Technical expertise and custom eCommerce systems designed to scale and integrate with third-party software for client growth and innovation.
Technical expertise and custom eCommerce systems designed to scale and integrate with third-party software for client growth and innovation.
04/09/26: Integration / Systems

“Boring” Account Security Emails ARE Important

Every so often, a client sends their customers a short, plain email: use a strong password, don’t share your login, don’t reset your password unexpectedly, turn on two-factor authentication if you can. Nothing flashy. No urgency, no scare tactics — just a reminder that account security is something worth a few minutes of attention.

It’s a small piece of communication, but it works. Account security notices tend to get written off as compliance box-ticking, but the good ones do real work. They tell a customer, clearly, what your business will and won’t ask them to do — which is often the best defence against phishing you can offer, because a customer who knows “we never ask you to reset your password out of the blue” is a customer who’ll pause before clicking a link that claims otherwise.

They also signal something less obvious: that you’re thinking about your customers’ accounts as something worth protecting, not just a login field between them and checkout. For B2B accounts especially — where a login might expose negotiated pricing, order history and account-specific catalogues — that reassurance matters more than it looks like it should.

A few habits cover most of the ground:

Strong, unique passwords. Reused passwords are the single biggest reason one breached account turns into ten. A password manager solves this for customers who’ll never memorise a dozen unique passwords, and it’s worth saying so plainly.

Credentials that don’t get shared. For B2B accounts with multiple staff logging in under one account, this is where things get messy — access should be tied to the person, and revoked the moment someone leaves the organisation, not left live indefinitely.

A clear policy on password resets. If customers know your business doesn’t send unprompted reset requests, an email that claims otherwise stops being convincing.

Two-factor authentication, offered rather than assumed. 2FA is still the single biggest lift in account security for the effort it takes to turn on — but only if the platform actually supports it and makes enabling it simple.

No stored card data. Whether or not a business processes cards directly, being able to tell customers plainly that payment details aren’t stored on-site is one less thing for them to worry about.

The email is the easy part. The harder part — and the part that actually determines whether any of it is true — is what the platform underneath it supports: does it offer 2FA at all, can access be managed and revoked per user on a shared B2B account, is card data actually kept off your servers and handled through a compliant gateway rather than stored locally?

That’s the layer we work on. Building account security into a platform — not just writing about it after the fact — is part of what goes into every B2B and retail site we deliver, from login and access controls through to payment handling. If a customer-facing security email like this one would currently be more aspiration than fact for your platform, that’s usually a sign it’s worth a proper look at what’s underneath your login page.

At dbg we build B2B and retail eCommerce platforms with account security handled at the platform level — access controls, two-factor authentication and compliant payment handling included.