How to Evaluate Software Security for a Small Business
Many small businesses have realised the importance of having robust software security measures in place. Cyber threats are becoming increasingly common, and it's essential for small businesses to take steps to protect themselves.
Evaluating Software Security
The first step is to evaluate your current software security.
- Assess the types of data you store: Consider what personal identifiable information you hold and how it may be used by cybercriminals.
- Look for signs of vulnerability: Check for outdated software, weak passwords, and unsecured connections.
- Consider data encryption: Ensure that your data is encrypted to prevent interception by hackers.
It's also essential to consider the consequences of a data breach. This can result in financial losses, damage to reputation, and legal action being taken against your business.
Choosing the Right Software
When choosing new software, look for vendors that have a good track record when it comes to security.
- Check for certifications: Look for software that has been certified by reputable bodies such as the National Institute of Standards and Technology (NIST).
- Review their security policies: Understand how your data will be protected and stored.
- Assess their incident response plan: Find out what action they will take in the event of a breach.
It's also essential to consider mobile security when choosing software that you'll use on-the-go. Look for vendors that offer secure connections and encryption.
How to Put This Into Practice
You don't need a technical background to run a reasonable security check on a piece of software before signing up. Start with the vendor's own security or trust page, usually linked in the footer of their website. Look for three things: whether two-factor authentication is available on every plan (not just the enterprise tier), whether data is encrypted both in transit and at rest, and which country or region the data is actually stored in.
Email the vendor directly if the answers aren't public — a reasonable vendor will answer within a day or two. Ask specifically: "Where is our data physically hosted?" and "Do you hold any independent security certification such as ISO 27001 or SOC 2?" A vendor that can't answer either question clearly, or becomes evasive, is a warning sign regardless of how polished the product looks. Also check what happens if the vendor is breached — does their contract or terms of service commit to notifying you within a set number of days, as UK GDPR effectively requires for personal data incidents.
A Worked Example
A four-person bookkeeping practice was choosing between two client-portal tools for sharing financial documents. Tool A had a slicker interface and was £10 a month cheaper. Tool B's website took longer to load but had a clear security page stating data was hosted in the UK, encrypted at rest with AES-256, and covered by an ISO 27001 certificate renewed the previous year.
The practice owner emailed both vendors asking where client data was stored. Tool A's support team took four days to reply and said data was hosted "on secure cloud servers" without naming a location or certification. Tool B replied within a few hours with the exact data centre region and a link to their certification. Given that the practice handled clients' financial records and had its own professional indemnity obligations to consider, it chose Tool B despite the higher price — a decision that took under a week of back-and-forth emails to reach.
Common Mistakes
- Assuming a professional-looking website or app interface is evidence of good underlying security.
- Not checking whether 2FA is actually available on the plan you're paying for, rather than a higher tier.
- Accepting vague language like "bank-level encryption" or "enterprise-grade security" without asking what it specifically means.
- Never checking where data is physically hosted, which matters for GDPR compliance if it's outside the UK or EU.
- Failing to ask what the vendor's breach notification process is before an incident happens, rather than after.
A Simple Checklist
- Check whether 2FA is available on your actual plan tier
- Confirm the data hosting location and whether it's UK/EU based
- Look for an independent certification such as ISO 27001 or SOC 2
- Ask about encryption in transit and at rest in plain terms
- Confirm the vendor's breach notification commitment in writing
- Review who at the vendor can access your data and under what conditions
Frequently Asked Questions
What is the most common type of cyber attack on small businesses?
Phishing attacks are a common threat, as hackers often try to trick employees into revealing sensitive information.
How can I protect my data from being intercepted by hackers?
Data encryption and secure connections are essential for protecting your data.
What should I do if I suspect that my software has been compromised?
Act quickly to contain the breach and notify your vendors and any relevant authorities.
The increasing reliance on technology by small businesses highlights the need for effective digital infrastructure management to maximise productivity and mitigate cyber risks. — Editor, AppSoluteTec