TacDesk
All articles

Cyber Security Basics for Security Companies: Protecting Guard and Client Data

Security companies handle sensitive guard, client, and site data every day — here's what basic cyber hygiene looks like for a manned guarding business.

By Michael Bryce · 6 August 2026 · 3 min read

Security companies spend a lot of energy protecting other people's premises and think comparatively little about protecting their own data. That's a gap worth closing. A guard management system holds SIA licence numbers, home addresses, DBS references, client site plans, alarm codes, and incident reports — exactly the kind of data a criminal or a nosy competitor would want. Ironically, the business built on physical security is often one of the softer targets on the digital side.

What's actually at risk

Think about what sits in your systems right now: guard personal details and right-to-work documents, client keyholding and alarm instructions, site vulnerability notes from incident reports, and financial data like charge rates and invoices. A breach of any of this isn't just embarrassing — it's a live safety and compliance problem. Leaked alarm codes or key safe locations turn a data breach into a physical security incident at a client site.

Common weak points in security company IT

The most common failure isn't a sophisticated hack — it's basic hygiene. Shared logins across a whole control room team, password reuse from personal accounts, guard-facing apps installed on personal phones with no separation from work data, and spreadsheets of client site details emailed around without encryption. None of these require a hacker with special skills to exploit; they just require someone to lose a phone or click a phishing link.

Practical steps that don't need a big budget

Individual logins for every user, not shared accounts — this alone makes an audit trail possible when something goes wrong. Multi-factor authentication on anything that touches client or guard data, including email. A clear policy on what can and can't be stored on personal devices, especially for guards using their own phones for clock-in and reporting. Regular review of who has access to what — an ex-employee's login should be revoked the day they leave, not whenever someone remembers.

Encryption in transit and at rest matters too, but this is largely something your software vendor should be handling rather than something you build yourself. When you're evaluating guard management software, ask directly: is data encrypted at rest, where is it hosted, who can access it, and what happens in a breach. A vendor that can't answer clearly is a red flag.

Why this matters for ACS and client trust

ACS assessors are increasingly asking about data handling as part of the wider governance and management standard, not just about vetting paperwork. Clients running tender processes for contracts involving sensitive sites — government, critical infrastructure, financial services — are starting to ask security suppliers for evidence of basic cyber hygiene as standard due diligence. Being able to answer confidently is a competitive advantage, not just a compliance checkbox.

Building it into how you operate

You don't need a dedicated IT security function to get the fundamentals right. Pick software that takes this seriously by design, enforce individual logins and MFA, train guards and office staff on phishing basics, and have a plan — even a simple one — for what you'd do if a device was lost or an account was compromised. Most breaches in smaller security companies come from basic gaps like these, not sophisticated attacks, which means most of the risk is genuinely manageable with modest effort.


Ready to modernise your security operations? Request a free demo of TacDesk and see how cloud-based guard management can transform your business.

MB

Michael Bryce

Founder of TacDesk. Writes about SIA compliance, operations, and running a UK security company — from someone who actually works the shifts.

Connect on LinkedIn →

See TacDesk in action

Win contracts, pass SIA audits, and run your whole operation from one place. Book a free 30-minute demo.

Book a Free Demo

Get Field Notes

The ACS traps, licensing changes and ops shortcuts we write about — one straight email every week or two, from someone still doing the shifts, not a marketing team. Unsubscribe anytime.