The responsibility for IT security now rests entirely on your organization. Unlike utilities such as electricity or telecom, IT is not heavily regulated. As reliance on technology grows, organizations must be prepared to invest more in security.
At Electric Software, we adapt to meet the changing needs of our clients. In 2025, we will place an even greater emphasis on security and compliance. While we aim to reduce costs where possible, every client should expect increased IT spending based on:
1. The sensitivity of your data and compliance requirements.
2. The importance of your data to your operations.
3. The number of users needing secure access.
4. The systems requiring safeguards.
5. The potential cost of a critical security incident.
We've spent the past two years researching and consulting with security experts to develop comprehensive solutions. Moving forward, we'll focus on:
• Keeping Electric Software safe.
• Protecting client data and operations.
• Electric Software needs to stay fully operational so we can continue to provide the services our clients depend on. So will be taking steps to limit our exposure if clients choose not to follow recommendations.
A comprehensive safeguard checklist is crucial for maintaining robust security practices. This checklist covers key areas that organizations should address to protect their digital assets and sensitive information.

The standard safeguard checklist should be regularly reviewed and updated to ensure it remains effective against evolving cyber threats. It serves as a foundation for implementing and maintaining a strong security posture across the organization.

Use Keeper or other company-approved password manager to store and manage passwords securely.
Stop employees from saving passwords in their browsers, like Chrome or Edge.
Teach employees how to create strong passwords and why it's important not to reuse them.
Set up secure, password-free options like facial recognition or phone-based codes.
Require two-step verification (MFA) for all logins to add extra protection.
Only allow logins from approved devices and locations.
Keep Microsoft 365 or Google Workspace updated
Monitor for suspicious activities
Stop cyberattacks proactively
• Keep your Microsoft 365 or Google Workspace settings updated for the best protection. • Set up alerts for suspicious activities, like mass deletions or unauthorized sharing of files. • Enable tools that scan for and stop cyberattacks before they happen.
Spot potential data leaks or unusual behavior
Prevent malicious emails from reaching employees
Automatically secure emails or provide secure file sharing links
• Automatically encrypt emails with sensitive information or provide a secure link for sharing files.
• Block spam and phishing emails from reaching employees.
• Monitor email activity to spot potential data leaks or unusual behavior.
Use Mobile Device Management (MDM) to separate personal and work data on employee devices.
Set rules to remotely lock or wipe work data if a device is lost or compromised.
Consider providing secure, company-owned devices for employees accessing sensitive data.
Find and fix potential weaknesses
Cloud, servers, networks, sensitive apps
Run regularly and fix promptly
• Schedule regular penetration testing to find and fix potential weaknesses in your systems. • Prioritize testing for cloud accounts, servers, networks, and any apps handling sensitive data. • Regularly run scans for vulnerabilities and fix them promptly.
Use managed Endpoint Detection and Response (EDR) tools to quickly spot and stop threats.
Install antivirus and anti-malware software on all devices.
Keep all devices up to date with the latest patches and security updates.
Watch for and respond to ransomware attempts automatically.
Provide annual training for employees to spot scams and phishing attempts.
Run practice phishing simulations to improve awareness.
Tailor training to your industry, such as focusing on CIPA compliance for schools or PCI DSS for businesses.
Meet legal and industry requirements
Regular compliance updates
Response and notification
• Create and maintain written policies to meet legal and industry requirements (e.g., CIPA, HIPAA, PCI DSS). • Schedule regular compliance reviews and updates. • Have a plan in place for responding to breaches and notifying affected parties.
Ensure quick data recovery
Emails, cloud drives, servers
For emergencies like ransomware
• Test your disaster recovery plan to ensure you can recover lost data quickly.
• Back up all important files, including emails, cloud drives, and servers.
• Keep a separate copy of backups in case of emergencies, like a ransomware attack.
Scan your network regularly for weaknesses.
Use firewalls and content filters to block dangerous websites and activities.
Protect your DNS (the address book of the internet) to prevent hackers from redirecting traffic.
Regular security checks
Up-to-date coverage
Strict transaction policies
• Test your systems regularly to ensure they're secure.
• Keep cyber insurance up to date to cover potential losses.
• Set up strict rules for financial transactions to avoid scams like fake payroll changes.
Block inappropriate websites as required by CIPA.
Restrict student access to only what they need for schoolwork.
Manage school devices like Chromebooks or tablets to keep them secure.
Protect donor and volunteer data with strong encryption and controls.
Train staff to spot scams targeting donations or sensitive information.
Use secure payment systems that follow PCI DSS rules.
Protect HR files with strict access controls and encryption.
Stay compliant with rules like PCI DSS, HIPAA, or GDPR, depending on your industry.
Make sure any apps handling payments or sensitive data are secure and regularly checked.
Set up alerts for quick response
System health and potential risks
Watch for stolen credentials
• Use Dark Web Monitoring to watch for stolen credentials. • Provide regular reports on your systems' health and any potential risks. • Set up alerts to respond quickly to threats or unusual activity.
For financial transactions
Prevent fraudulent requests
Spot fake money requests
• Require multi-step approvals for financial transactions to avoid scams.
• Train employees to spot fake requests for money, like gift card or payroll scams.
Security for 2025