-
Introduction to Cybersecurity
-
Assessing Your Current State
-
Building a Security-Conscious Culture
-
Device Management and BYOD Policies
- Phishing and Social Engineering Attacks
- Password Management and Authentication
-
Security Practices and Device Planning
- Data Backup and Recovery
-
Securing WiFi and Network Connections
-
Payment and Financial Security
-
Payment Providers and System Separation
- Multifactor Authentication and Advanced Protocols
-
Expert Consultation with Colabmo
-
Conclusions and Next Steps
Identifying What Needs Protection
Identify what needs protection
Learning edition: 5 October 2026. Introductory learning material.
Create an inventory that connects information and systems to the work they support. Include customer and employee records, financial information, business documents, accounts, devices and supplier services.
- Record where information is stored and shared.
- Identify the business owner and who can access it.
- Note which records are sensitive and why.
- Identify retention, contract and regulatory questions for the appropriate owner.
- Include cloud services and business information on approved personal devices.
Activity: Map one record from collection through use, sharing, storage and disposal. Record any access or retention questions that need a decision.
Reference: NIST small-business cybersecurity framework resources. Check the source and your system provider’s current instructions before implementation.

Look closely: Different information needs different protection. Identify the owner, sensitivity, access rules and recovery needs for each category before choosing controls.
Security Measures by Afsal CMK, via UC Berkeley CLTC. CC BY 4.0. Unmodified image.
Include AI in the inventory
Ask where people use AI, including meeting assistants, browser extensions, personal accounts and features built into existing software. Record the business purpose, owner, approved account, data involved and connected services. Discuss why people use unapproved tools so the business can provide workable alternatives.
Activity: Add one AI tool to your inventory, or record that none is used. Identify who can approve it and remove its access.
Further reading: NCSC: The hidden risks of shadow AI (7 September 2026).
There are no comments for now.