A notary, accountant, or tax consultant's office usually has five to fifteen people and no IT staff at all. The network was installed by the ISP technician on day one and never touched again.
Yet what the office holds is more sensitive than most shops or cafés: ID card copies, deeds, land certificates, financial statements, and clients' tax data. If files like that leak, the office isn't the only one harmed.
Clients on the guest network, not the office network
This is the cheapest step with the biggest effect. Clients waiting in reception can reasonably be given Wi-Fi, but they don't need to see the printer, scanner, or shared folders on the office network.
- Turn on the guest network on the router, with its own name and password. Make sure the option that separates guests from the local network is on; the name varies by brand, such as isolation, or "allow guests to see the local network" switched off.
- The staff password is never given to clients, including on a note at the reception desk. Only the guest password goes on display.
- Change the guest password regularly, say monthly, so someone who visited a year ago doesn't stay connected from the car park.
How it works is covered in more detail in separating the guest network. If the office uses more than one access point, a cleaner separation can be built with VLANs.
One person, one account
The most common habit in small offices: one office email account shared by everyone, one password for every staff computer, and one router admin account held by who knows whom.
The problem shows when someone leaves. Revoking their access means changing a password everyone uses, so it usually doesn't happen. Create separate accounts per person on computers, email, and file storage, then turn on two-factor authentication for email and cloud services. When someone leaves, only their account needs disabling.
Scanners, printers, and shared storage
A document office almost certainly has a multifunction copier that also scans, and often a network storage device (NAS) where scans collect. Both quietly keep a lot of copies:
- Multifunction machines often have internal storage holding recent scans, and "scan to email" or "scan to folder" features that store passwords. Change the default admin password and switch off features you don't use. Details are in securing a network printer.
- A NAS should only be reachable from the office network, with folders shared by need rather than one folder open to everyone. Choosing one is covered in choosing network storage, and sharing folders safely in file-sharing security on a local network.
- Update firmware on the router, NAS, and multifunction machine. Devices left for years without updates are the doors tried most often. See updating router firmware.
Opening files from outside the office
Sooner or later, the notary or a partner wants to open files from home or while meeting a client. There are two sensible ways, and one to avoid.
Sensible: a VPN to the office, which makes the laptop behave as if it were sitting inside the office network; or a cloud storage service with per-person accounts and two-factor authentication. For an office without IT staff, cloud storage is usually easier to maintain.
Best avoided: exposing the NAS or remote desktop directly to the internet through port forwarding. Once that port is open, anyone on the internet can try the device, continuously, and it's one of the most common ways ransomware gets into small offices.
When working from a café or hotel, the principles in VPNs for public Wi-Fi still apply.
Backups that can actually be restored
Losing files in an office like this is more than an inconvenience. Deeds and client archives carry retention duties, and not all of them can be recreated.
- At least three copies: the working files, one backup in the office, and one backup outside it, either in a cloud service or on drives taken home in rotation.
- A backup that isn't always connected. Ransomware encrypts whatever it can reach, including a backup drive permanently plugged into a computer.
- Test a restore every few months. A backup that has never been restored hasn't been proven to exist.
Automating it is explained in automatic backups on a home network; the principles are the same for a small office. Add a UPS for the NAS and router, so a power cut doesn't damage a disk mid-write.
The duty to protect client data
An office that stores clients' personal data shares the duty to protect it. The general shape is explained in personal data security and the PDP law, and professions such as notaries already carry their own duty of professional confidentiality.
In practice, most of that duty is met by the steps above: separate guests, per-person accounts, locked-down shared devices, remote access without open ports, and backups outside the office. If something does leak, the reporting steps are in reporting a personal data breach.
If there's only time for three things
- Move clients to the guest network and change the staff Wi-Fi password.
- Close any port forwarding on the router whose purpose nobody knows.
- Make one backup outside the office and try restoring a file from it.
The rest can follow. For small office networks in general, including access point placement and choosing a plan, see Wi-Fi for small offices and backup internet for businesses.
Frequently asked questions
Can clients use the same Wi-Fi as staff?
Better not. Clients only need a guest network that opens the internet, without seeing the office printer, scanner, or file storage. Nearly every modern router has this feature and turning it on takes a few minutes.
How can staff open office files safely from home?
Through a VPN to the office, or a cloud storage service with per-person accounts and two-factor authentication. What to avoid is exposing office storage directly to the internet with port forwarding, because anyone can then try it.
Is an external hard drive enough for backups?
One external drive beats nothing, but it fails along with the office in a flood, a theft, or a ransomware attack while it's plugged in. Keep at least one copy outside the office, and test restoring from it now and then.