[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9IGpCVSSu9qOPDZS7qkXHxoxX80TIcXicHGBCev-s7o":3},{"item":4},{"id":5,"idKnowledge":6,"idDomain":7,"idCluster":7,"kindOverride":7,"slug":8,"title":9,"description":10,"bodyMarkdown":11,"bodyHtml":12,"author":13,"date":14,"createdAt":15,"topics":16,"image":18,"hasDownload":19,"fileName":7,"youtubeId":20},"489","EF440659-2093-3643-B0C9-559220CE37EC","","hoe-bescherm-je-bedrijfsdata-zonder-werkvertraging","How to protect your business data without slowing down work","How do you protect business data without slowing down your processes? Practical measures for FileMaker, integrations, apps and employees. In practice.","A sales employee exports a customer list to Excel to work on the go. An integration with an accounting package uses a single shared password. An old FileMaker account still has full access because no one is sure what it was created for. This is how data breaches usually happen: not through a spectacular hack, but through a practical exception that becomes permanent unnoticed. Anyone asking: **how do you protect business data** without slowing down operations must therefore look beyond antivirus software alone.\n\nGood data security aligns with how your organization actually works. Employees need to find information, process orders and collaborate with customers or suppliers. At the same time, you want to prevent personal data, financial data, price agreements or intellectual property from reaching someone who has no reason to access it. The solution is not an extra lock on every door, but a clear system of roles, access rules, basic technical measures and controls.\n\n## How do you protect business data in existing systems?\n\nFor many SMBs, business data is not in one place. It sits in a FileMaker database, cloud storage, an accounting package, mailboxes, mobile devices and web applications. That makes a generic security policy insufficient. The risk is often in the transitions: an export, an API integration, a temporary import folder or an account belonging to an external party.\n\nStart with a practical overview. What data is business-critical? Where is it stored, processed and copied? Who uses it, with which application and from which location? You don't need to classify every column in a database immediately. Start with data whose loss, unwanted modification or disclosure causes direct damage, such as customer data, contracts, personnel files, quotes, inventory and financial data.\n\nMake a distinction between availability, confidentiality and accuracy. A planning tool that is unavailable for one morning presents a different problem than a database where bank account numbers leak. An incorrect price in an order can be operationally just as damaging as unauthorized download. That nuance determines which measure has priority.\n\n### Access based on work, not based on trust\n\nThe most effective first step is access control. Give people access to what they need for their function, not to everything that is technically available. For example, a planner should be able to modify assignments, but not see all salary data. An external accountant may need access to financial exports, but not to operational customer notes.\n\nIn FileMaker, this works well with [clear accounts and privilege sets](https:\u002F\u002Floggix.com\u002Fblog\u002Fa-practical-guide-to-identity-and-oauth-for-business-integrations\u002F). Avoid shared login credentials. Not only do you lose visibility into who did what, but you also cannot selectively revoke access when someone changes role or leaves. Make administrator rights scarce and document why someone has those rights.\n\nReview these rights periodically, for example each quarter and always when someone leaves, changes role or a new supplier is brought in. In practice, old accounts often remain because the system has been developed without formal ownership. Especially in custom systems, this is a manageable risk as long as someone is responsible for this review.\n\nMulti-factor authentication belongs wherever possible, especially for administrators, external access and cloud portals. It is not a replacement for good rights structures, but an important protection against stolen passwords. Choose a method that fits your working environment. For employees on the shop floor, logging in should not become so cumbersome that shared accounts become tempting again.\n\n## Secure the technology around your data\n\nAccess rights help little if data in transit or storage is insufficiently protected. Make sure connections to business applications are encrypted, for example via TLS. For FileMaker environments, this includes, among other things, a properly configured SSL certificate and secure connections between FileMaker Pro, FileMaker Go, WebDirect or other connected services.\n\nEncryption of database files is a separate consideration. For sensitive data, encryption at rest is usually sensible, but it also requires careful key management, recovery procedures and administrator accounts. An encrypted database that no one can open after an incident is not a useful measure. So don't just test whether encryption is enabled, but also whether recovery works according to procedure.\n\nBack-ups deserve the same attention as the production environment. A backup often contains all data from the primary system and is thus an attractive target. Store backups encrypted, separate from the production server and with limited access. Maintain multiple recovery points so that an encrypted or damaged database does not automatically overwrite the only available backup.\n\nTest recovery actually. A notification that a backup succeeded only proves that a file was created. Only when you can restore a copy, open it and verify its completeness do you know your continuity measure works. For systems that support order processing, planning or invoicing, this is an operational test, not a purely technical exercise.\n\n### API integrations are often the weak point\n\n[Integrations save manual work](https:\u002F\u002Floggix.com\u002Fapis\u002F), but increase the attack surface. Think of a FileMaker solution that exchanges customer data with Exact, a webshop, Microsoft 365, a payment provider or a mobile app. Every integration has authorizations, tokens, error messages, logging and data flows that need to be managed.\n\nUse a separate technical account for each integration with as few rights as possible. An API that may only create new orders does not need to be able to delete or export the entire customer database. Do not store access tokens hardcoded in scripts, layouts or loose documentation. Document who owns the integration, what data it processes and how you revoke access when a supplier or employee leaves.\n\nAlso pay attention to error handling. Technical logs are needed to manage an integration, but must not inadvertently contain passwords, tokens or complete personal data. Set retention periods and limit who can view these log files. In custom development, this can often be built in without users having to perform extra steps.\n\n## Make employees part of the protection\n\nMany security measures fail not through unwillingness, but through time pressure. Someone shares a file via a personal email account because a customer needs a quick response. A colleague clicks on a convincing invoice email because it appears to come from a known supplier. Clear procedures make secure behavior simpler than improvising.\n\nDiscuss specific situations from your own process: who may export an address list, how do you share documents with external parties and what does someone do when they see a suspicious login notification? A short, recurring instruction works better than an annual document that no one reads. Also give employees a low-threshold route to report concerns. Quick reporting should be seen as careful conduct, not as causing a problem.\n\nUse mobile devices and home workplaces with policy. That doesn't mean every device must be managed by IT, but it does mean you determine what data may be stored locally, whether screen locking is mandatory and how access is revoked if a device is lost. An app with only planning tasks has different requirements than an app with customer files and contracts.\n\n## Document what you do if something goes wrong\n\nNo environment is completely risk-free. Therefore, an incident procedure is just as relevant as prevention. In advance, document who decides when a data breach is suspected, who can block technical access, where logs and backups are located and how you inform users or customers if necessary. Under GDPR, reporting obligations may apply. Waiting until all details are known is not always wise.\n\nA useful procedure doesn't need to be long. The core is that people know what to do immediately: report the problem, don't cover up suspicious access themselves, block affected accounts if necessary and determine the impact. Practice this scenario occasionally, for example around a lost laptop, a phishing email or an incorrectly configured user role.\n\n## Choose improvements that match your risk\n\nNot every organization needs the same security architecture. A small team with one internal FileMaker solution has different priorities than an organization with field staff, customer portals and multiple API integrations. Start with points that offer both risk and practical benefit: unique accounts, appropriate rights, current software, encrypted connections, reliable backups and control over external access.\n\nModernizing doesn't have to mean [a complete replacement](https:\u002F\u002Floggix.com\u002Fblog\u002Fbuild-buy-or-extend-how-to-choose\u002F) of an existing system. Often it's smarter to gradually strengthen a valuable FileMaker solution with better rights management, secure integrations, logging and a modern web or mobile interface. Loggix precisely helps organizations fit such improvements without stopping daily work.\n\nThe best security is ultimately visible in the ease of the process: employees can keep working, administrators know who has access and you can demonstrate where critical data is located. Don't start with the most complicated technology, but with the next situation where someone today can see, share or modify more data than necessary. That's usually where the quickest improvement lies.","\u003Cp>A sales employee exports a customer list to Excel to work on the go. An integration with an accounting package uses a single shared password. An old FileMaker account still has full access because no one is sure what it was created for. This is how data breaches usually happen: not through a spectacular hack, but through a practical exception that becomes permanent unnoticed. Anyone asking: \u003Cstrong>how do you protect business data\u003C\u002Fstrong> without slowing down operations must therefore look beyond antivirus software alone.\u003C\u002Fp>\n\u003Cp>Good data security aligns with how your organization actually works. Employees need to find information, process orders and collaborate with customers or suppliers. At the same time, you want to prevent personal data, financial data, price agreements or intellectual property from reaching someone who has no reason to access it. The solution is not an extra lock on every door, but a clear system of roles, access rules, basic technical measures and controls.\u003C\u002Fp>\n\u003Ch2>How do you protect business data in existing systems?\u003C\u002Fh2>\n\u003Cp>For many SMBs, business data is not in one place. It sits in a FileMaker database, cloud storage, an accounting package, mailboxes, mobile devices and web applications. That makes a generic security policy insufficient. The risk is often in the transitions: an export, an API integration, a temporary import folder or an account belonging to an external party.\u003C\u002Fp>\n\u003Cp>Start with a practical overview. What data is business-critical? Where is it stored, processed and copied? Who uses it, with which application and from which location? You don&#39;t need to classify every column in a database immediately. Start with data whose loss, unwanted modification or disclosure causes direct damage, such as customer data, contracts, personnel files, quotes, inventory and financial data.\u003C\u002Fp>\n\u003Cp>Make a distinction between availability, confidentiality and accuracy. A planning tool that is unavailable for one morning presents a different problem than a database where bank account numbers leak. An incorrect price in an order can be operationally just as damaging as unauthorized download. That nuance determines which measure has priority.\u003C\u002Fp>\n\u003Ch3>Access based on work, not based on trust\u003C\u002Fh3>\n\u003Cp>The most effective first step is access control. Give people access to what they need for their function, not to everything that is technically available. For example, a planner should be able to modify assignments, but not see all salary data. An external accountant may need access to financial exports, but not to operational customer notes.\u003C\u002Fp>\n\u003Cp>In FileMaker, this works well with \u003Ca href=\"https:\u002F\u002Floggix.com\u002Fblog\u002Fa-practical-guide-to-identity-and-oauth-for-business-integrations\u002F\">clear accounts and privilege sets\u003C\u002Fa>. Avoid shared login credentials. Not only do you lose visibility into who did what, but you also cannot selectively revoke access when someone changes role or leaves. Make administrator rights scarce and document why someone has those rights.\u003C\u002Fp>\n\u003Cp>Review these rights periodically, for example each quarter and always when someone leaves, changes role or a new supplier is brought in. In practice, old accounts often remain because the system has been developed without formal ownership. Especially in custom systems, this is a manageable risk as long as someone is responsible for this review.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication belongs wherever possible, especially for administrators, external access and cloud portals. It is not a replacement for good rights structures, but an important protection against stolen passwords. Choose a method that fits your working environment. For employees on the shop floor, logging in should not become so cumbersome that shared accounts become tempting again.\u003C\u002Fp>\n\u003Ch2>Secure the technology around your data\u003C\u002Fh2>\n\u003Cp>Access rights help little if data in transit or storage is insufficiently protected. Make sure connections to business applications are encrypted, for example via TLS. For FileMaker environments, this includes, among other things, a properly configured SSL certificate and secure connections between FileMaker Pro, FileMaker Go, WebDirect or other connected services.\u003C\u002Fp>\n\u003Cp>Encryption of database files is a separate consideration. For sensitive data, encryption at rest is usually sensible, but it also requires careful key management, recovery procedures and administrator accounts. An encrypted database that no one can open after an incident is not a useful measure. So don&#39;t just test whether encryption is enabled, but also whether recovery works according to procedure.\u003C\u002Fp>\n\u003Cp>Back-ups deserve the same attention as the production environment. A backup often contains all data from the primary system and is thus an attractive target. Store backups encrypted, separate from the production server and with limited access. Maintain multiple recovery points so that an encrypted or damaged database does not automatically overwrite the only available backup.\u003C\u002Fp>\n\u003Cp>Test recovery actually. A notification that a backup succeeded only proves that a file was created. Only when you can restore a copy, open it and verify its completeness do you know your continuity measure works. For systems that support order processing, planning or invoicing, this is an operational test, not a purely technical exercise.\u003C\u002Fp>\n\u003Ch3>API integrations are often the weak point\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Floggix.com\u002Fapis\u002F\">Integrations save manual work\u003C\u002Fa>, but increase the attack surface. Think of a FileMaker solution that exchanges customer data with Exact, a webshop, Microsoft 365, a payment provider or a mobile app. Every integration has authorizations, tokens, error messages, logging and data flows that need to be managed.\u003C\u002Fp>\n\u003Cp>Use a separate technical account for each integration with as few rights as possible. An API that may only create new orders does not need to be able to delete or export the entire customer database. Do not store access tokens hardcoded in scripts, layouts or loose documentation. Document who owns the integration, what data it processes and how you revoke access when a supplier or employee leaves.\u003C\u002Fp>\n\u003Cp>Also pay attention to error handling. Technical logs are needed to manage an integration, but must not inadvertently contain passwords, tokens or complete personal data. Set retention periods and limit who can view these log files. In custom development, this can often be built in without users having to perform extra steps.\u003C\u002Fp>\n\u003Ch2>Make employees part of the protection\u003C\u002Fh2>\n\u003Cp>Many security measures fail not through unwillingness, but through time pressure. Someone shares a file via a personal email account because a customer needs a quick response. A colleague clicks on a convincing invoice email because it appears to come from a known supplier. Clear procedures make secure behavior simpler than improvising.\u003C\u002Fp>\n\u003Cp>Discuss specific situations from your own process: who may export an address list, how do you share documents with external parties and what does someone do when they see a suspicious login notification? A short, recurring instruction works better than an annual document that no one reads. Also give employees a low-threshold route to report concerns. Quick reporting should be seen as careful conduct, not as causing a problem.\u003C\u002Fp>\n\u003Cp>Use mobile devices and home workplaces with policy. That doesn&#39;t mean every device must be managed by IT, but it does mean you determine what data may be stored locally, whether screen locking is mandatory and how access is revoked if a device is lost. An app with only planning tasks has different requirements than an app with customer files and contracts.\u003C\u002Fp>\n\u003Ch2>Document what you do if something goes wrong\u003C\u002Fh2>\n\u003Cp>No environment is completely risk-free. Therefore, an incident procedure is just as relevant as prevention. In advance, document who decides when a data breach is suspected, who can block technical access, where logs and backups are located and how you inform users or customers if necessary. Under GDPR, reporting obligations may apply. Waiting until all details are known is not always wise.\u003C\u002Fp>\n\u003Cp>A useful procedure doesn&#39;t need to be long. The core is that people know what to do immediately: report the problem, don&#39;t cover up suspicious access themselves, block affected accounts if necessary and determine the impact. Practice this scenario occasionally, for example around a lost laptop, a phishing email or an incorrectly configured user role.\u003C\u002Fp>\n\u003Ch2>Choose improvements that match your risk\u003C\u002Fh2>\n\u003Cp>Not every organization needs the same security architecture. A small team with one internal FileMaker solution has different priorities than an organization with field staff, customer portals and multiple API integrations. Start with points that offer both risk and practical benefit: unique accounts, appropriate rights, current software, encrypted connections, reliable backups and control over external access.\u003C\u002Fp>\n\u003Cp>Modernizing doesn&#39;t have to mean \u003Ca href=\"https:\u002F\u002Floggix.com\u002Fblog\u002Fbuild-buy-or-extend-how-to-choose\u002F\">a complete replacement\u003C\u002Fa> of an existing system. Often it&#39;s smarter to gradually strengthen a valuable FileMaker solution with better rights management, secure integrations, logging and a modern web or mobile interface. Loggix precisely helps organizations fit such improvements without stopping daily work.\u003C\u002Fp>\n\u003Cp>The best security is ultimately visible in the ease of the process: employees can keep working, administrators know who has access and you can demonstrate where critical data is located. Don&#39;t start with the most complicated technology, but with the next situation where someone today can see, share or modify more data than necessary. That&#39;s usually where the quickest improvement lies.\u003C\u002Fp>\n","Jeroen","2026-09-09",1788954207000,[17],"Socials","\u002Fapi\u002Fknowledge\u002Fimage\u002F489\u002F?v=e9a7014f59ee",false,null]