Philippines-only hiring guide

Virtual assistant security checklist for a safe first month

Use this virtual assistant security checklist to set up a Filipino remote assistant with limited access, named accounts, clear approval rules, and a clean exit plan. The owner keeps final control while the assistant works inside a clear task lane.

Reviewed against primary sources on July 25, 2026.

Direct answer

A virtual assistant security checklist should cover the account, device, data, task, approval, review, and exit rules for the role. For a Filipino remote assistant, set these rules before the first live login and test them with masked sample work.

Start with a named account, the smallest useful set of permissions, and a second sign-in check. Keep account recovery, payments, contracts, private staff matters, and final customer promises with the owner or another named manager.

First rules to write down

  • Use a named account, not the owner login.
  • Open only what the first task needs.
  • Use a second sign-in check.
  • Write stop rules for sensitive work.

Why a small business needs a written security plan

A remote assistant may touch the inbox, calendar, cloud files, CRM, or customer notes. One loose login can expose more of the business than the task needs, so access must follow the job instead of the person asking for it.

The 2024 FBI Internet Crime Complaint Center report logged 859,532 complaints and reported a 33 percent rise in losses from 2023. Those figures cover many kinds of online crime, but they show why a new remote account should never be treated as a casual setup. Read the FBI 2024 IC3 report.

Map the role before you open an account

Write one sentence that says what the assistant does, which tool starts the task, and what finished work looks like. A calendar assistant may prepare meeting options and notes, while the owner keeps private events, deletions, purchases, and final sends.

List the records the role may see and the choices it may not make. This short map becomes the access plan, the training list, and the review sheet for the first week.

Use a named account for each person

Do not send the owner password through chat or email. Create a separate account for the Filipino assistant, use their work name, and record who approved it and which role it supports.

A named account makes actions easier to review and access easier to remove when the role changes. It also keeps the owner account and its recovery methods away from daily task work.

What the 2024 FBI report recorded

The figures below come from reports sent to the FBI Internet Crime Complaint Center. They describe reported events, so they should not be read as a count of every event that happened.

Published online crime complaint figures
MeasurePublished valuePeriodWhat it means
Online crime complaints received859,5322024Reports sent to IC3 that year.
Complaints reporting an actual loss256,2562024Reports that included an actual loss.
Increase in reported losses33%2024 vs. 2023Change from the prior year.
Average complaints per dayMore than 2,0002020-2024Daily average over five years.

Source: FBI 2024 IC3 Annual Report

Complaints that reported an actual loss

FBI IC3 complaints in 2024Horizontal bars compare all 859,532 complaints with 256,256 complaints that reported an actual loss.All complaints859,532Reported a loss256,256
Units are complaints submitted to the FBI Internet Crime Complaint Center in 2024. Bar lengths use the published counts and are rounded to the nearest whole pixel; they do not estimate unreported events. Open the FBI report.

Give only the access the first tasks need

NIST defines least privilege as allowing only the access needed to complete assigned work. In plain terms, an inbox assistant does not need every drive folder, billing control, staff record, or admin setting. See the NIST least-privilege control.

Open one tool at a time and test the account before the first shift. If the assistant cannot finish the approved task, add one permission after the manager checks why it is needed.

Protect every sign-in and recovery path

CISA tells users to make passwords at least 16 characters and to use a different strong password for each account. A password manager can create and store those passwords without asking the assistant to reuse an easy phrase. Use the CISA password guide.

Turn on multi-factor authentication for email, the CRM, cloud storage, and the password manager when each tool supports it. CISA says MFA adds a second check beyond the password, so the password alone is not enough to enter the account. Read the CISA MFA guide.

Train with masked records first

Use old or made-up records for the first practice batch, and remove names, phone numbers, addresses, and account details. Ask the assistant to show the exact steps for sorting, drafting, updating, and handing the work back.

Open live data only after the sample is correct and the stop rules are clear. The Philippine Data Privacy Act of 2012 covers personal information processing and requires reasonable protection against improper access, loss, or disclosure. Read Republic Act 10173.

Report a suspected incident

"We want to be there for you, and what you report will help us help others."

B. Chad Yarbrough, Operations Director for Criminal and Cyber, Federal Bureau of Investigation. 2024 IC3 Annual Report.

A first-access table for common assistant work

Use this table as a starting point, then change it to match the tools and legal duties in your business. A Filipino assistant can prepare and update approved work while the accountable owner keeps sensitive control.

Swipe to compare all columns.

Suggested first-access boundaries
Work areaStart withOwner or manager keeps
Email and calendarAssigned mailbox or limited calendar rightsRecovery, private folders, deletion, and sensitive sends
CRM and customer notesNamed user with needed records onlyExports, mass changes, refunds, contracts, and private notes
Cloud filesOne folder for approved tasksAdmin rights, staff files, legal files, and full-drive sharing
Password managerEntries for approved tools onlyRecovery, owner logins, and unrelated vault items
Money and purchasesView or prepare approved informationTransfers, purchases, refunds, and banking actions

A safe access handoff

Five-step virtual assistant security processMap the task, limit access, test safely, check the work, and close access.MapMap the task
Name the tool, data, output, and owner.
LimitLimit access
Open only what the first task needs.
TestTest safely
Use masked records and small batches.
CheckCheck the work
Review actions, questions, and stop rules.
CloseClose access
Remove accounts when the role or task ends.
This process is a planning aid. The business should adjust it for its systems, contracts, data, and legal duties.

Write simple stop and approval rules

Tell the assistant to stop when a request involves a payment, refund, contract, password reset, private staff issue, angry customer, or unusual file. The assistant should collect the facts, mark the task, and ask the named manager before taking the next step.

Keep the rule short enough to use during a busy shift. A clear rule such as "draft it, flag it, and wait" is easier to follow than a long policy that nobody can recall.

Check links and change requests outside the message

A message can look like it came from the owner even when it did not. If it asks for a new login, a file share, a money action, or a change to recovery details, verify the request in a known channel before doing anything.

Do not rely on the reply address, display name, or urgent tone as proof. Save the suspicious message, tell the manager what happened, and use the company reporting path instead of forwarding it around the team.

Review the first week in small batches

Have the assistant work in small batches that a manager can check on the same day. Review wrong labels, unexpected downloads, skipped approvals, and any question that arrived too late.

Fix the written rule when two careful people read it in different ways. Add wider access only when the current task is steady and the manager can name the reason for the change.

Keep a short account and data list

Record the tool, account owner, permission level, data type, approver, review date, and removal step in one list. The list should be useful during onboarding, a role change, an incident, and the final day.

Check the list after the first week and once each month while the role is active. Remove unused access rather than leaving it open for a task that may return later.

Plan the exit before the role starts

Write who will disable accounts, move unfinished work, change shared secrets, recover company files, and check active sessions. Set the order before a rushed exit makes the team guess.

On the last day, remove access first, then confirm that the company has the needed work and records. Keep a dated note of the accounts closed and the manager who checked each one.

Questions about virtual assistant security

Should a virtual assistant use my main login?

No. Give each assistant a named account with only the access needed for the assigned tasks. Keep the owner login and recovery controls with the owner or a trusted manager.

What should I give a Filipino assistant on day one?

Start with one tool, masked practice records, written stop rules, and a small task batch. Open live records only after the assistant can show the task and handoff correctly.

Does a remote assistant need multi-factor authentication?

Use MFA on every work account that supports it. Keep recovery methods with the company, and write down who can restore access if a device is lost.

Can an assistant handle customer data?

The role may handle approved customer data when the business has a lawful reason and suitable protection. Limit the records, train with masked examples, and keep sensitive decisions with the right manager or qualified person.

What happens when the assistant leaves?

Disable accounts, end active sessions, recover company work, change any shared secrets, and move unfinished tasks to a named owner. Record what was closed and who checked it.

Where are assistants hired through this service?

Every candidate offered through this service is recruited and hired in the Philippines. The work is remote, so local errands, walk-in reception, and physical file duties need a local employee or vendor.

Pick the next page that matches the work you want to hand over. Each link stays inside the Philippines-only hiring path on this site.

Sources

These primary sources support the figures, quote, account guidance, access guidance, and Philippine privacy notes above. We checked each link before publication and kept the source wording separate from our planning advice.

  1. FBI Internet Crime Complaint Center, 2024 IC3 Annual Report: Complaint figures and the exact expert quote.
  2. CISA, Use Strong Passwords: Password and password-manager guidance.
  3. CISA, Turn on Multifactor Authentication: Guidance on a second sign-in check.
  4. NIST SP 800-53 Rev. 5, Security and Privacy Controls: Access controls and least privilege.
  5. Republic Act No. 10173, Data Privacy Act of 2012: Philippine personal-information law.