Back to the on-screen lesson ·

Protect payments and data

Most small-business losses come from ordinary tricks; confirm changed bank details by phone, use unique passwords with a second login step, back up separately, collect only needed data, price each protection by the expected cost it removes, and know the first steps after a breach.

Paper packet. Every task here also exists on screen, where it is checked automatically; answers written on paper are not assessed by Nydus. When you are back at a device, enter your answers there.

1. What you will learn

You will price card fraud and three security risks, test whether a fraud check pays, handle a fake change of bank details, work what a backup is worth, fill in a shop's fraud sheet, and work what a phone-check rule saves.

2. What you already have

Records are now useful and backed up. They, and the money flowing through the business, are also worth stealing. Most losses in small businesses come from ordinary tricks, and ordinary habits stop them. The risk map's arithmetic applies here too: a chance, a cost, and what a protection removes.

3. Words for this lesson

TermWhat it means
Payment fraudTricking a business into sending money to the wrong place, often with a fake request to change bank details.
Second login stepA code from a phone or app asked for as well as the password.
ChargebackA card payment the bank takes back from the business, as when a stolen card was used.
BreachSomeone getting at data or accounts they should not.
Data minimizationCollecting and keeping only the data a purpose needs.
Least accessGiving each person only the accounts and files their work needs.

4. Five habits that stop most losses

  1. Confirm changed bank details by phone, on a number you already had. An email saying 'our bank has changed, pay this account' is the commonest payment fraud; the email can look exactly like the supplier's.
  2. A unique password for every account, with a second login step. One stolen password then opens nothing else, and alone opens nothing at all.
  3. Back up to somewhere separate, automatically. A lost laptop or a ransom demand then costs a day, not the business's history.
  4. Collect only what you need. Data never collected cannot leak. Card details belong with the payment provider, not in a spreadsheet.
  5. Give each person only the access they need, and remove it when they leave.

$$\text{what a protection saves} = \text{expected cost without} - \text{expected cost with}$$

Fraud can be priced like any risk. Maya's shop takes 3,000 orders a year; about 2 in every thousand use stolen cards, and the bank takes back each one, averaging 60 dollars: 3 × 2 × 60 = 360 dollars a year. A checkout fraud check that halves that saves 180 a year, so it pays if it costs less.

Another way: table

Threats and the habits that answer them.

ThreatHabit
Fake bank detailsPhone on a known number
Stolen passwordUnique passwords, second step
Lost deviceSeparate backup
Data leakCollect less
Former staffRemove access when they leave

Another way: steps

  1. List the security risks: fake requests, stolen passwords, lost devices, leaks.
  2. Put a chance and a cost on each, and work the expected cost.
  3. Price each protection: expected cost without it, less with it, less its own cost.
  4. Make the cheap habits rules, whatever the arithmetic says.
  5. Write down the first steps after a breach before one happens.

5. The method, step by step, and how to check it

List the risks. For a small business the list is short and familiar: a fake request to change bank details, a stolen or guessed password, a lost or broken device, a leak of customer data, a former employee who still has access, a card payment made with a stolen card.

Price them. Each gets a chance in a year and a cost, as on the risk map. The cost of a lost laptop without a backup is the time to rebuild the records, if they can be rebuilt at all. The cost of a paid fake invoice is usually the whole invoice, since banks rarely recover it.

Price the protections. A protection either cuts the chance — a phone check, a second login step — or cuts the cost — a backup. Either way, what it is worth is the expected cost without it less the expected cost with it.

Check each figure by sense. A protection that cuts the chance to a tenth saves nine tenths of the expected cost; a backup that cuts the cost of a loss saves the chance times the difference in cost, never more.

6. Why the cheap habits win

Most of the habits in this lesson cost almost nothing: a phone call, a password manager, a backup service for a few dollars a month, a shorter sign-up form. Set against the losses they prevent, they pay many times over, so they should be rules rather than decisions made each time.

Payment fraud through fake bank details deserves special attention because a single success can cost more than a year's profit. The fraud works by imitating a real supplier at the moment a real invoice is due, often from a supplier's own email account that has been broken into, so the message can come from a genuine address and mention a genuine invoice. The only reliable check is outside the message: a phone call to a number the business already had. No genuine supplier minds that call.

7. Passwords, second steps and access

A password used on one account and reused on another is only as safe as the least careful of the two websites. When one leaks, criminals try the same email and password everywhere else. A password manager lets every account have its own long password without anyone having to remember them.

A second login step — a code from an app or a text message — means a stolen password alone opens nothing. It matters most on the accounts that open everything else: the business email, the bank, the payment provider, the accounting software.

Give each person only the access their work needs, and remove it on their last day. A cleaner needs the day's door codes, not every customer's; a part-time bookkeeper needs the accounting software, not the bank's payment screen.

8. Collect less, and keep card details out

Data never collected cannot leak. A sign-up form for a seasonal email needs a name and an email address; birth dates, home addresses and phone numbers add nothing to the email and add harm if the list is ever lost. Delete what is no longer needed, too: old customer lists, former staff files, scanned documents kept 'just in case'.

Card details belong with the payment provider. Businesses that take cards must follow the card industry's security standard, PCI DSS, and the simplest way to meet it is never to store card numbers at all, letting the provider's checkout handle them.

9. If something goes wrong

The first hour matters. Stop the damage: change the password, end logged-in sessions, disconnect an infected computer. Secure the other accounts, starting with email and the bank. Tell those who need to know: the bank if money moved — quickly, because the chance of stopping a transfer falls by the hour — the software provider, affected customers, and any authority the law requires. Every US state has a law requiring businesses to notify people whose personal information is exposed, each with its own rules and deadlines, so owners check the rules where they operate. Then find the cause and fix it.

Write these steps down before they are needed, with the bank's fraud line and the providers' contacts, because in a breach nobody thinks clearly.

10. Habits the whole team keeps

Most of these habits depend on people, not software, so staff need to know them. A short conversation when someone joins, and a reminder now and then, covers the essentials: never change where money is sent without a phone call on a known number; never share a password or a login code, even with someone claiming to be from the bank or the software provider; report a lost phone or laptop the same day; and tell the owner at once about anything odd, without fear of blame.

That last point matters more than it seems. A staff member who clicked a bad link and says so within the hour gives the business a chance to change passwords and stop the damage. One who is afraid of being blamed and says nothing gives the intruder days. Owners who thank people for reporting mistakes hear about them sooner.

Criminals also call. A caller claiming to be from the bank, the tax authority or the card processor, asking for a login code or an urgent payment, is using the same trick as the fake email: pressure and a borrowed name. The same rule answers it: hang up, and call back on a number the business already had.

11. In the world: a contractor's fake invoice

A small roofing contractor in Tampa, Florida, paid its shingle supplier about 40 invoices a year, averaging 8,000 dollars. One spring the office manager received an email from the supplier's real address, replying in a genuine thread about a genuine order, saying the supplier's bank had changed and attaching new details. The supplier's own email had been broken into.

The manager paid 11,400 dollars to the new account. The real supplier called two weeks later about the unpaid invoice. The bank, told late, recovered nothing, and the contractor paid the invoice a second time: a loss larger than two months of its profit.

The owner then priced the rule the firm should have had. Without a phone check, the owner guessed perhaps 1 invoice in 200 could be a successful fake: 40 ÷ 200 × 8,000 = 1,600 dollars a year expected. With a rule that every change of bank details is confirmed by phone on a number from an old invoice, perhaps 1 in 2,000: 160 a year. The rule saved about 1,440 a year on average, for the cost of a phone call. The firm also turned on second login steps for its email and bank, and told its customers it would never change its own bank details by email.

12. In the world: guidance for small businesses

Government agencies such as the Federal Trade Commission and the Cybersecurity and Infrastructure Security Agency publish free, plain guidance for small businesses on these habits. The habits in this lesson are the core of that guidance.

13. Where this goes wrong

Small businesses are not targets. They are targeted because they are less protected.

An email from a known address is genuine. Addresses can be faked, and real accounts can be broken into.

Keep customer data in case it is useful. Collect only what is needed.

A strong password is enough. Add a second login step, and never reuse it.

A backup stops the loss. It makes the loss cheaper; the device is still gone.

Security is the software provider's job. Providers secure their systems; the business still chooses the passwords, turns on the second step, decides who has access, and answers the phone when a fake supplier calls.

A breach can be handled when it happens. Without written steps and contacts ready, the first hours are lost to searching for phone numbers while the damage spreads.

14. Northside Repairs' near miss

  1. Read the request.

    $\text{pay } 4200 \text{ to a new account}$

    An email 'from' the parts wholesaler.

  2. Check outside the email.

    $\text{phone the number on last year's invoices}$

    A contact she already had.

  3. Hear the answer.

    $\text{their bank has not changed}$

    The email was a fraud.

  4. Report the fake email.

    $\text{to her bank and the wholesaler}$

    Their email may be compromised.

  5. Make it a rule.

    $\text{every change of bank details gets a call}$

    The habit made a rule.

15. Maya's checkout fraud check

  1. Count the thousands of orders.

    $3000 \div 1000 = 3$

    A year.

  2. Count the fraudulent orders.

    $3 \times 2 = 6$

    Two in every thousand.

  3. Price the fraudulent orders.

    $6 \times 60 = 360$

    A year of chargebacks.

  4. Work the fraud with the check.

    $3 \times 1 \times 60 = 180$

    Half the rate.

  5. Find what the check removes.

    $360 - 180 = 180$

    The most it is worth.

  6. Compare with its fee.

    $120 < 180$

    It pays, by 60 a year.

16. Bright Home Cleaning's security map

  1. Work the fake bank details.

    $0.1 \times 5000 = 500$

    One in 10, a whole invoice.

  2. Work the lost laptop.

    $0.2 \times 4000 = 800$

    Rebuilding the records.

  3. Work the leaked door codes.

    $0.05 \times 8000 = 400$

    Changing locks and lost trust.

  4. Price the backup.

    $0.2 \times (4000 - 200) = 760$

    A backup service at 60 a year.

  5. Price the phone-check rule.

    $500 - 0.01 \times 5000 = 450$

    For the cost of a call.

  6. Limit the door codes.

    $\text{each cleaner sees that day's codes}$

    Least access.

  7. Write the breach steps.

    $\text{stop, secure, tell, fix}$

    Before they are needed.

17. Your turn: Monica's laptop

  1. Work the expected cost without a backup.

    $0.2 \times 3000 = 600$

    Rebuilding her records.

  2. Work it with a backup.

    $0.2 \times 100 = 20$

    A morning restoring files.

  3. Your turn: work this step out. Its working is at the end of the packet.

    Find what the backup is worth.

18. Guided practice

Maya's online shop takes $3000$ orders a year. About $1$ in every thousand turn out to be paid with stolen cards, and each such order, averaging $80$ dollars, is taken back by the bank. Complete the sentence.

About f orders a year are paid with stolen cards, costing her c dollars.

19. Guided practice

Complete the worked solution: Maya's shop takes $2000$ orders a year, and about $4$ in every thousand use stolen cards, each costing her $70$ dollars. A checkout fraud check would cut that to $1$ in every thousand and costs $150$ dollars a year. Find what the check adds to her year's profit.

  1. Multiply the thousands of orders, the rate and the cost.

    $2 \times 4 \times 70 =$ l

    Fraud now, a year.

  2. Do the same at the checked rate.

    $2 \times 1 \times 70 =$ m

    Fraud with the check.

  3. Subtract the second from the first.

    $(\text{now}) - (\text{checked}) =$ s

    What the check removes.

  4. Subtract the check's fee.

    $(\text{removed}) - 150 =$ n

    What it adds.

  5. Read the sign.

    $\text{positive, so the check pays}$

    The same test as any reduction.

20. Guided practice

Bright Home Cleaning maps three security risks for the year. A fake change of bank details paid by mistake: a $3$ in 20 chance, costing $6000$ dollars. The office laptop lost with no backup: a $3$ in 10 chance, costing $4000$ dollars to rebuild the records. A stolen email password used to trick customers: a $5$ in 20 chance, costing $2000$. Fill in each risk's expected cost, in dollars.

Expected cost, dollars
Fake bank details
Lost laptop
Stolen password

21. Practice

Neighborhood Kitchen receives an email that appears to come from its meat supplier: 'Our bank has changed. Please pay this month's invoice of $2244$ dollars to the new account below.' What should the owner do?

22. Practice

Northside Repairs reckons there is a $3$ in 10 chance a year of losing its office laptop. Without a backup, rebuilding the records would cost about $7000$ dollars; with a nightly backup, restoring them would cost about $700$. How much a year, on average, is the backup worth, in dollars?

Answer:

23. Somewhere new

An online candle shop in Austin takes $9000$ orders a year. About $4$ in every thousand use stolen cards; each costs the shop the $150$-dollar order, which the bank takes back. A fraud-screening service at $500$ dollars a year would cut the rate to 1 in every thousand. Fill in the working sheet.

Amount
Fraudulent orders a year now
Fraud cost a year now
Fraud cost a year with screening
What screening adds a year

24. Lesson test

Lesson test: one question per skill, one attempt each, no hints. Your answers are checked when you submit.

25. Test question

Neighborhood Kitchen pays about $400$ supplier invoices a year, averaging $7000$ dollars. It estimates that without a rule, $1$ invoice in every $200$ could be a fake change of bank details that gets paid; with a rule that every change is confirmed by phone on a known number, $1$ in every $2{,}000$. How much a year, on average, does the rule save, in dollars?

Answer:

26. What you can do now

You can protect a small business's money and data with a few habits, and price what each is worth. Tell someone how to check a request to change bank details. Next: choosing a tool.

Working for the steps left to you

17. Your turn: Monica's laptop, step 3

$600 - 20 = 580$

Against a service at 60 a year.