Security

Business data security: 10 things to do right now

By The GREEN TECH team08/08/20269 min read
Business data security: 10 things to do right now

One phishing email, one leaked password or one lost laptop is enough to put your customer and financial data in the wrong hands. The good news is that most of these risks can be reduced significantly with basic measures that don't cost much. Here are 10 things small and medium-sized businesses should start doing right away.

Small businesses are targets for cybercriminals too

Many business owners think their company is too small to attract attention. In reality, attackers often use automated tools to scan large numbers of targets at once and go after whoever has the weakest defenses. A lack of security staff, simple passwords and untested backups make small businesses easy prey.

Common attacks include ransomware that encrypts all of your data and then demands a ransom, phishing emails that steal passwords, and spoofed partner emails asking you to transfer money to a different account. Beyond the direct damage, a personal data breach also brings legal liability: Decree 13/2023/ND-CP on Personal Data Protection and, after it, the Law on Personal Data Protection (in effect from January 1, 2026) require organizations that process personal data to apply appropriate safeguards and notify the authorities when a breach occurs.

Steps 1–3: Protect accounts and access

Most incidents begin with a compromised account. That's why locking down the “front door” is the top priority, and it's also the least expensive group of measures.

Also draw up a list of your critical systems and who holds admin rights to each one, so you never end up with nobody knowing who controls the domain, hosting or Facebook Page accounts.

  • 1. Turn on two-factor authentication (2FA) for business email, accounting software, online banking, website admin accounts and social media. Where possible, choose an authenticator app such as Google Authenticator or Microsoft Authenticator, or a physical security key, over SMS codes.
  • 2. Use strong passwords and a password manager. Give every system its own, sufficiently long password, and use a tool like Bitwarden or 1Password to store and share them securely instead of keeping them in an Excel file or a chat group.
  • 3. Apply least-privilege access. Employees should only be able to access the data they need for their work, and admin accounts should be kept separate and never used for everyday tasks. When someone leaves the company, revoke all of their access the same day.

Steps 4–5: Back up regularly and keep software updated

4. Back up regularly and test your restores. Backups are your last line of defense against ransomware or hardware failure. The widely used 3-2-1 rule says to keep at least three copies of your data, on two different types of storage media, with one copy stored somewhere separate such as the cloud. Backups should be isolated from your internal network or protected against modification and deletion so ransomware can't encrypt them. Test restores regularly, because a backup that has never been tested can't be considered safe.

5. Update software and patch vulnerabilities. Operating systems, browsers, website plugins and network devices such as routers and cameras all need regular updates. Many attacks exploit vulnerabilities that were patched long ago but never installed. Turn on automatic updates and replace software and devices that are no longer supported.

Steps 6–7: Train staff and control processes

No matter how good your technology is, a single wrong click can undo it. People are a weak point, but they can also become an effective layer of defense when they're equipped with knowledge and clear processes.

For example, an accountant at an import-export company receives an email “from a partner” announcing a change of bank account, along with an invoice that looks exactly like the real thing. A single verification call to the phone number already on file is enough to expose the fraud. Encourage employees to speak up immediately when they're suspicious or have clicked something by mistake, rather than hiding it for fear of being punished.

  • 6. Train employees regularly to recognize phishing emails and messages: unusual sender addresses, strange links, pressure to act urgently, and requests for passwords or OTP codes. Simulated phishing tests can help keep everyone alert.
  • 7. Set up verification procedures for sensitive actions. Every request to change a receiving bank account, make an urgent transfer or export customer data must be confirmed through a separate channel, for example by calling the requester back on a phone number saved beforehand.

Steps 8–9: Protect devices and sensitive data

8. Protect your devices and internal network. Install anti-malware software on every computer, enable disk encryption (BitLocker on Windows, FileVault on macOS) on laptops that often leave the office, and set screens to lock automatically. Separate guest Wi-Fi from your internal network, and change the default passwords on routers and cameras. If employees work remotely, use a VPN or a secure access solution instead of opening ports directly to the internet.

9. Classify and protect sensitive data. Not all data needs the same level of protection. Identify which data matters most and apply proportionate measures.

  • List everywhere customer, HR, financial and contract data is currently stored.
  • Encrypt sensitive data at rest and in transit; your website should always use HTTPS.
  • Limit file sharing via public links, and set expiration dates on shared links.
  • Collect only the personal data you truly need, with the data subject's consent, and delete it once it has served its purpose.

Step 10: Plan your incident response

10. Have an incident response plan ready. When an incident occurs, the first few hours are critical. Even a short plan of one or two pages is far better than scrambling to find someone to deal with it.

You don't need to tackle all ten in a single week. Start with two-factor authentication, backups and software updates, then work through the rest one by one, and review everything at least once a year. If you don't have dedicated security staff, GREEN TECH can help assess your current situation and put in place security measures suited to the size of your business.

  • Who the point of contact is and who needs to be notified: leadership, the IT team, service providers.
  • Initial containment steps: disconnect infected machines from the network and change the passwords of affected accounts.
  • How to restore from backups, and the order in which each system should be brought back.
  • Obligations to notify the authorities and affected customers in the event of a personal data breach.

Key takeaways

  • Two-factor authentication, strong passwords and least-privilege access are your first layer of protection.
  • Back up using the 3-2-1 rule, test restores regularly and keep software up to date.
  • Staff training and verification procedures stop most scams.
  • Protect personal data in line with regulations and have an incident response plan ready.
Contact us now!

Need an expert partner for your project?

The GREEN TECH team is ready to listen to your business challenges and recommend technology solutions that fit your goals, budget and timeline.

Talk to an expert

Get in touch

Start Your Project
Today

Work with us

Or email us directly at: