AppSoluteTec — Practical business technology and automation guides for small business owners.

How to Evaluate Software Security for a Small Business

Many small businesses have realised the importance of having robust software security measures in place. Cyber threats are becoming increasingly common, and it's essential for small businesses to take steps to protect themselves.

Evaluating Software Security

The first step is to evaluate your current software security.

  1. Assess the types of data you store: Consider what personal identifiable information you hold and how it may be used by cybercriminals.
  2. Look for signs of vulnerability: Check for outdated software, weak passwords, and unsecured connections.
  3. Consider data encryption: Ensure that your data is encrypted to prevent interception by hackers.

It's also essential to consider the consequences of a data breach. This can result in financial losses, damage to reputation, and legal action being taken against your business.

Choosing the Right Software

When choosing new software, look for vendors that have a good track record when it comes to security.

It's also essential to consider mobile security when choosing software that you'll use on-the-go. Look for vendors that offer secure connections and encryption.

How to Put This Into Practice

You don't need a technical background to run a reasonable security check on a piece of software before signing up. Start with the vendor's own security or trust page, usually linked in the footer of their website. Look for three things: whether two-factor authentication is available on every plan (not just the enterprise tier), whether data is encrypted both in transit and at rest, and which country or region the data is actually stored in.

Email the vendor directly if the answers aren't public — a reasonable vendor will answer within a day or two. Ask specifically: "Where is our data physically hosted?" and "Do you hold any independent security certification such as ISO 27001 or SOC 2?" A vendor that can't answer either question clearly, or becomes evasive, is a warning sign regardless of how polished the product looks. Also check what happens if the vendor is breached — does their contract or terms of service commit to notifying you within a set number of days, as UK GDPR effectively requires for personal data incidents.

A Worked Example

A four-person bookkeeping practice was choosing between two client-portal tools for sharing financial documents. Tool A had a slicker interface and was £10 a month cheaper. Tool B's website took longer to load but had a clear security page stating data was hosted in the UK, encrypted at rest with AES-256, and covered by an ISO 27001 certificate renewed the previous year.

The practice owner emailed both vendors asking where client data was stored. Tool A's support team took four days to reply and said data was hosted "on secure cloud servers" without naming a location or certification. Tool B replied within a few hours with the exact data centre region and a link to their certification. Given that the practice handled clients' financial records and had its own professional indemnity obligations to consider, it chose Tool B despite the higher price — a decision that took under a week of back-and-forth emails to reach.

Common Mistakes

A Simple Checklist

Frequently Asked Questions

What is the most common type of cyber attack on small businesses?

Phishing attacks are a common threat, as hackers often try to trick employees into revealing sensitive information.

How can I protect my data from being intercepted by hackers?

Data encryption and secure connections are essential for protecting your data.

What should I do if I suspect that my software has been compromised?

Act quickly to contain the breach and notify your vendors and any relevant authorities.

The increasing reliance on technology by small businesses highlights the need for effective digital infrastructure management to maximise productivity and mitigate cyber risks. — Editor, AppSoluteTec