Your beginners guide to data protection and building a Defence Posture – Top 5 Cyber Security Tips for Small & Medium Businesses
7th July 2024

Beginner Guide To Data Protection: Top 5 Security Tips For Businesses
If any customer or personal information you’re responsible for is lost, accidentally destroyed, altered without proper permission, damaged or disclosed to someone it shouldn’t have been, this could be classed as a data breach.
This could be as a result of a cyber-attack, flood, fire or theft for example.
Where this happens, you’ll need to act quickly and you may need to report it to the ICO within 72 hours. Enforcement action is taken regularly by the ICO including monetary penalties, enforcement notices, prosecutions, and reprimands.
Any personal information your business holds needs to be used fairly and securely in line with data protection laws. This information could be names, addresses, emails, telephone numbers and bank / credit card details.
Keeping personal information secure, and using it responsibly protects your reputation and helps prevent potential harm or distress to people. Good information management also helps maintain your customers trust, which really makes business sense – prevention is better than cure.Person putting credit card details into a mobile phone
You could have personal information stored in multiple places such as your mobile phone, tablet or computer to enable you to do your job – such as the names and contact details of customers, members or clients.
Actionable Steps
Step 1 – You should analyse with your IT partner the different locations of data storage and device usage – you should be generalising types of information such as ‘phone numbers of customers’ rather than listing actual phone numbers etc.
Data protection laws don’t apply when your using personal information for purely personal or household activities, so you can ignore things like family photo albums and personal holiday.
Step 2 – Ask ‘why do I need this information ‘
You must only collect what you actually need, and shouldn’t ask for or ‘keep anything just in case’.
If you’re holding or using people’s information, it must always be fair and lawful. This means you should only use their data in ways they’d reasonably expect.
Step 3 – Security
You must take steps to protect the data you hold.
A fantastic framework for SME’s is the Cyber Essentials program that provides two levels of accreditation and is a great way for organisations to ensure their digital footprint meets the required security standards. More information can be found here for our security programs.
In a 2023 Data Breach Investigations Report, researches found that the top patterns of cyber security threats for small businesses were :
- System intrusion
- Social engineering
- Basic application attacks
This represents 92% of breaches with several types of attacks including phishing, malware, watering hole attacks and drive by downloads driving these categories of threats.
Phishing – is typically launched when a threat actor poses as a legitimate entity to lure individuals into providing sensitive data or launching malicious files. Phishing scams are both common and growing increasing convincing with the help of generative AI tools like ChatGPT.
Malware – is the overarching term for malicious software of any kind. It is the software, script or code that performs an attack on your systems. It is normally disseminated through various vectors, including websites, files, phishing and drive by downloads.
Watering Holes / Drive by Downloads – these can be particularly frustrating as the attack doesn’t always require user interaction. When a person visits a website an unintentional download of malicious code happens without any interaction, once on the endpoint it can hijack the device, spy on activity, exfiltrate data or disable the device entirely.
5 Essential Cyber Security Tips for Small Business
1 – Conduct Regular Software and patch updates
2 – Implement Cyber Security training for employees
3 – Enforce Strong passwords and authentication policies
4 – Ensure your Anti Virus (Endpoint Detection Response) software is of a Tier 1 vendor and proactively managed
5 – Use layered security which includes User Identity Security / Device Security / Application Security / Document Security
We would recommend elevating your security to include:
- Threat & Vulnerability Management
- Attack Surface Reduction
- Next Generation Protection
- Endpoint Detection & Response
- Auto Investigation & Remediation
Step 4 – Be transparent
You must tell people why you need their data, who you’ll share it with and how long you’ll keep if for.
Having a privacy notice is a great way to be transparent.
Step 5 – know how to handle personal data breaches.
If any personal information your responsible for is lost, accidentally destroyed, altered without proper permission, damaged or disclosed to someone it shouldn’t have been this could be a personal data breach. This could be because of a cyber-attack, flood, fire or theft.
If this happens, you should report it to the ICO within 72 hours.
If you would like to discuss any element of your data protection or IT security then please contact us at sales@digital-origin.co.uk











