Data security for small businesses: the checklist that actually matters
Small businesses are not too small to be a target; they are often easier ones. The good news is that a short list of habits blocks most of what actually happens.
By Ayush Jain, Founder, grewray
Security advice for businesses is usually written for companies with an IT department. A small service business has customer addresses, phone numbers, payment records and staff details to protect, and nobody whose job is to protect them. The result is often either worry without action, or nothing at all.
You do not need to do everything. You need to do the few things that block most real incidents, and do them consistently. Here they are, roughly in order of how much each one protects.
1. Lock down sign-in
Most break-ins start with a stolen or guessed password, not a clever hack.
- Turn on two-factor sign-in everywhere it is offered, starting with email, banking and any system with customer data. A code from an app on your phone stops most stolen passwords from working.
- Use a password manager so every account has its own long password, and nobody reuses one.
- Never share logins. Each person gets their own account. Shared logins make it impossible to know who did what, or to remove one person's access.
2. Give people only the access they need
The crew needs to see tomorrow's jobs. They do not need to see margins, pay or every customer's payment history. Set roles so each person sees what their work needs, and nothing more. It limits the damage from any single compromised account, and it avoids awkward conversations too.
3. Remove access the day someone leaves
The most common gap in small businesses is the former employee who can still sign in. When someone leaves, remove their accounts the same day, change any shared passwords they knew, and make sure every session they had is ended, on every device.
4. Keep devices up to date and locked
Phones and laptops carry your business around. Turn on automatic updates, require a screen lock, and make sure a lost phone can be located and wiped. Keep business data in your systems, not in camera rolls and downloads folders, so a lost device loses a device, not your records.
5. Know where your data lives, and that it is backed up
Could you carry on tomorrow if your laptop died tonight? Make sure the systems that hold your business data are backed up by someone, and that you know how much could be lost and how long a restore would take. A backup nobody has ever restored is a hope, not a backup.
6. Check your software suppliers
Most of your customer data lives with the companies whose software you use. Before you choose one, ask:
| Question | Why it matters |
|---|---|
| How is my data kept separate from other customers'? | Most software is shared by many businesses |
| Is two-factor sign-in available, and required for admins? | It blocks most account takeovers |
| How often is data backed up, and are restores tested? | Backups only count if they restore |
| Can I export all my data, free? | You can leave, and keep your own copy |
| How and how fast will you tell me about a breach? | Your own customers may need to know |
A quick test for any supplier
Ask a supplier to describe what would happen, step by step, if another customer of theirs was breached. A vendor that has thought about isolation, logging and notification will answer in specifics. A vague answer is itself an answer.
7. Watch for the scams that target small businesses
Two deserve a rule of their own, because they rely on nothing more than a convincing message.
- Fake invoices and changed bank details. An email, apparently from a supplier, saying their bank details have changed. Always confirm a change of bank details by phone, on a number you already had.
- Urgent requests from "the boss". A message asking someone to pay or buy something quickly and quietly. Agree a rule that no payment is made on the strength of a message alone.
8. Have a plan for when something goes wrong
Decide now who to call and what to do: change passwords, end sessions, contact your software suppliers, and work out whose data might be affected. In many countries, data protection law sets rules about telling affected people and authorities about a breach, often within tight deadlines, so know what applies to you before you need it.
9. Collect less, keep less
The customer data you never collected cannot leak. Ask for what the job needs and no more, and do not keep copies of identity documents, card numbers or passwords anywhere. Delete old records you no longer need, following the retention rules that apply to you, and keep what remains in one proper system rather than scattered across inboxes, spreadsheets and phones.
10. Train the team in ten minutes
Most incidents start with a person, not a machine, so a short conversation protects more than an expensive tool. Once a year, and whenever someone joins, cover four points:
- Use two-factor sign-in and a password manager, and never share a login.
- Confirm any change of bank details, or any urgent payment request, by phone.
- Lock your phone and laptop, and report a lost device the same day.
- If something looks wrong, say so straight away. Nobody gets in trouble for reporting.
Write it on one page
Put all of the above on a single page: who has access to what, how you sign in, where data lives, who to call when something goes wrong. It becomes your security policy, and it is the page a larger client will ask to see before they trust you with their data.
How grewray handles its part
When your business runs on grewray, much of this list is handled for you. Every business's data is kept separate by four independent layers, from the application down to the database itself. Owners and admins must use two-factor sign-in, every person has their own login and role, and removing someone ends their sessions on every device at once. Backups allow a restore to within five minutes and are restore-tested every quarter. You can export all your data, free, at any time. And any suspected exposure of one business's data to another is treated as our most serious incident, acknowledged within fifteen minutes.
Read the details on our security page, and see how team access and roles work.