-
Introduction to Cybersecurity
-
Assessing Your Current State
-
Building a Security-Conscious Culture
-
Device Management and BYOD Policies
- Phishing and Social Engineering Attacks
- Password Management and Authentication
-
Security Practices and Device Planning
- Data Backup and Recovery
-
Securing WiFi and Network Connections
-
Payment and Financial Security
-
Payment Providers and System Separation
- Multifactor Authentication and Advanced Protocols
-
Expert Consultation with Colabmo
-
Conclusions and Next Steps
Protocols for Sharing Sensitive Information
Share sensitive information deliberately
Learning edition: 5 October 2026. Introductory learning material.
Before sharing, confirm the recipient, purpose, information required and approved transfer method. Encryption helps protect transmission, but it does not correct a wrong recipient or overly broad access.
- Share only the information needed for the task.
- Use approved services with recipient-specific access and appropriate authentication.
- Review link permissions and expiry settings before sending.
- Keep access records where required and remove access when it is no longer needed.
- Follow retention and incident-reporting procedures.
Activity: Review a sample sharing link using non-sensitive test content. Confirm who can open it and how access can be revoked.
Reference: FTC cybersecurity guidance for small businesses. Check the source and your system provider’s current instructions before implementation.
Sharing with an AI service is still sharing
Use a business-approved tool and account for the task. Before entering work data, check the provider’s current retention, training-use, access and deletion terms, and the organization’s rules. A paid subscription alone does not establish suitable protection.
Use the minimum approved information. Do not paste passwords, recovery codes, customer records or confidential business material into an unapproved AI service. Removing a name may leave a person or organization identifiable from other details.
Activity: Write an approved-use example using fictional data, and one example that requires a data owner’s review. If information was shared incorrectly, report it promptly; deleting the chat may not remove every retained copy.
Further reading: ASD ACSC, NCSC NZ and COSBOA: Artificial intelligence for small business (2025 edition).
There are no comments for now.