Skip to content
grewray
Going digital5 min read

Data security for small businesses: the checklist that actually matters

Small businesses are not too small to be a target; they are often easier ones. The good news is that a short list of habits blocks most of what actually happens.

By Ayush Jain, Founder, grewray

Security advice for businesses is usually written for companies with an IT department. A small service business has customer addresses, phone numbers, payment records and staff details to protect, and nobody whose job is to protect them. The result is often either worry without action, or nothing at all.

You do not need to do everything. You need to do the few things that block most real incidents, and do them consistently. Here they are, roughly in order of how much each one protects.

1. Lock down sign-in

Most break-ins start with a stolen or guessed password, not a clever hack.

  • Turn on two-factor sign-in everywhere it is offered, starting with email, banking and any system with customer data. A code from an app on your phone stops most stolen passwords from working.
  • Use a password manager so every account has its own long password, and nobody reuses one.
  • Never share logins. Each person gets their own account. Shared logins make it impossible to know who did what, or to remove one person's access.

2. Give people only the access they need

The crew needs to see tomorrow's jobs. They do not need to see margins, pay or every customer's payment history. Set roles so each person sees what their work needs, and nothing more. It limits the damage from any single compromised account, and it avoids awkward conversations too.

3. Remove access the day someone leaves

The most common gap in small businesses is the former employee who can still sign in. When someone leaves, remove their accounts the same day, change any shared passwords they knew, and make sure every session they had is ended, on every device.

4. Keep devices up to date and locked

Phones and laptops carry your business around. Turn on automatic updates, require a screen lock, and make sure a lost phone can be located and wiped. Keep business data in your systems, not in camera rolls and downloads folders, so a lost device loses a device, not your records.

5. Know where your data lives, and that it is backed up

Could you carry on tomorrow if your laptop died tonight? Make sure the systems that hold your business data are backed up by someone, and that you know how much could be lost and how long a restore would take. A backup nobody has ever restored is a hope, not a backup.

6. Check your software suppliers

Most of your customer data lives with the companies whose software you use. Before you choose one, ask:

Questions to ask any software supplier
QuestionWhy it matters
How is my data kept separate from other customers'?Most software is shared by many businesses
Is two-factor sign-in available, and required for admins?It blocks most account takeovers
How often is data backed up, and are restores tested?Backups only count if they restore
Can I export all my data, free?You can leave, and keep your own copy
How and how fast will you tell me about a breach?Your own customers may need to know

A quick test for any supplier

Ask a supplier to describe what would happen, step by step, if another customer of theirs was breached. A vendor that has thought about isolation, logging and notification will answer in specifics. A vague answer is itself an answer.

7. Watch for the scams that target small businesses

Two deserve a rule of their own, because they rely on nothing more than a convincing message.

  • Fake invoices and changed bank details. An email, apparently from a supplier, saying their bank details have changed. Always confirm a change of bank details by phone, on a number you already had.
  • Urgent requests from "the boss". A message asking someone to pay or buy something quickly and quietly. Agree a rule that no payment is made on the strength of a message alone.

8. Have a plan for when something goes wrong

Decide now who to call and what to do: change passwords, end sessions, contact your software suppliers, and work out whose data might be affected. In many countries, data protection law sets rules about telling affected people and authorities about a breach, often within tight deadlines, so know what applies to you before you need it.

9. Collect less, keep less

The customer data you never collected cannot leak. Ask for what the job needs and no more, and do not keep copies of identity documents, card numbers or passwords anywhere. Delete old records you no longer need, following the retention rules that apply to you, and keep what remains in one proper system rather than scattered across inboxes, spreadsheets and phones.

10. Train the team in ten minutes

Most incidents start with a person, not a machine, so a short conversation protects more than an expensive tool. Once a year, and whenever someone joins, cover four points:

  1. Use two-factor sign-in and a password manager, and never share a login.
  2. Confirm any change of bank details, or any urgent payment request, by phone.
  3. Lock your phone and laptop, and report a lost device the same day.
  4. If something looks wrong, say so straight away. Nobody gets in trouble for reporting.

Write it on one page

Put all of the above on a single page: who has access to what, how you sign in, where data lives, who to call when something goes wrong. It becomes your security policy, and it is the page a larger client will ask to see before they trust you with their data.

How grewray handles its part

When your business runs on grewray, much of this list is handled for you. Every business's data is kept separate by four independent layers, from the application down to the database itself. Owners and admins must use two-factor sign-in, every person has their own login and role, and removing someone ends their sessions on every device at once. Backups allow a restore to within five minutes and are restore-tested every quarter. You can export all your data, free, at any time. And any suspected exposure of one business's data to another is treated as our most serious incident, acknowledged within fifteen minutes.

Read the details on our security page, and see how team access and roles work.

Put it into practice on grewray.

Start a free trial, or try the interactive demo first. If you have data to bring, we move it in for you.