Grow through the stages by headcount 10 of 23 in this group
SOP 155
Set up employee technology and security
What this page is for. Use it when your team works on its own phones and laptops, or when people joining and leaving the business carry data and access with them. It carries the technology function at ten to nineteen people (SOP 152 — Sell a second product at ten to nineteen people), company-owned devices and the rules around them; and at twenty to forty-nine people (SOP 157 — Optimize the business at twenty to forty-nine people), security, onboarding, offboarding and five basic protocols. The function is called IT: how you gather, store, analyze and display information. Each section says which stage it comes from.
SOP-155-Set-up-employee-technology-and-security.md
1. The constraint and what graduates it, by stage
| Stage | The constraint | What graduates it |
|---|---|---|
| Ten to nineteen people | Employees use their personal hardware and software, which causes problems when people leave; nothing tracks the leads and customers dealing with your business | The company provides hardware and software it owns and controls, and a dashboard and reporting system |
| Twenty to forty-nine people | New people are coming in, and old people are leaving with intellectual property, data and access | Cyber security, malware protection and password protection for your employees, with onboarding and offboarding procedures |
2. Ten to nineteen: buy company devices, and do not skimp
Give people company hardware. The warning attached, from a first business: do not skimp. A bad phone, bad service, bad internet, a slow computer, too little memory or RAM: each of these affects productivity. And people will not use work devices if their personal ones are better, faster and more current. So do not be cheap; invest in their work devices.
The arithmetic given. A really good laptop, phone and the rest might cost about $2,000 or $3,000. On a salesperson, you would make that back on one sale a year, so it makes almost no sense not to do it. The cases offered: in a media department, a work computer with twice the upload or download speed of someone's own; and a salesperson on a bad connection who, with better equipment or service, would drop far fewer calls.
The cheap instinct lost out. In one practice, the cheaper of two people thought cheap phones would do, and was the one who ended up losing out overall. Make the slightly higher investment in the short term, to get far more back over the long tail.
It is also a cool factor. A new job comes with new gear: the same kind of moment you create for customers, given to your team. It does not cost much. Spend $2,000 on an employee you pay $100,000, and that is 2 percent of their income. Does the buy-in alone, the sense that it is cool, raise their productivity by 2 percent? Maybe: if they enjoy working on their computer more, they will work more.
3. Ten to nineteen: set the rules on return and damage
Invest in the devices, and put very strong policies around them:
- Return. You get the devices back if they leave.
- Damage. If they damage them, set what they are liable for and what you are liable for.
- Insurance. Get insurance on all of it (SOP 156 section 5).
- The handbook. It can go in the employee handbook: devices are turned in when someone is fired or quits. The handbook's sections, including technology use and what happens to a company-issued computer when someone leaves, are on SOP 149 section 10.
4. Ten to nineteen: own the work, not only the devices
If you have ever had someone walk away with all your SOPs, all your customer data, or all your files of videos you recorded, and you have none of the originals because they took them, this is why you own this stuff. You are now making real investments. The products of their work belong to the company: not only the hardware, but what they did on it. If someone builds complex models that live only on the computer, then when it goes, the work is gone.
That ownership statement is carried as it was made; the law on who owns work product is not covered on this page.
5. Ten to nineteen: the dashboard and reporting system
A dashboard and reporting system is part of what graduates this stage, so that the leads and customers dealing with the business are tracked. How to build one is not established on this page.
6. Twenty to forty-nine: onboard every account through the company
In this view, cyber security is not exciting; most of business is boring. What graduates this stage is security, malware and password protection for your employees, with onboarding and offboarding procedures.
Onboarding means checklists, and an account-creation process, passwords included, for every system, all on company credentials.
- The password tool. By this point you should have a password protection tool; a central tool for passwords came in at five to nine people (SOP 149 section 8).
- Company email only. Make sure every account anyone signs up for is created with their company email. It sounds simple, but you would be surprised: bring in the password tool, people do not want to use it, and they sign up for accounts with their personal email instead. So when you onboard people, allow only the company email, and they must sign up for everything with it.
- Track accounts by email. There are tools that show, for a given email, every account someone has signed up for. So even if a person does not put an account into the password tool, you can see what else they have signed up for with that email.
7. Twenty to forty-nine: train by role
Train each person on each system for their use case or role. In practice, that means training each department on cyber security and on what is unique to it. It will look different for a finance department, a sales department and a customer service department.
Anyone who handles the money, anyone who transacts, needs a lot of training on this. People in operations, maybe managing facilities or events, might not have to worry too much about it. People who facilitate sales, facilitate transactions or handle financial information need training on how to remain compliant and how to keep proper security protocols in place.
Why it matters. The case given is a regular payment sent to a new account, on the strength of a request that seemed to come from the supplier; the supplier's own email had been spoofed. The lesson drawn: these things are real. For some businesses, a loss like that, even when it was not your fault and even when you had insurance, could, in three or four months, destroy the business, because the cash flow is not there. And the more money you handle, the more of a target you become. Cover for losses of this kind is discussed on SOP 156 section 3.
8. Twenty to forty-nine: offboard in one click
If you can create proper onboarding, offboarding becomes easy: if people put their company email into the system and use the password protection, then when they leave you can do a one-click shutdown.
A lot of people hesitate to fire someone because they are worried about everything that person has access to. If you onboard properly and actually use the systems, then when someone goes absent without a word, has to be fired, or quits, you shut it all off in one click by deleting their account from that system. The earlier stage made the same move, deactivating everything when someone leaves (SOP 149 section 8); letting someone go is SOP 153 — Fire without surprise and plan who covers the work.
9. Twenty to forty-nine: the five basic protocols
At this size you need to learn what these mean. The advice given is to understand them well enough that, if you bring in someone to install them in your business, you know the five basics you want. In this order:
| # | Protocol | What it is, as stated here |
|---|---|---|
| 1 | Firewall | Something that monitors and filters what comes into and goes out of your network |
| 2 | Encryption | Encoding data so that only authorized people can read it; for legal and financial information, primarily |
| 3 | Multi-factor authentication | Like logging into Google and being sent a text to your phone to confirm it is you; on multiple accounts, for different people in the company |
| 4 | Software updates and patch management | Keeping software up to date and applying the patches and updates that fix security vulnerabilities; software left un-updated leaves you vulnerable, and often that is where a data breach can come in |
| 5 | Access control | The fewest people possible in control of what are, in the view here, high-risk platforms: financial, legal, transactional, and customer information that is confidential; so that if there is ever a breach, you know only these few people, four in the example, could have had access |
For access control, keep a list of who has access to the riskiest systems. Again, think legal and financial.
10. The bottom line
At ten to nineteen people, your team works on its own hardware and software, so the company provides its own and sets the rules around it. At twenty to forty-nine, people coming in and people leaving with data and access create risk, so you install security protocols, malware and password protection, and proper onboarding and offboarding, so the risk is gone and you can sleep well at night.
11. What this page does not decide for you
- How to build the dashboard and reporting system (section 5). Not established on this page.
- Which tools track accounts by email (section 6). Not established on this page.
- Who installs the five protocols. Not established on this page.
12. What this page does not cover
Chat and project-management tools are on SOP 149 section 8. Employment law and data-protection law are not covered on this page.