Philippines-only hiring guide
Virtual assistant security checklist for a safe first month
Use this virtual assistant security checklist to set up a Filipino remote assistant with limited access, named accounts, clear approval rules, and a clean exit plan. The owner keeps final control while the assistant works inside a clear task lane.
Reviewed against primary sources on July 25, 2026.
Direct answer
A virtual assistant security checklist should cover the account, device, data, task, approval, review, and exit rules for the role. For a Filipino remote assistant, set these rules before the first live login and test them with masked sample work.
Start with a named account, the smallest useful set of permissions, and a second sign-in check. Keep account recovery, payments, contracts, private staff matters, and final customer promises with the owner or another named manager.
First rules to write down
- Use a named account, not the owner login.
- Open only what the first task needs.
- Use a second sign-in check.
- Write stop rules for sensitive work.
Why a small business needs a written security plan
A remote assistant may touch the inbox, calendar, cloud files, CRM, or customer notes. One loose login can expose more of the business than the task needs, so access must follow the job instead of the person asking for it.
The 2024 FBI Internet Crime Complaint Center report logged 859,532 complaints and reported a 33 percent rise in losses from 2023. Those figures cover many kinds of online crime, but they show why a new remote account should never be treated as a casual setup. Read the FBI 2024 IC3 report.
Map the role before you open an account
Write one sentence that says what the assistant does, which tool starts the task, and what finished work looks like. A calendar assistant may prepare meeting options and notes, while the owner keeps private events, deletions, purchases, and final sends.
List the records the role may see and the choices it may not make. This short map becomes the access plan, the training list, and the review sheet for the first week.
Use a named account for each person
Do not send the owner password through chat or email. Create a separate account for the Filipino assistant, use their work name, and record who approved it and which role it supports.
A named account makes actions easier to review and access easier to remove when the role changes. It also keeps the owner account and its recovery methods away from daily task work.
What the 2024 FBI report recorded
The figures below come from reports sent to the FBI Internet Crime Complaint Center. They describe reported events, so they should not be read as a count of every event that happened.
| Measure | Published value | Period | What it means |
|---|---|---|---|
| Online crime complaints received | 859,532 | 2024 | Reports sent to IC3 that year. |
| Complaints reporting an actual loss | 256,256 | 2024 | Reports that included an actual loss. |
| Increase in reported losses | 33% | 2024 vs. 2023 | Change from the prior year. |
| Average complaints per day | More than 2,000 | 2020-2024 | Daily average over five years. |
Complaints that reported an actual loss
Give only the access the first tasks need
NIST defines least privilege as allowing only the access needed to complete assigned work. In plain terms, an inbox assistant does not need every drive folder, billing control, staff record, or admin setting. See the NIST least-privilege control.
Open one tool at a time and test the account before the first shift. If the assistant cannot finish the approved task, add one permission after the manager checks why it is needed.
Protect every sign-in and recovery path
CISA tells users to make passwords at least 16 characters and to use a different strong password for each account. A password manager can create and store those passwords without asking the assistant to reuse an easy phrase. Use the CISA password guide.
Turn on multi-factor authentication for email, the CRM, cloud storage, and the password manager when each tool supports it. CISA says MFA adds a second check beyond the password, so the password alone is not enough to enter the account. Read the CISA MFA guide.
Train with masked records first
Use old or made-up records for the first practice batch, and remove names, phone numbers, addresses, and account details. Ask the assistant to show the exact steps for sorting, drafting, updating, and handing the work back.
Open live data only after the sample is correct and the stop rules are clear. The Philippine Data Privacy Act of 2012 covers personal information processing and requires reasonable protection against improper access, loss, or disclosure. Read Republic Act 10173.
Report a suspected incident
"We want to be there for you, and what you report will help us help others."
B. Chad Yarbrough, Operations Director for Criminal and Cyber, Federal Bureau of Investigation. 2024 IC3 Annual Report.
A first-access table for common assistant work
Use this table as a starting point, then change it to match the tools and legal duties in your business. A Filipino assistant can prepare and update approved work while the accountable owner keeps sensitive control.
Swipe to compare all columns.
| Work area | Start with | Owner or manager keeps |
|---|---|---|
| Email and calendar | Assigned mailbox or limited calendar rights | Recovery, private folders, deletion, and sensitive sends |
| CRM and customer notes | Named user with needed records only | Exports, mass changes, refunds, contracts, and private notes |
| Cloud files | One folder for approved tasks | Admin rights, staff files, legal files, and full-drive sharing |
| Password manager | Entries for approved tools only | Recovery, owner logins, and unrelated vault items |
| Money and purchases | View or prepare approved information | Transfers, purchases, refunds, and banking actions |
A safe access handoff
Write simple stop and approval rules
Tell the assistant to stop when a request involves a payment, refund, contract, password reset, private staff issue, angry customer, or unusual file. The assistant should collect the facts, mark the task, and ask the named manager before taking the next step.
Keep the rule short enough to use during a busy shift. A clear rule such as "draft it, flag it, and wait" is easier to follow than a long policy that nobody can recall.
Check links and change requests outside the message
A message can look like it came from the owner even when it did not. If it asks for a new login, a file share, a money action, or a change to recovery details, verify the request in a known channel before doing anything.
Do not rely on the reply address, display name, or urgent tone as proof. Save the suspicious message, tell the manager what happened, and use the company reporting path instead of forwarding it around the team.
Review the first week in small batches
Have the assistant work in small batches that a manager can check on the same day. Review wrong labels, unexpected downloads, skipped approvals, and any question that arrived too late.
Fix the written rule when two careful people read it in different ways. Add wider access only when the current task is steady and the manager can name the reason for the change.
Keep a short account and data list
Record the tool, account owner, permission level, data type, approver, review date, and removal step in one list. The list should be useful during onboarding, a role change, an incident, and the final day.
Check the list after the first week and once each month while the role is active. Remove unused access rather than leaving it open for a task that may return later.
Plan the exit before the role starts
Write who will disable accounts, move unfinished work, change shared secrets, recover company files, and check active sessions. Set the order before a rushed exit makes the team guess.
On the last day, remove access first, then confirm that the company has the needed work and records. Keep a dated note of the accounts closed and the manager who checked each one.
Questions about virtual assistant security
Should a virtual assistant use my main login?
No. Give each assistant a named account with only the access needed for the assigned tasks. Keep the owner login and recovery controls with the owner or a trusted manager.
What should I give a Filipino assistant on day one?
Start with one tool, masked practice records, written stop rules, and a small task batch. Open live records only after the assistant can show the task and handoff correctly.
Does a remote assistant need multi-factor authentication?
Use MFA on every work account that supports it. Keep recovery methods with the company, and write down who can restore access if a device is lost.
Can an assistant handle customer data?
The role may handle approved customer data when the business has a lawful reason and suitable protection. Limit the records, train with masked examples, and keep sensitive decisions with the right manager or qualified person.
What happens when the assistant leaves?
Disable accounts, end active sessions, recover company work, change any shared secrets, and move unfinished tasks to a named owner. Record what was closed and who checked it.
Where are assistants hired through this service?
Every candidate offered through this service is recruited and hired in the Philippines. The work is remote, so local errands, walk-in reception, and physical file duties need a local employee or vendor.
Keep planning the role
Pick the next page that matches the work you want to hand over. Each link stays inside the Philippines-only hiring path on this site.
Sources
These primary sources support the figures, quote, account guidance, access guidance, and Philippine privacy notes above. We checked each link before publication and kept the source wording separate from our planning advice.
- FBI Internet Crime Complaint Center, 2024 IC3 Annual Report: Complaint figures and the exact expert quote.
- CISA, Use Strong Passwords: Password and password-manager guidance.
- CISA, Turn on Multifactor Authentication: Guidance on a second sign-in check.
- NIST SP 800-53 Rev. 5, Security and Privacy Controls: Access controls and least privilege.
- Republic Act No. 10173, Data Privacy Act of 2012: Philippine personal-information law.