Treat email as part of your financial controls
A municipal inbox is a working queue: contractor questions, invoices, resident concerns, meeting material, and requests from other departments. A convincing message can slip into that queue without looking unusual. Protecting the inbox matters, but so does the procedure staff follow when a message asks them to change something important.
Consider an email that appears to come from a familiar contractor and requests a new bank account for the next payment. The immediate question should be how to verify that instruction independently. A quick reply to the same email thread does not provide independent confirmation. Build a process in which staff know when to pause, who can approve a change, and how that approval is recorded.
Plan stronger sign-ins with staff in mind
Multifactor authentication adds a separate check to a sign-in. Some methods resist phishing more effectively than others. Microsoft recommends phishing-resistant authentication for privileged administrator accounts and describes methods such as passkeys and security keys. Ask your IT team which options fit your environment and which systems still depend on older sign-in methods.
Rollout needs preparation. Microsoft advises registering appropriate methods before enforcement and testing Conditional Access policies in report-only mode. For your township, that means scheduling enrollment, helping part-time employees, and making sure emergency access is accounted for. A policy should not first reveal its problems when the treasurer is trying to complete an important transaction.
Make payment changes a separate conversation
Write down which requests require verification: new banking details, unexpected wire instructions, unusual urgency, or changes to established payment contacts. Use contact information already held in your vendor records, rather than a phone number supplied in the message being checked. Decide which staff member performs verification and which person approves the change. Keep the result with the transaction record.
Apply the same principle to requests that appear to come from elected officials or managers. A name in an email signature does not authorize a new payment procedure. Staff should have a straightforward way to check an instruction without feeling that they are obstructing work. A consistent rule protects relationships because the verification is routine rather than a personal judgment about the sender.
Give staff one easy reporting route
Training should answer a practical question: what should I do with this message right now? Show staff the approved reporting button or support contact, and explain what details help investigation. Avoid a process that requires several forwards or screenshots before anyone can help. A staff member who clicked a link should be able to report that promptly and clearly.
Use short examples from municipal work: a document-sharing invitation for a board packet, an invoice with changed payment instructions, or a sign-in prompt after following a link. Discuss what made the message believable and how to check it. The purpose is to create a useful pause before action and a fast path to help when something feels wrong.
- Verify financial changes using a previously known contact.
- Report unexpected sign-in prompts and suspicious messages.
- Keep administrator access separate from everyday email use.
- Tell IT promptly if a password or verification code was entered.
Review the process, not just the settings
Ask your IT support team to confirm which accounts have stronger authentication, who holds administrator access, and how unusual sign-ins are investigated. Ask finance staff to walk through a payment-change example from start to finish. Technical settings and office procedures need to meet in the middle; neither is a substitute for the other.
IT support for municipalities should make these protections usable for the people answering residents and processing the day’s work. Start with one high-impact workflow and one well-planned authentication improvement. After rollout, check whether staff understand the reporting process and whether exceptions are still necessary. A manageable process that people follow is more useful than an ambitious plan nobody can explain.
YOUR NEXT STEP
Pair stronger sign-ins with an independent verification rule for financial changes and a reporting route every employee can use.
Need a hand putting a plan in place? Explore our Managed IT services for Michigan municipalities or talk with our team.
