# Cybersecurity, compliance, & data automation made for growing businesses.

Cybersecurity, compliance, & data automation made for growing businesses. Cost-effective security, compliance, & database automation solutions to keep your businesses running -- without the enterprise.

[ravi@wersec.com](mailto:ravi@wersec.com)

## Wersec

#### Who are we?

Wersec was born as a brainchild of the founder with 30 years of experience working in cybersecurity, compliance, IT application development mainly at global Fortune 100 companies. We bring a proven, enterprise-grade approach shaped in global organizations and apply it to growing businesses that need strong, practical, and scalable security solutions.

Our focus is to deliver Fortune 100-level expertise and standards through onshore services—at a fraction of the cost typically associated with this level of capability.

## Our Story at Wersec

#### How We Started?

Wersec was formed when a group of senior global executives working for large global Fortune 100s decided to focus our expertise to better the IT and cyber needs of small to medium-sized businesses in our community.

#### Our Growth

Over the years, we have grown from a small startup to a meaningful provider of IT & cyber solutions. Our commitment to innovation, customer service, and quality has helped us build a loyal customer base and establish ourselves as a trusted partner in the industry.

#### Our Philosophy

We bring extensive experience across healthcare, fintech, banking, automotive, and e-commerce/retail industries to help your business thrive—at a fraction of the cost charged by larger providers. Our mission is to deliver this expertise to small and medium-sized businesses in a way that's both impactful, cost-effective, and sustainable.

## Contact Us

#### Questions or Comments?

Send me a message on what you need. I will get back to you soonest.

#### Wersec Inc.

Chicago, Illinois, United States

[ravi@wersec.com](mailto:ravi@wersec.com)

## Our Blog

### Simple Solutions to SMB Staffing Data Security Threats

November 28, 2024

**Time Burden:** 10 min read

Idea behind this article is to share some thoughts on how small to medium-sized (SMB) staffing business owners can protect your business without spending an arm and a leg. Protecting sensitive data of your business need not be expensive. When done consciously, you can ensure optimal security while building trust with your candidates, clients, and partners as you seek a competitive landscape.

Staffing businesses play a vital role in connecting talent with organizations. This connection, however, comes with a significant responsibility: handling a diverse range of sensitive information. This data varies based on the nature of the job but generally includes:

1. **Personally Identifiable Information of candidates:** This includes Social Security numbers (U.S.), names, dates of birth, addresses, phone numbers, and sometimes driver’s license numbers.
2. **Bank account information:** Required for payroll processing.
3. **Background check data of candidates:** Such as criminal records, credit reports, and drug screening results.
4. **Employment history:** Information derived from resumes.
5. **Work authorization and immigration Status of candidates:** Required for legal compliance.
6. **Behavioral assessment Data:** From psychometric tests, as applicable for certain roles.

**Now, what is the worst thing that could happen when this information gets compromised?** Depending on the extent of unauthorized access of this information and who has access, identity theft, financial/insurance fraud, reputational damage, including legal penalties are a possibility. While SMB staffing businesses may not have the cyber muscle power to deploy enterprise-grade security controls, here are some practical cost-effective measures to use to sail safely in the rough seas:

1. **Train your recruiters:** Include mandatory annual data security training for all recruiting and staffing teams minimally outlining what actions are to be avoided when coming in contact with sensitive candidate data. **Why is this important?** When your recruiter uses their personal email to share a candidate's sensitive information and if that email gets compromised, you are taking the liability as the business owner.
2. **Enforce the use of hardened work laptops / company email addresses for business transactions:** Consider recruiters as “high-risk employees” due to their access to sensitive information. Have your recruiters use only their work laptops, work emails to conduct business. Harden these work laptops removing unnecessary apps, using only licensed and authorized software; restrict admin access, enabling multi-factor authentication on all critical operations; and disable mail forwarding / routing from your work email to personal email addresses. **Why is this important?** Reducing and restricting the number of places sensitive data stays within your wheelhouse will avoid a lot of problems down the line for you. Keep things simple.
3. **Use a 3rd party secure file sharing service to send/receive sensitive information:** Use a reputed 3rd party secure file sharing service to send/receive any/all sensitive information from candidates or any 3rd parties. Distribute a Standard Operating Procedure to your staff on how to use this secure file sharing service and avoid exposure of any sensitive information to recruiters' laptops. **Why is this important?** By using these secure file sharing services, you are fulfilling your fiduciary obligations and also in some cases fulfilling your compliance obligations on data encryption, tokenization, access controls required to safeguard them at the right levels.
4. **Outsource Payroll and Payment Processing:** As a small or medium-sized staffing business, it’s often best to focus on your core strengths and leave the complexities of securing payroll and payment transactions, like credit card or ACH, to third-party services. **Why is this important?** By outsourcing these critical services, you are able to minimize your potential security risks and in some cases transfer your compliance/regulatory responsibilities to these 3rd party services, reducing your overall risks.
5. **Create a Data Retention Policy:** Develop an internal policy that specifies how long sensitive candidate and client information should be retained and how it should be securely disposed of. Work with your legal team to enforce this. **Why is this important?** By removing the amount of sensitive data you need to protect, you are not just reducing your cybersecurity risks but also reducing your financial burden.
6. **Include standard security contract clauses with your 3rd party vendors/partners:** Relationships are key in staffing, so include minimum security requirements and data protection clauses in all your contracts with vendors, partners and customers. **Why is this important?** By documenting the minimal expectations from your 3rd party vendors, you are limiting your exposure and cybersecurity liabilities.
7. **Expect the unexpected / Consider cyber liability insurance:** Have a plan in place for whom to contact in the event of a security incident. This should include clear protocols to follow for quick and effective responses. For risks beyond your control, such as risks coming from a 3rd party, consider investing in cyber liability insurance. **Why is this important?** Security incidents are a very common occurrence. Preparing ahead will help you react better and also provide a safety net against potential financial fallout from security incidents.
8. **Establish a Social Media Policy:** Develop guidelines for customer-facing staff, account managers, and recruiters on social media use. **Why is this important?** Their online presence can affect your company’s brand, so ensure they understand the importance of maintaining a professional image.

*Disclaimer: Opinions expressed here are entirely my own and do not represent my current or past employers.*

**Image credit:** Staffingproxy.com
