A stolen or failed device is the most likely security incident a small business will experience. Encryption, automatic backup, a lock screen, and remote wipe are settings rather than projects, and together they make the loss inconvenient rather than serious.

The likely incident

Not an intrusion. A device left in a vehicle, lost at an airport, dropped in water, or simply failing.

For most small businesses that is the realistic security event, and it is the one least planned for, because security advice is written about attackers.

The consequences split into two: losing access to what was on the device, and somebody else gaining access to it. Different protections address each, and both are straightforward.

Encryption

The single most important setting and one many people have never checked.

Full disk encryption means that without the password, the contents are unreadable. Without it, somebody who takes the device can read everything on it by removing the drive, regardless of your login password.

It is built into current operating systems on both desktop and mobile, it is frequently on by default on newer devices and frequently not on older ones, and enabling it is a settings change rather than a project.

The one requirement it creates: the recovery key must be stored somewhere other than the device, because a forgotten password on an encrypted drive means the data is genuinely gone.

Backup that actually runs

The other half, addressing loss rather than exposure.

Automatic and continuous rather than something somebody remembers. A backup requiring a manual step is a backup that stops happening within a month.

Worth having both: a cloud backup, which survives theft and fire, and a local copy, which is faster to restore from and does not depend on a subscription.

The step almost nobody takes: restoring something from the backup to confirm it works. A backup nobody has tested is an assumption rather than a protection, and discovering it was incomplete during an actual loss is the worst moment to find out.

Testing it once a year, by restoring a single file, takes minutes.

The lock screen

Trivial and consistently neglected.

A device that locks after a short period, requiring a password or biometric, is the difference between a lost laptop and a lost laptop somebody can use.

On a phone, a passcode rather than a simple pattern, since patterns are readable from the smudges.

Biometric unlocking is convenient and worth using, with the underlying passcode still strong, since that is what protects the device when biometrics fail or are bypassed.

Remote wipe and find

Available on every current platform and frequently not enabled.

It lets you locate a device, lock it remotely, display a message, and erase it if recovery is hopeless.

Enabling it costs nothing and requires being signed into the platform account, which most people are. Confirming it is on, and knowing where to go to use it, is the part worth doing before you need it.

For a device holding customer information, remote wipe is what converts a data exposure into a device loss.

The personal and business mixture

The reality for most small businesses, and worth managing rather than pretending otherwise.

One phone holding personal photographs, family messages, business email, customer contacts, and banking. One laptop used by the owner and occasionally by a family member.

What that creates: a device that cannot be wiped without personal loss, business information accessible to whoever borrows it, and no separation if the device is examined for any reason.

The practical middle ground, short of separate devices: a separate user account on shared computers, keeping business information in a work account rather than a personal one, and not letting others use the device that holds business banking.

Where staff use their own devices for work, the position needs deciding rather than drifting: what is accessible, what happens when they leave, and whether customer information sits on a phone you do not control.

The physical part

Unglamorous and it prevents most of these incidents.

Not leaving devices visible in vehicles, which is how a large share of business laptop thefts happen. Not leaving a laptop unattended in a public place, even briefly. And not leaving a device unlocked while you walk away.

For a trade with a vehicle, a device out of sight in a locked box is a meaningfully different proposition from one on a passenger seat.

Disposal

The step that gets skipped entirely.

A device sold, traded, given to a family member, or discarded still contains everything unless it was erased properly.

On an encrypted device, a factory reset is generally sufficient, since the data becomes unreadable. On an unencrypted one, a simple reset may leave recoverable data.

Which is another argument for encryption: it makes disposal safe as a side effect.

The same applies to phones traded in, and to old devices sitting in a drawer, which are frequently the least protected devices a business owns.

The afternoon

  1. Confirm encryption is on for every device, and store the recovery keys elsewhere.
  2. Confirm backup is automatic, and restore one file to test it.
  3. Set the lock screen to a short timeout.
  4. Enable find and remote wipe.
  5. Erase and dispose of old devices properly.

That is an afternoon against the most likely incident, and it sits alongside the continuity question of what happens if you cannot be reached, as covered in security when there is only you.


Frequently asked questions

What is the likely security incident?

A device lost, stolen, or failing. That is the realistic event for most small businesses and the one least planned for.

Why does encryption matter?

Without it, somebody who takes the device can read everything by removing the drive, regardless of your login password. It is a settings change on current systems.

What does encryption require?

Storing the recovery key somewhere other than the device, since a forgotten password on an encrypted drive means the data is genuinely gone.

What makes a backup real?

That it runs automatically and that you have restored something from it. A backup nobody has tested is an assumption rather than a protection.

What about mixing personal and business use?

Decide rather than drift. Use separate accounts on shared computers, keep business information in a work account, and settle what happens with staff-owned devices.

What is forgotten at disposal?

Old devices still contain everything unless erased properly. On an encrypted device a factory reset is generally sufficient, which is another argument for encryption.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Never checked whether the work laptop is encrypted?

We run the five settings that turn a stolen device into an inconvenience rather than an incident.

Start a Conversation