Ask a business
owner to picture a cyberattack and you'll get the same image almost every time:
someone on the other side of the world, hammering away at the firewall. It's
one of the most persistent myths in small-business security, and it's the wrong
place to start. When I sit down to look at a company's risk, the first question
I ask isn't who's trying to get in. It's who already has a key.
That isn't a
knock on your people. Most insider problems don't involve a villain. They look
like a shared password, a former employee whose account nobody shut off, or a
well-meaning manager pasting a customer list into a free AI tool. Intentional
or not, the exposure is real, and the fix starts in the same place: knowing who
can reach what.
What I look for first
1. Data walking out the door
Customer files
copied to a personal drive on someone's way out. A laptop with client records
that leaves in a backpack and never comes back. Whether it's deliberate or
careless, the question I ask is the same: would you even know it happened?
2. Sabotage
It's rare, but
it's expensive when it happens: someone deletes files, changes passwords, or
locks the business out of its own systems. The window I pay the closest
attention to is the one around a departure, especially one that didn't end
well.
3. Access nobody meant to grant
Permissions
pile up the way boxes pile up in a storage closet. Someone changes roles, and
their access never changes with them. Usually nobody is snooping. They can
simply see things their job doesn't require, and so can anyone who steals their
login.
4. Honest mistakes
The wrong
recipient on an email. A skipped update. A file shared with "anyone with the
link." Nothing malicious, and the same exposure as if it were.
5. Shared logins
One account for
the front desk. The admin password on a sticky note under the keyboard. When
five people share a key, you lose any way to tell which of them used it, and
that's the first thing you'll need to know if something goes wrong.
6. Unapproved AI tools
I've written
about AI business strategy, and my view is simple: AI isn't the problem. Using
it without rules is. When an employee pastes a client contract or a customer
list into a public AI tool nobody has reviewed, that data has left your
control, and you can't pull it back.
What it looks like before it becomes a problem
These are the
patterns worth paying attention to. None of them is proof of anything on its
own, but a cluster of them deserves a closer look.
•
Access that doesn't fit the job: someone
suddenly opening files that have nothing to do with their role.
•
Large or unusual downloads: customer data moving
to a USB drive or personal cloud account.
•
Repeated requests for more access: especially to
systems their responsibilities don't touch.
•
Personal devices on business data: a home laptop
or unmanaged phone opening company files.
•
Security tools turned off: antivirus disabled, a
firewall rule changed, an update blocked.
•
Company data in unapproved AI tools: sensitive
information showing up in platforms nobody has vetted.
•
Changes in behavior: missed deadlines, unusual
secrecy, or visible stress.
The earlier you
notice a pattern, the more options you have for handling it quietly and fairly.
What I'd put in place, in plain terms
1.
Give every person their own login and turn on
multi-factor authentication. A password vault takes away the reason people
share passwords in the first place.
2.
Match access to the job, and revisit it. Every
role change is a reason to review what that person can reach.
3.
Make offboarding a checklist, not a memory exercise.
Accounts disabled the same day, devices returned, shared passwords changed.
This is why we build custom onboarding and offboarding forms with each client
instead of handing over a generic template.
4.
Write down your AI rules, then train to them. Which
tools are approved, and what information never goes into any of them. Keep the
training short and in plain language. People follow rules they understand.
5.
Back up your data and know how you'll respond. I
covered what a solid incident response plan looks like in an earlier post. Make
sure yours includes insider scenarios, not just outside attacks.
Where I'd start
I don't quote
security work sight-unseen, and I'd be skeptical of anyone who does. You can't
fix inside risk until you know where it actually sits in your business.
If you run a
business in Louisville or Southern Indiana and want an honest read on it, book
a 15-minute discovery call. We'll talk through who has access to what, how you
handle departures, and where AI is already showing up in your day-to-day work.
If you're in good shape, I'll tell you that too.
Dean Lause | CEO, Argentum IT
Argentum IT — Veteran Owned and Run