Protecting customer information is a core responsibility for any solo business. The goal is not to run an enterprise security programme. The goal is to reduce risk to a level that matches the scale and value of the business. This article gives direct, practical steps you can apply today to limit exposure, simplify recovery, and maintain trust with customers.
Start with a simple risk inventory
You cannot protect what you do not know you hold. Create a single plain text inventory that lists the types of customer information you collect and store. Include data sources, formats, and where each item is kept. For example payments via payment processor, invoices on your computer, email exchanges with attachments, and exported CRM data in a cloud folder.
Next, score each item for sensitivity and necessity. Ask three questions for each type of data Is it required to deliver my service Is it required by law Would losing it harm the customer or my business If the answer is no, delete or stop collecting the data. Prioritize protection work on data that is both sensitive and necessary.
Limit collection and storage
Minimizing the data you hold reduces your exposure and ongoing maintenance. Apply clear rules and automation where possible.
Practical rules to adopt
Only collect required fields when taking orders or signing clients. Do not collect birth dates or national identifiers unless absolutely required.
Prefer tokenised payment processors such as Stripe or Square so you never store card numbers.
Keep the smallest useful retention period. For common documents set a retention period such as 12 months or 24 months and schedule automatic deletion.
Avoid sending customer files to personal email accounts. Use a dedicated business email and a shared storage location with proper access controls.
- Only collect required fields
- Use tokenised payment processors
- Set and automate retention periods
- Avoid personal email for customer files
Control access and authentication
Access control is the highest leverage control for a solo operator. Even if you are the only person with access you are still subject to compromise from weak authentication.
Use a reputable password manager to generate and store unique passwords for every account. Recommended options include Bitwarden and 1Password. Do not reuse passwords across accounts.
Enable two factor authentication on all accounts that support it. Use an app based second factor such as Authy or Google Authenticator rather than SMS when possible. For critical accounts consider a hardware security key such as a YubiKey.
Lock down local devices with strong user passwords and enable full disk encryption. On Mac enable FileVault. On Windows enable BitLocker. Keep operating systems and applications up to date and install only software you need.
Backups and recovery planning
Backups are insurance. The plan must be automated, encrypted, and tested.
Set up an automated backup for all customer data using at least two distinct locations. For example a local backup drive and an encrypted cloud backup. Confirm the cloud provider encrypts data at rest and in transit.
Encrypt backup files with a strong passphrase before uploading if the backup solution does not provide end to end encryption. Record the passphrase securely in your password manager.
Practice restoration twice a year. A backup that cannot be restored is not useful. Time the restores so you know how long recovery will take and what steps you will need to operate in the meantime.
- Automate backups to two locations
- Use encryption for backups
- Store backup passphrases in your password manager
- Test restores at least twice a year
Prepare for incidents and communication
Even with good controls incidents can occur. Having a simple incident playbook reduces confusion and harm. Your playbook can be a single page that covers detection, containment, recovery, and communication.
Detection notes should list the signs of compromise you will watch for such as unexplained file changes, account login alerts, or customer reports of suspicious messages that appear to come from you. Containment steps should include revoking access credentials, rotating keys and passwords, and isolating infected devices from your network.
For recovery include where backups are stored, who to contact for urgent help such as a trusted IT consultant, and how to restore customer facing services. For communication prepare a short factual message to customers that explains what happened what you are doing about it and what customers should do if anything. Keep legal and regulatory requirements in mind and consult counsel if the incident involves sensitive personal information.
- Create a single page incident playbook
- List signs of compromise to monitor
- Define containment and recovery steps
- Prepare a factual customer message template
Keep it maintainable and proportional
Security for a solo business must be practical and repeatable. Automate routine tasks where you can. Schedule a quarterly review of your data inventory, access list, and backups. Use simple checklists rather than complex policies.
Invest time in training yourself on phishing awareness and basic operational hygiene. The most common compromise vector is targeted email. If you cannot verify a link or attachment do not open it. Maintain a list of trusted vendors and support contacts so you do not fall for impersonation.
Finally, be honest with customers. Clear communication about what you collect and how you protect it builds trust. If you follow the steps in this article you will substantially reduce risk without the cost and complexity of enterprise security programs.
Take these three things away
- Collect only the customer data you genuinely need for the service
- Store data securely and delete it once there is no business reason to keep it
- Check the specific legal requirements for your jurisdiction with a qualified adviser
Written for the Hayley Duster editorial project as general information for people running businesses alone. It is not medical, legal, financial or tax advice, and it is not a substitute for guidance from a qualified professional who knows your circumstances.
All articles