Buying one
Four questions: per-user logins? Two-factor? Export to CSV? And, in writing: does our data train your models? A vendor that dodges any of them has answered.
Think of it as the plan I’d follow if this were my own shop: what I’d put in place first, what would come next, and how I’d use customer data to help the business once it was properly protected.1
Thursday, 6:10 in the evening. An email from a supplier you use - same logo, same sign-off, new bank details. Nobody targeted you. A script found an unlocked mailbox upstream and sent ten thousand of these today. That is what most small companies face: automated attacks fishing for the reused password, the mailbox without two-factor, the unpatched laptop, the untested backup.2
AI is already helping uncover new software flaws. In the wrong hands, it makes attacks faster and easier to scale. The fix is still the same five moves, done properly - most of them in an afternoon, on tools you already pay for.
Because attackers automate and defenders don't. A script doesn't care that you're small - you look exactly like everyone else it scans.
The baseline removes the five things the scripts are written to find. Past that line, extra spending buys very little until the business gets more complicated.
Every other door hangs on this one. A password manager so no password is repeated, and two-factor on anything that touches money, email, or customer data. Keep an admin account you rarely touch and a daily account you live in. A phish eventually catches everyone; set up this way, it catches the small account, not the keys to the company.
A laptop gets left in a cab. That sentence should end “so I bought a new laptop” - not “so we wrote to every customer we have.” The difference is four switches that ship with the machine: encryption, automatic updates, screen lock, remote wipe. Flip them today. There is no step two.
Most fraud never hacks anything. It just asks: an email that looks like a vendor, or like you, wanting a wire or a new account number. Set SPF, DKIM, and DMARC so strangers can't send mail wearing your domain. Then one house rule: anything that moves money gets confirmed on a second channel, every time. Especially when it looks like it came from the boss.
Ransomware becomes a business-ending problem when the locked files are your only copy. So: three copies, two kinds of storage, one somewhere your machine cannot reach. Then the step almost everyone skips: restore a file, once, this month. I have seen a backup that had been failing quietly for a year. It looked fine until the day it was needed.
Write one list: every system, who can get in, at what level. Give people the least they need to do the job. When someone leaves, the list becomes the offboarding checklist, walked the same day. It also finds the contractor who still has keys from two years ago.
Here is what I see in small companies: the customer data gets used like a phone book. Look up a number, log a call, done. Connected to AI correctly, the same records start answering the questions you have: who has gone quiet, who is ready for more, what to write to them this week. Connected carelessly, they are the leak in the next section.
First, the boring questions, wherever the records live - real CRM, homemade database, or the spreadsheet with the hopeful name. Where does it live? Who can read it? Is it encrypted? Is it in the backups? Can you take all of it with you the day you leave the vendor?3
Four questions: per-user logins? Two-factor? Export to CSV? And, in writing: does our data train your models? A vendor that dodges any of them has answered.
If you build, build lazy. A managed database someone else patches, one login per person with real roles, the encryption boxes checked. A server you patch by hand is how a side project becomes a liability.
The record you never store cannot leak. Keep what serves the relationship, skip what doesn't, and never hold card numbers; taking that risk is what payment processors are paid for.
At solo scale a spreadsheet is a perfectly good CRM, if it lives behind two-factor, sits in the backups, and never travels as an attachment. The day two people need it daily, move.
Scoped and read-only: the tool sees the fields it needs and nothing else, a no-training agreement sits behind it, and a log shows what was read. Your assistant knows your customers; the vendor doesn't.
Every setup is different. I help choose the safest useful connection, put the pieces in the right order, and make it fit the way your business works.
Because a breached customer list is the one security failure your customers experience personally - fraud that knows their name, in their inbox.
And lock-in is a security problem too: a vendor you can't export from is one you can't leave when their security slips.
I have watched the newest leak happen in real time. Someone on the team pastes the customer list into a free chatbot to draft follow-up emails. An hour saved, genuinely. And the customer list is now on someone else's server, under a personal account, on terms nobody read. With a cloud AI tool, treat every prompt as information sent to that provider.
Banning the tools does not work - people just go quiet about using them. What works is three sentences, written down. One: we use the business accounts, not personal ones. Two: the training setting is off, and we have that in writing.4 Three: card numbers, passwords, and health details never get pasted at all. For sensitive work, keep the raw customer data local and send the outside model only what it needs. Hand that to the team, and the whole problem moves into daylight.
Because the pasting is never malice - it is someone trying to work faster. Punish it and it goes underground, onto personal accounts with no agreement and no logs.
Rules you can say out loud in ten seconds are the ones people follow. Make the safe way the easy way.