Field guide

Cybersecurity Basics for Service Contractors

Low-friction controls that help protect scheduling, customer, and payment-related information.

This guide provides an operating framework, not legal, financial, safety, medical, licensing, or regulatory advice. Adapt it to your business and local requirements.

Inventory business-critical accounts

List email, field service, accounting, payments, file storage, website, and domain accounts. Record the owner, recovery method, and who should retain access when a staff member leaves.

Require strong authentication

Use unique passwords stored in a reputable password manager and enable multi-factor authentication wherever available. Avoid shared credentials because they prevent meaningful access control.

Limit access by role

Technicians, dispatchers, office staff, and external bookkeepers do not need identical permissions. Grant the minimum access required and review it when responsibilities change.

Prepare for suspicious messages

Train staff to pause when messages request credentials, payment changes, urgent downloads, or unusual account actions. Verify sensitive requests through a known, separate contact method.

Back up and test recovery

Identify the records required to resume scheduling and customer communication. Maintain protected backups and periodically restore a sample so recovery is more than an assumption.

Practical next step: Choose one section, turn it into a one-page checklist, assign an owner, and test it during normal operations before making it standard.

← Back to all guides