Every small business – be it a restaurant, beauty salon, travel agency or retirement village – is a data custodian. It’s a responsibility you should take seriously. Otherwise, you’ll make your company vulnerable to breaches, endanger your customers’ identity and finances, and increase your organisation’s liability. Knowing how to protect personal information online matters to comply with local and international regulations and keep your brand’s reputation unblemished.
Types of Personal Information
Personally identifiable information is any data that can reveal an individual’s identity when used alone or combined with other pieces of information. The most common types are:
- Names
- Physical addresses
- Phone numbers
- Email addresses
- Login credentials
- Photos
- Biometric data – such as fingerprints and unique patterns within irises
- Audio or video recordings
- Unique identifiers – like driver’s license numbers
The Privacy Act provides 13 information privacy principles to govern how small businesses should collect, store, use and share personal data. The Privacy Commissioner has also issued six codes of practice, modifying how the principles apply to some industries.
How to Protect Personal Information Online – 4 Tips
Protecting personal information online can be technical and complicated. However, observing these four best cybersecurity practises for small-business owners can make life more difficult for hackers.
1. Inventory All Data Repositories
Understanding where you store sensitive information enables you to make sound decisions.
Generally, organisations store sensitive data on-site, off-site or a combination of the two. Most fall into the third category.
Cloud computing has minimised the amount of data a business owner keeps on-site. Using cloud-based applications means storing information on servers housed in remote locations. Cloud service providers may operate their data centres or rent space in colocation facilities.
Data centres almost always have superior cybersecurity compared to in-house hardware. These buildings employ impregnable physical security measures and implement sophisticated network strategies to keep criminals at bay. Their operators also back up data off-site to prevent loss in case of a natural disaster, ensuring painless retention and retrieval over the long term.
When you outsource personal information protection duties to a third party, catalogue what you store on-site to reinforce your repositories’ cybersecurity proactively.
2. Encrypt Everything
Encryption makes personal data unintelligible to unauthorised parties. An encryption key is necessary to unscramble the unreadable text.
Data encryption renders any personal data in your custody useless when hacked. Some algorithms are stronger than others, so use industry standards to reduce your cybersecurity blindspots.
You can use various tools to encrypt data hackers, fraudsters and identity thieves may go after. Consider the following:
- Encryption software: This tool locks files behind an encryption system and turns ordinary folders into encrypted vaults. Some have advanced features – like file shredding, which permanently deletes content you want gone for good.
- Password manager: This tool serves as an encrypted directory for dozens of login credentials and generates strong passwords, reducing the need to remember or write anything.
- Hypertext transfer protocol secure (HTTPS): This encryption protocol secures communications between a website owner and visitors. If your site has HTTPS, snoopers won’t be able to view activities on it.
3. Educate Your Staff and Customers
Hackers target the weakest links in the cybersecurity chain, which are technologically illiterate employees and customers. Educate them about basic cybersecurity practises and cyberthreats.
For example, preach the merits of password strength over memorability to make online accounts harder to crack by brute force. Another recommendation is to enable two-factor identification to add a second layer of defence against malicious parties. Explaining the ins and outs of phishing also makes average internet users more difficult targets of social engineering attempts to steal login credentials.
Staying current with the latest cyberattacks should go without saying. Arranging cybersecurity refresher training and proactively informing customers about the latest threats they should worry about inspires vigilance.
4. Designate a Privacy Officer
This person keeps tabs on all your organisation’s privacy obligations, allowing you to comply with standards more easily. This way, there’s no confusion about who should keep up with cybersecurity trends and communicate findings with others.
Even if you have a small business, assign the privacy officer role to at least two capable employees. This enormous, sensitive task is more manageable when shared.
Adopt Sound Practises in Cybersecurity for Small-Business Owners
Personal data theft is too lucrative to convince hackers and phishers to stop. Fortunately, cybercriminals take the path of least resistance. Knowing how to adequately protect personal information online instantly makes your organisation a less desirable target.
