The accounting system holds your customers, your prices and your bank details. Most ERP breaches in small firms come from a shared admin login and a pen drive.
Users and roles
One login per person with the rights their job needs; the admin password held by the owner only; TallyVault (or the equivalent encryption) on the company data; the audit trail enabled so every change has a name.
Data movement
Exports to the CA through a shared drive link with expiry, not a pen drive; remote access through the vendor's licensed remote feature or a VPN, never by opening the PC to the internet; the data folder in the daily backup.
The two mistakes
A shared ‘admin / admin’ login used by everyone (no accountability, no way to revoke one person). Data copied to personal phones or drives to ‘work from home’ (the copy is unencrypted and unbacked).
Checklist
- ☐One user per person, least privilege
- ☐Vault / encryption on the data
- ☐Audit trail enabled
- ☐Daily backup includes the data folder
- ☐No pen-drive data movement
- ☐Remote access via licensed feature or VPN only