuity.

Good IT governance is affordable, practical, and essential for every SME using iCoreHosting.

  • 0 Usuários acharam útil
Esta resposta lhe foi útil?

Artigos Relacionados

How to Provide Your Support PIN for Verification

How to Provide Your Support PIN for Verification Table of Contents Service Direction /...

What is TeamViewer and Why Do We Use It?

Table of Contents Service Direction / Introduction / Scope Service Transparency...

How to Send Support Requests via Email or WhatsApp for Effective Assistance

How to Send Support Requests via Email or WhatsApp for Effective Assistance Table of...

Emergency Server Support After Office Hours

Emergency Server Support After Office Hours Table of Contents Service Direction / Scope...

Maintenance Types at iCoreHosting

Table of Contents Service Direction / Introduction / Scope Service Transparency...