Current events: a useful file to open the discussion
France Num published a guide to the fundamentals of data encryption, written by Parsec, a service provider referenced as France Num Activator. We use this publication as a starting point; the technical recommendations below are also based on the CNIL sheets cited in the article.
For a small business, the subject begins with a concrete question: what would happen if the computer containing the quotes disappeared tomorrow? Can you find your documents? Do you know which accounts give access to it? Does anyone still have a sharing link that you forgot existed?
These questions cover different issues. Encryption concerns the confidentiality of data made unreadable without the necessary key. Access management concerns the people authorized to consult them. Backup is about your ability to recover a usable copy. A cohesive organization must examine these three dimensions.
Start by finding copies of your customer files
Before choosing a tool, draw the path of an ordinary document. A request can arrive by form, be received by email, copied into a spreadsheet then exported to quotation software. Each step can create a new copy and new access to verify.
Let's take a fictitious craftsman who receives construction site photos. They can remain in their email, on their phone, in a shared folder and in a conversation with a subcontractor. Securing only your computer leaves several other locations out of the reasoning. The inventory must track real uses, including those that seem practical and informal.
Create a simple table with the document type, location, who accesses it, and who is responsible for the account. Add a “to check” column when you ignore an answer. This table is used to prepare for a discussion with your service provider, not to prove that all your security is already under control.
| Document | Location to identify | Priority question |
|---|---|---|
| Request from the site | Messaging and tracking tool | Who receives it? |
| Quote with contact details | Software and local exports | Where are the copies? |
| Construction site photos | Phone and shared folder | Who are they accessible to? |
| Saving documents | Separate support or service | Can we restore it? |
Your site’s journey therefore deserves a place in this inventory. Our website audit in Saint-Brieuc can help frame points to examine on forms and the user journey; a complete assessment of your information system requires specialized support.
Encryption at rest and in transit: two separate questions
The CNIL sheet dedicated to the cloud recommends in particular to consider the encryption of stored and exchanged data, as well as key management. She reminds that security also depends on your configuration and the responsibilities shared with the supplier. A service provider that manages the keys can maintain data access capacity.
To prepare your technical exchange, separate two situations: the file kept on a device or service, and the file sent between two systems. Then ask what happens when someone opens the document with an authorized account. The presence of encryption does not replace the access rules at this stage.
An HTTPS site does not, on its own, demonstrate that all files received by the company are encrypted on each device. Likewise, the word “secure” in an offering does not automatically describe who has the keys or how access is administered. Have the exact perimeter of the announced protection specified.
Do not randomly change a workstation's encryption settings. Prepare the recovery conditions with your service provider: who keeps the necessary elements, where and how does the company access them if the usual manager is absent? Poorly prepared protection can also prevent legitimate users from finding their documents.
An authorized account remains an entry point to protect
An encrypted file can be readable by a person logged in with the necessary rights. If an account is hijacked, it is therefore necessary to examine what it really allows you to do. The CNIL recommends limiting privileges and carefully managing authentication and authorizations in cloud services.
In your inventory, distinguish the account owner, the administrator and the people who use the documents on a daily basis. An employee who has to read a file does not necessarily need to manage all the users. A temporary worker does not necessarily need lasting access to the entire tree.
Plan for a check during shift changes. A person leaves the company, a service provider completes their mission or a shared mailbox is no longer used: these are concrete moments to review rights. Note who is doing this review and how the information gets to them, otherwise everyone may think that someone else is doing it.
Also avoid copying customer documents into an AI assistant to quickly resolve an organizational problem. Start with fictional examples and framed usage. Our article on poor use of AI in business explains why the ease of a tool is not enough to authorize all treatments.
Save: check that the copy can really be used
The CNIL recommends regular backups, including offline copying and preservation on a separate site, as well as restoration controls. Copy protection deserves the same attention as that of current data. A backup available only in the same environment may suffer the same incident.
For your company, the first practical question is: what document should we be able to retrieve to resume a working day? Identify a few representative files with the person who knows the activity. Then prepare a framed recovery test in a separate location, without overwriting the production documents.
Note the date of the copy, the time it took to find the file and the possibility of opening it correctly. A message saying "save successfully" does not answer all of these questions. Testing is used to discover problems while the business is still operating normally.
In our fictitious example, finding a quote is not enough if the essential attachments are missing. Conversely, recovering all the photos without knowing which folder they belong to leaves work to be done again. Define an understandable recovery unit: the complete file necessary to continue an intervention, with its associated information.
Five questions to ask your service provider
Prepare a short conversation from your inventory. Ask where your files are stored, what exchanges are protected, who manages the keys, which accounts can open the documents and how a restore is tested. Ask for an explanation adapted to your uses, with the points remaining to be covered.
Keep the response in a document accessible to responsible people. Add a review date and the contact to contact in the event of an incident. The objective is to be able to act if a person is missing, without depending solely on their memory or their computer.
This organization completes the maintenance of your website. Site updates, account management and file recovery fall within scopes which must be explained in the support chosen. Check what is covered and assign the remaining tasks to an identified individual.
Frequently asked questions about protecting customer files
Is an encrypted file protected against all incidents?
No. It is also necessary to examine the authorized accounts, the devices used and the recovery capacity. Encryption does not replace access management or backup and does not, on its own, guarantee protection against ransomware.
Is cloud storage enough for backup?
Don't assume so. Specify the recovery functions, their duration and their independence from current files. Synchronization and a restorable backup do not necessarily meet the same need.
Can we test a restoration without stopping the activity?
A test can be prepared on a copy in a separate location, with the appropriate provider. It must avoid overwriting the data used by the team. Define the scope, the people involved and the verification expected before the operation.
Where to start when you're short on time?
Choose a representative client file and follow its copies of the form until archiving. Identify the unknowns, then have access and recovery checked as a priority. This first concrete scope is more usable than a general list of tools to purchase.
Official sources
Transform reading into action.
Start by clarifying the requests and documents that pass through your site. ISS-AGENCY can organize this process and the points to be examined with your technical service provider.
Request the audit

