<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>The Proton Blog</title><description>News from the front lines of privacy and security</description><link>https://proton.me/</link><language>en</language><feed_url>https://proton.me/feed</feed_url><item><title>What is business resilience? Definition and key strategies</title><link>https://proton.me/business/blog/business-resilience</link><guid isPermaLink="true">https://proton.me/business/blog/business-resilience</guid><description>Your board wants a business resilience strategy. Here&apos;s what that means, with a four-pillar framework, and a plan to build resilience fast. </description><pubDate>Fri, 31 Jul 2026 16:51:21 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Cyberattacks, &lt;a href=&quot;https://proton.me/business/blog/supply-chain-attack&quot;&gt;supply chain failures&lt;/a&gt;, and geopolitical shocks shake otherwise stable businesses every year. How your business responds to the unexpected is what will make it last.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A comprehensive business resilience strategy can see you through disruption, help you recover faster, and adapt to whatever comes next.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This article offers:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;A clear definition of business resilience and what threatens it&lt;/li&gt;



&lt;li&gt;A business resilience framework you can take to your board&lt;/li&gt;



&lt;li&gt;A business resilience strategy you can use to maximize your resilience starting today&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is business resilience? &lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Business resilience is your organization’s ability to anticipate, withstand, recover from, and adapt to disruption. It protects not just your operations, but your finances, your people, and your reputation.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Businesses today face a range of potential disruptions, including:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Cyberattacks:&lt;/strong&gt; Proton’s SMB Cybersecurity Report 2026 found that &lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;&lt;u&gt;nearly 1 in 4 SMBs&lt;/u&gt;&lt;/a&gt; were hit by cyberattacks in the previous 12 months&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Infrastructure outages: &lt;/strong&gt;Many businesses now rely on major cloud infrastructure providers to support their critical business tools. When those infrastructures go down (as in the &lt;a href=&quot;https://proton.me/business/blog/aws-outage&quot;&gt;2025 AWS outage&lt;/a&gt;), thousands of businesses feel the impact, particularly those without resilience&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Supply-chain disruptions:&lt;/strong&gt; We saw the consequences of this risk at its height during COVID, and the lifting of lockdowns hasn’t eliminated it: A 2024 report found that &lt;a href=&quot;https://www.thebci.org/resource/bci-supply-chain-resilience-report-2024.html&quot;&gt;&lt;u&gt;nearly 80% of organizations’ supply chains had been disrupted&lt;/u&gt;&lt;/a&gt; in the last 12 months&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Market and geopolitical shocks: &lt;/strong&gt;In Q4 2024, only 8.3% of CFOs named trade and tariffs as a top concern. By Q1 2025, &lt;a href=&quot;https://www.richmondfed.org/publications/research/economic_brief/2025/eb_25-12&quot;&gt;&lt;u&gt;that share had more than tripled to 30.5%&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The evolution of technology and work:&lt;/strong&gt; The World Economic Forum predicts AI will &lt;a href=&quot;https://www.weforum.org/publications/the-future-of-jobs-report-2025/digest/&quot;&gt;&lt;u&gt;displace 92 million jobs by 2030&lt;/u&gt;&lt;/a&gt;, and create 170 million new ones&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why is business resilience important?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The most resilient businesses are able to:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Anticipate disruption.&lt;/strong&gt; Rather than waiting for a crisis to expose their &lt;a href=&quot;https://proton.me/business/blog/vulnerability&quot;&gt;vulnerabilities&lt;/a&gt;, they identify risks in advance.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Withstand disruption.&lt;/strong&gt; They can take the shock of it, while it&amp;#8217;s happening, without catastrophic failure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Recover from disruption.&lt;/strong&gt; Resilient businesses minimize costs by rapidly getting back to operational normality.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Adapt to disruption.&lt;/strong&gt; Returning to the status quo means carrying the same vulnerabilities. Resilient businesses update their operations, strategy, and business model in response to what happens.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Business resilience vs. disaster recovery vs. business continuity&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Disaster recovery and business continuity are components of business resilience, covering what happens &lt;strong&gt;during&lt;/strong&gt; and &lt;strong&gt;immediately&lt;/strong&gt; &lt;strong&gt;after&lt;/strong&gt; disruption.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Disaster recovery&lt;/strong&gt; is about restoring IT infrastructure and operations in the immediate aftermath of a disruption. If a ransomware attack takes your file servers offline, for example, disaster recovery is your IT team rebuilding the servers and restoring data from &lt;a href=&quot;https://proton.me/business/drive/cloud-backup-small-business&quot;&gt;cloud backup&lt;/a&gt; until the system works again.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Business continuity&lt;/strong&gt; is about keeping your business functionally operational while disaster recovery is in progress. That includes your leadership team deciding how to respond, this decision reaching staff, customers, and possibly regulators, and the practical workarounds that keep things running while your systems are down: phone and paper processes, deadlines still being hit, invoices still going out.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Disaster recovery is about how you recover from disruption; business continuity is about how you withstand it while recovery is underway. &lt;strong&gt;Business resilience &lt;/strong&gt;is the wider capacity that covers both — plus what happens either side of this: your ability to anticipate a disruption and recover quicker as a result, and your ability to adapt afterwards so the same attack doesn&amp;#8217;t catch you out a second time.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A four pillar business resilience framework&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before you build a business resilience strategy, you need to know what it should cover. This four-pillar framework reflects where disruption actually hits a business.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Measure your business against these four pillars to understand how resilient you are, then use the strategy below to close the gaps you find.&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;br&gt;&lt;strong&gt;Example scenarios&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Real-world cases&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Operational resilience&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Can you keep critical business functions running?&lt;/td&gt;&lt;td&gt;A supplier fails to deliver.&lt;br&gt;A cyberattack locks your team out of critical systems.&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://www.bloomberg.com/news/articles/2025-05-21/marks-spencer-says-cyber-attack-to-cost-business-300-million&quot;&gt;&lt;u&gt;M&amp;amp;S&amp;#8217;s 2025 ransomware attack&lt;/u&gt;&lt;/a&gt; knocked out the British retailer&amp;#8217;s online ordering for 46 days, wiping an estimated £300 million off annual profit.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Financial resilience&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Can you absorb a disruption’s economic impact without threatening your long-term viability?&lt;/td&gt;&lt;td&gt;A major client defaults during a market downturn.&lt;br&gt;A shock to supply drives material costs up sharply.&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://www.autonews.com/general-motors/an-gm-guidance-0501/&quot;&gt;&lt;u&gt;General Motors cut its 2025 profit guidance&lt;/u&gt;&lt;/a&gt; after estimating tariffs would add $4–5 billion in costs it hadn&amp;#8217;t priced into its original forecast.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;People resilience&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Can you keep the right people available, safe, and able to work through a disruption?&amp;nbsp;&lt;/td&gt;&lt;td&gt;Your CFO resigns mid-crisis.&lt;br&gt;A function is automated faster than your workforce was prepared for.&lt;/td&gt;&lt;td&gt;In 2022, staffing and scheduling failures forced Southwest Airlines to cancel 16,700 flights. &lt;a href=&quot;https://www.transportation.gov/briefing-room/dot-penalizes-southwest-airlines-140-million-2022-holiday-meltdown&quot;&gt;The Department of Transportation fined them&lt;u&gt; a record $140 million&lt;/u&gt;.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Reputational resilience&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Can you protect and recover stakeholder trust during and after a disruption?&lt;/td&gt;&lt;td&gt;A &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;data breach&lt;/a&gt; exposes client records.&lt;br&gt;A supplier&amp;#8217;s practices attract negative coverage that reflects on your brand.&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;TikTok had assured regulators that EU user data wasn&amp;#8217;t stored in China, then admitted in 2025 that some had been. This drew a &lt;a href=&quot;https://www.dataprotection.ie/en/news-media/latest-news/irish-data-protection-commission-fines-tiktok-eu530-million-and-orders-corrective-measures-following&quot;&gt;&lt;u&gt;€530 million GDPR fine&lt;/u&gt;&lt;/a&gt; (one of the largest on record) and compounded TikTok’s global trust problem.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to build a business resilience strategy&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Now you know what your strategy needs to cover. This is where business resilience planning starts.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. Conduct a risk and dependency audit / assessment&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before you do anything else, you need to audit your exposure across all four pillars.&amp;nbsp;&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Operational: &lt;/strong&gt;Surface infrastructure and vendor dependencies. Where are you single-sourced, and what comms channels depend on cloud infrastructure that could go down?&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Financial: &lt;/strong&gt;Review insurance coverage against your actual risk exposure. Stress-test financials against plausible disruptions before they happen.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;People: &lt;/strong&gt;Identify single-point-of-failure roles and thin coverage. Where does the business depend on one person, or one team with no backup?&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Reputational: &lt;/strong&gt;Assess your current crisis-response readiness. If a breach or scandal broke tomorrow, do you have a communications plan and a spokesperson ready?&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. Define and test your business resilience plan&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Using your findings, you now need to put together a &lt;strong&gt;business resilience plan &lt;/strong&gt;(sometimes called a &lt;strong&gt;business resilience policy&lt;/strong&gt;).&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Document decision-makers: &lt;/strong&gt;Establish who has the authority to declare a crisis, reallocate a budget, or approve a public statement.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Identify priority processes: &lt;/strong&gt;Which functions can’t go down, and which can wait if your resources are stretched?&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Map out provisional measures to maintain operations:&lt;/strong&gt; offsite backups with automated failover, pre-arranged credit facilities so liquidity isn&amp;#8217;t a scramble, clear employee safety protocols, and pre-approved messaging with escalation protocols ready before a crisis breaks.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Make sure the right tech is in place to execute the plan: &lt;/strong&gt;backup communication channels, private and confidential remote access and &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt;, and a flexible working infrastructure. &lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Test the plan before you need to execute it: &lt;/strong&gt;&amp;#8220;War-game&amp;#8221; scenarios regularly to expose weaknesses and let the team learn in a safe environment.&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. Assign an owner to each resilience pillar&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Resilience fails when it&amp;#8217;s treated as one function&amp;#8217;s job (usually IT’s) alone. Each resilience pillar needs an owner: accountable for its exposure, responsible for keeping the audit current and the plan&amp;#8217;s provisions in place, and ready to act if disruption strikes.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Map named owners to named pillars: your COO for operational, your CFO for financial, your CHRO for people, and legal/comms for reputational.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How Proton supports business resilience&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Workspace is a privacy-first business suite. It increases your operational and reputational resilience by:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Protecting your data:&lt;/strong&gt; Proton Workspace is built on an &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;&lt;u&gt;end-to-end encrypted&lt;/u&gt;&lt;/a&gt;, &lt;a href=&quot;https://proton.me/blog/zero-knowledge-cloud-storage&quot;&gt;&lt;u&gt;zero-knowledge&lt;/u&gt;&lt;/a&gt; infrastructure, which means not even Proton can access your data. It’s additionally protected by some of the world’s &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;&lt;u&gt;most stringent privacy laws&lt;/u&gt;&lt;/a&gt;. Plus, Proton Workspace includes a business p&lt;a href=&quot;https://proton.me/business/pass&quot;&gt;&lt;u&gt;assword manager&lt;/u&gt;&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/vpn&quot;&gt;&lt;u&gt;VPN&lt;/u&gt;&lt;/a&gt; to further strengthen data protection.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Helping you recover: &lt;/strong&gt;In the event of a major cloud infrastructure outage, &lt;a href=&quot;https://proton.me/blog/sustaining-mission-over-time&quot;&gt;&lt;u&gt;Proton’s independent infrastructure&lt;/u&gt;&lt;/a&gt; stays up and your teams can continue to email, use cloud storage, collaborate on documents, and meet via video. You can set up a &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;&lt;u&gt;business continuity plan&lt;/u&gt;&lt;/a&gt; with Proton so you’re ready to quickly switch over when disruption hits&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even the best business resilience strategy depends on a solid technology foundation to succeed. Proton Workspace is built to strengthen that foundation.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Learn more about &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;business continuity&lt;/a&gt; with Proton.&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>Document management systems explained: features, types, and platforms</title><link>https://proton.me/business/blog/document-management-system</link><guid isPermaLink="true">https://proton.me/business/blog/document-management-system</guid><description>Document management systems store your most sensitive data. Here&apos;s what to look for — and why most platforms fall short on security.</description><pubDate>Fri, 31 Jul 2026 16:36:16 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Document management system (DMS) are the software equivalent of an office&amp;#8217;s filing cabinet. It&amp;#8217;s where your business stores, categorizes, organizes, or secures classified documentation. You probably already have one in place.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It could be &lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt;, SharePoint, or an internal &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt; system you created yourself. You could be using it to collect contracts, invoices, bank statements, employee records, or product brochure. But how you manage these documents could also be the reason you face astronomical financial losses, industry penalties, and regulatory action.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Why? Because DMS systems were built to keep your documents in order, not protect the data from the threats that have emerged in recent years.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s what secure document management actually looks like, and why the system you&amp;#8217;re using right now may not be providing it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is a document management system?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A document management system is any software used as a central repository to store, track, and distribute digital documents. With the right storage practices, a DMS can remove the need for physical paperwork and keeps hard-to-track archived files within reach.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A DMS can help you:&lt;strong&gt;:&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Store and organize files: In a single location where every document that was once scattered in folders, email attachments and physical files is accessible and searchable in one search, regardless of who created it or when.&lt;/li&gt;



&lt;li&gt;Track who&amp;#8217;s seen or contributed to a file&lt;strong&gt;: &lt;/strong&gt;You can see a structured view of your entire sign-off process to double-check modifications to the document. With permissions and &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt; settings you can also limit internal exposure and keep sensitive records contained.&lt;/li&gt;



&lt;li&gt;Maintain a defensible audit trail: Pre-defined rules can help you archive or delete documents after defined periods, to help meet compliance standards. You can also track every view, edit, or download to stay accountable to regulators.&lt;/li&gt;



&lt;li&gt;Automate approval workflows&lt;strong&gt;: &lt;/strong&gt;Notifications and alerts can route documents through stages of approval requests, sign-off stages and review cycles, so you don&amp;#8217;t have to chase people down in person.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The three most common document management systems — and why they don&amp;#8217;t protect your data&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The three platforms below were built for collaboration and scale, and they deliver both. But businesses should want more from their DMS.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;Data breaches&lt;/a&gt; happen every day and SMBs are particularly at risk. As many as &lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;&lt;u&gt;25% of SMBs&lt;/u&gt;&lt;/a&gt; suffered a breach or cyberattack last year. And even if your business isn’t breached, you could fall out of compliance with regulations such as GDPR, HIPAA, or fail audits against standards like ISO 27001 because they mandate proactive data protection. The vulnerability itself is grounds for penalization.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With security in mind, we&amp;#8217;re analyzing the platforms many IT managers and CEOs choose by default.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Microsoft SharePoint&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Why it&amp;#8217;s the office default:&lt;/strong&gt; SharePoint is deeply embedded in the Microsoft 365 ecosystem, which makes it the path of least resistance for businesses already running Outlook, Teams, or Excel. It handles large volumes of documents, supports granular permission settings, and integrates with the rest of the Microsoft stack without additional configuration. For teams that live in Microsoft 365, it works.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;How it introduces security risks:&lt;/strong&gt; SharePoint&amp;#8217;s vulnerabilities are largely structural. It operates under Microsoft&amp;#8217;s broad data access model — meaning Microsoft retains the ability to access your stored content for purposes including service delivery, compliance, and law enforcement requests. Encryption is applied, but Microsoft holds the keys. Your documents are protected from outside attackers, but not from the platform itself. SharePoint also has a history of misconfiguration issues: overly permissive sharing settings are easy to set and easy to forget, and internal data sprawl — documents shared across teams with no clear ownership or expiry — is a common compliance failure mode.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;What to look for instead:&lt;/strong&gt; A system where the vendor cannot access your content by design — not by policy. Look for end-to-end encryption with keys you control, clear data residency commitments, and sharing settings that default to least privilege rather than open access.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Google Drive&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Why it&amp;#8217;s the office default:&lt;/strong&gt;&amp;nbsp;&lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt; is the default choice for businesses already in the Google ecosystem — &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;Gmail&lt;/a&gt;, &lt;a href=&quot;https://proton.me/drive/google-docs-alternative&quot;&gt;Docs&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/drive/google-sheets-alternative&quot;&gt;Sheets&lt;/a&gt;, Meet. It&amp;#8217;s fast to set up, requires no IT overhead, and its real-time collaboration features are genuinely best-in-class. For small teams that need to move quickly, it gets the job done.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;How it introduces security risks:&lt;/strong&gt;&amp;nbsp;Google&amp;#8217;s business model is built on data. Even under a &lt;a href=&quot;https://proton.me/business/google-workspace-alternative&quot;&gt;Google Workspace&lt;/a&gt; agreement, Google retains broad rights to process your content — for service improvement, ad infrastructure, and compliance with legal requests. Like SharePoint, encryption is standard, but Google holds the keys. There&amp;#8217;s also the question of sprawl: Drive makes it frictionless to share documents externally, which means sensitive files can quietly end up accessible to anyone with a link, often without the original owner realizing it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;What to look for instead:&lt;/strong&gt;&amp;nbsp;A platform that treats your documents as yours — not as data to be processed. &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;Zero-access encryption&lt;/a&gt;, where the vendor cannot read your files under any circumstances, and external sharing controls that require deliberate action rather than a single click.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Dropbox&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Why it&amp;#8217;s the office default:&lt;/strong&gt;&amp;nbsp;&lt;a href=&quot;https://proton.me/drive/dropbox-alternative&quot;&gt;Dropbox&lt;/a&gt; built its reputation on simplicity. It syncs files instantly across devices, plays well with third-party tools, and has a low learning curve that makes it popular with smaller teams and freelancers. For straightforward file storage and sharing, it&amp;#8217;s hard to fault on usability.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;How it introduces security risks:&lt;/strong&gt;&amp;nbsp;Dropbox encrypts files in transit and at rest — but, again, holds the encryption keys itself. That means Dropbox employees, and by extension government requests, can access your content. It also has a notable breach history: a 2012 incident exposed 68 million user credentials, and the platform has faced criticism for how long it took to disclose the scale of that breach. For businesses handling regulated data, Dropbox&amp;#8217;s compliance coverage is also thinner than enterprise alternatives, which can create gaps against GDPR or HIPAA requirements.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;What to look for instead:&lt;/strong&gt;&amp;nbsp;Storage built for &lt;a href=&quot;https://proton.me/business/blog/blog-cybersecurity-compliance&quot;&gt;cybersecurity compliance&lt;/a&gt; from the ground up — with end-to-end encryption, documented data residency, and a vendor whose architecture makes access to your files technically impossible, not just contractually prohibited.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What secure document management actually looks like&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The three platforms above aren&amp;#8217;t insecure by accident. They were built for collaboration and scale, and they deliver both. Security wasn&amp;#8217;t the problem those providers were solving for.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If data security is a priority for your business, these are the features that separate a genuinely secure DMS from one that just looks the part.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Zero-knowledge encryption:&lt;/strong&gt; Your DMS should encrypt your documents before they leave your device. That means the vendor never has access to your content — not for service delivery, not in response to legal requests. If the vendor holds the encryption keys, you&amp;#8217;re trusting their policy. If they can&amp;#8217;t hold them by design, you don&amp;#8217;t have to.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Open-source architecture and independent audits:&lt;/strong&gt; Security claims are easy to make. Look for vendors whose architecture is open source — meaning anyone can inspect it — and whose security posture is verified by independent third-party audits, not just internal assertions.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Recognized compliance certifications:&lt;/strong&gt; ISO 27001, SOC 2 Type II, and HIPAA certification aren&amp;#8217;t just checkboxes. They&amp;#8217;re evidence that a vendor&amp;#8217;s security controls have been tested against an external standard. If you operate in a regulated industry, these aren&amp;#8217;t optional.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Jurisdiction and data residency:&lt;/strong&gt; Where your vendor is headquartered determines which governments can compel access to your data. US-based platforms fall under the CLOUD Act. Make sure you know whose laws govern your documents — and whether that&amp;#8217;s acceptable for your business.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Privacy-safe AI:&lt;/strong&gt; If your DMS includes AI features, confirm that the AI operates without visibility into your document contents — and that your data isn&amp;#8217;t used to train the underlying model.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Choosing a DMS that actually protects your data&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The document management system you pick determines who can see your business&amp;#8217;s most sensitive files for as long as you retain them. Proton Workspace pairs secure document storage with team collaboration tools, so your business gets the collaboration features you need without handing a vendor the keys to your data.&lt;/p&gt;
</content:encoded><category>For business</category><author>Greg Ng</author></item><item><title>How to create a contingency plan that protects your business</title><link>https://proton.me/business/blog/contingency-plan</link><guid isPermaLink="true">https://proton.me/business/blog/contingency-plan</guid><description>A step-by-step guide to building a contingency plan. Learn about the key components, common mistakes to avoid, and how secure tools help.</description><pubDate>Fri, 31 Jul 2026 16:21:39 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even the best project plan can be disrupted by events you didn’t see coming, such as a key team member leaving, a vendor failing, or a platform changing its policies. You can’t control every risk, but you can control how prepared your business is when something goes wrong.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A contingency plan is your documented fallback. It outlines who does what, when, and how if a specific risk happens. Instead of scrambling to make decisions in the moment, your team has a clear plan to follow so work can keep moving.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In this guide, we’ll cover why contingency plans matter, what every plan should include, how to build one step by step, and the mistakes that can undermine them.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why contingency plans matter for businesses &lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Let’s think about fire evacuation plans for a moment. Every building, including your office and home, has one, and on a normal day, it just blends into the background. But if a fire does break out, the difference between a team that knows exactly where to go and one that doesn&amp;#8217;t is significant. Contingency plans work the same way. They don’t prevent the problem, but they determine how well you handle it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Consider what happens during a &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;data breach&lt;/a&gt;. It&amp;#8217;s going to cause damage regardless, but without a contingency plan, your team burns critical time figuring out who&amp;#8217;s leading the response, how to notify affected clients, and what systems to prioritize. That delay is what turns a serious incident into a prolonged crisis, because every hour without a coordinated response gives the damage more room to escalate.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The same applies to less dramatic but still disruptive risks, like an &lt;a href=&quot;https://proton.me/business/blog/microsoft365-copilot-flex-routing&quot;&gt;unexpected policy change&lt;/a&gt; on a key platform, which could force your team to rework a deliverable from scratch to stay compliant. Contingency plans don&amp;#8217;t eliminate these risks. But they give your team a clear path forward when a risk materializes, enabling faster recovery, less financial exposure, and stronger client confidence.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Step-by-step guide to create a contingency plan &lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A strong contingency plan has five core components. Here&amp;#8217;s how to work through each one.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 1: Identify and prioritize your risks&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Start by mapping the specific risks that could disrupt your projects or operations, such as cybersecurity incidents, vendor failures, or regulatory shifts. Assess what each would mean for your business so you can prioritize which risks require the most detailed contingency plans and which your business could absorb with minimal disruption.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 2: Set your trigger conditions&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Every contingency plan needs a clear activation point. Define what specific event or threshold triggers the plan. For example, if your primary cloud provider experiences more than 4 hours of downtime, you switch to the backup environment. Without defined triggers, your team won’t know when to act, and hesitation increases costs.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 3: Document your response actions&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Lay out the specific steps your team will follow once the plan is triggered. Keep these concrete and sequential: who does what, in what order, and with what resources. Avoid vague instructions like &lt;strong&gt;assess the situation&lt;/strong&gt;. Keep instructions clear and specific so your team acts as intended.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 4: Assign roles and establish communication protocols&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define who is responsible for each part of the response, who has decision-making authority, and who needs to be kept informed. Then, define your communication protocol — which channels you&amp;#8217;ll use, how quickly stakeholders need to be notified, and who owns external communications. Good communication keeps the plan in motion and maintains trust with your clients.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 5: Test, train, and maintain&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Run your team through the contingency plan with tabletop exercises or simulations so the response feels practiced and not improvised. Train new team members as they join, and review your plans regularly to keep them relevant.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to avoid common contingency plan mistakes&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To keep common mistakes from weakening your response during critical moments, build your plan around these best practices:&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Tailor plans to specific risks&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A data breach and a &lt;a href=&quot;https://proton.me/business/blog/supply-chain-attack&quot;&gt;supply chain attack&lt;/a&gt; require completely different responses. Tailor each plan to a specific risk scenario so your team has clear, relevant guidance when they need it.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Make communication part of the plan&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A plan can have perfect response actions and still fail if no one knows who to notify, when, or how. Clear communication helps keep the response coordinated during disruptions.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Keep your plans updated&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A plan written six months ago might reference tools you&amp;#8217;ve replaced or team members who&amp;#8217;ve moved on. Review regularly and update after any major operational change.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Plan for worst-case scenarios&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Plan for realistic worst-case scenarios, not the optimistic version. Your contingency plan exists for when things don&amp;#8217;t resolve quickly or easily.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Use secure tools for better contingency management&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data breaches, unauthorized access, and compromised communications are just some of the notable risks businesses plan contingencies for. Risks arise from vulnerabilities in your email provider’s security model, incomplete encryption on cloud storage, and weak or reused passwords.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Choosing the right workspace matters.&lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt; End-to-end encryption&lt;/a&gt; ensures that even if a breach occurs, the data remains unreadable to anyone who isn&amp;#8217;t authorized. Fewer exploitable vulnerabilities mean fewer incidents that trigger your contingency plans in the first place.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Workspace gives your team encrypted &lt;a href=&quot;https://proton.me/business&quot;&gt;collaboration tools&lt;/a&gt; for email, calendar, cloud storage, documents, video conferencing, and password management, with end-to-end and &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;zero-access encryption&lt;/a&gt; protecting sensitive business data.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton is &lt;a href=&quot;https://proton.me/business/iso-27001-certification&quot;&gt;ISO 27001 certified&lt;/a&gt;, &lt;a href=&quot;https://proton.me/blog/soc-2&quot;&gt;SOC 2 Type II audited&lt;/a&gt;, and supports compliance with frameworks such as &lt;a href=&quot;https://proton.me/business/gdpr&quot;&gt;GDPR&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/healthcare&quot;&gt;HIPAA&lt;/a&gt;, and &lt;a href=&quot;https://proton.me/business/drive/security&quot;&gt;CCPA&lt;/a&gt;. Based in Switzerland, Proton protects your data under strong Swiss and European privacy laws, helping keep it outside the reach of US surveillance and foreign access requests.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;None of this replaces the need for contingency planning. But the fewer fires your team has to fight, the more those plans stay where they belong — in the drawer, ready but unused.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Frequently asked questions about contingency plans&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;What&amp;#8217;s the difference between a contingency plan and a mitigation plan?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A contingency plan is reactive, outlining what you need to do after a specific risk occurs. Mitigation plans focus on reducing the likelihood of that risk happening in the first place, making them proactive. Businesses generally need both to ensure &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;business continuity&lt;/a&gt;: mitigation plans to minimize exposure, and contingency plans for when something gets through despite those efforts.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;How often should you update a contingency plan?&amp;nbsp;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Review your contingency plan whenever a major change affects your team, tools, vendors, or operations. Plan a review cadence outside of these changes, such as at the start of each quarter, to catch any instructions that might no longer serve your business.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;What are some examples of contingency plans?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some common scenarios businesses build contingency plans for include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Cybersecurity incidents: Who leads the response, how affected clients are notified, and how systems are isolated and restored.&lt;/li&gt;



&lt;li&gt;Key personnel departure: How responsibilities are redistributed, where critical knowledge is documented, and how handovers are managed. To make the offboarding process simpler to manage and more transparent, download our free &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding checklist templates&lt;/a&gt;.&lt;/li&gt;



&lt;li&gt;Vendor or supplier failure: Which backup vendors are pre-approved, how to adjust project timelines, and how to communicate delays to clients.&lt;/li&gt;



&lt;li&gt;Regulatory or policy changes: How to assess the impact on current projects, who&amp;#8217;s responsible for compliance adjustments, and what client communications are needed.&lt;/li&gt;
&lt;/ul&gt;
</content:encoded><category>For business</category><author>Greg Ng</author></item><item><title>What are email protocols? </title><link>https://proton.me/business/blog/email-protocols</link><guid isPermaLink="true">https://proton.me/business/blog/email-protocols</guid><description>Learn how email security protocols impact your organization&apos;s deliverability and which one is the most secure.</description><pubDate>Fri, 31 Jul 2026 16:13:38 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;We send and receive emails just about every day, rarely thinking about how it works or whether the process is secure. However, choosing the wrong email protocol can cause problems ranging from limited storage space on your computer to &lt;a href=&quot;https://proton.me/business/blog/data-breach-observatory-2026&quot;&gt;data breaches&lt;/a&gt;, loss of customer trust, or blocked domains.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This guide outlines how email protocols work, explains the critical difference between functionality and security, and provides a checklist for SMBs.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://docs.google.com/document/d/1G2AoDgJV4fxcwSG6jmg4JwI1Ss0oajO2kIp81LZcbnc/edit?tab=t.0#heading=h.4euw15vw3r6z&quot;&gt;Email glossary&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://docs.google.com/document/d/1G2AoDgJV4fxcwSG6jmg4JwI1Ss0oajO2kIp81LZcbnc/edit?tab=t.0#heading=h.gbiz48h5gttr&quot;&gt;Email protocols explained&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://docs.google.com/document/d/1G2AoDgJV4fxcwSG6jmg4JwI1Ss0oajO2kIp81LZcbnc/edit?tab=t.0#heading=h.o0i6ovaiubaz&quot;&gt;Email security protocols&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://docs.google.com/document/d/1G2AoDgJV4fxcwSG6jmg4JwI1Ss0oajO2kIp81LZcbnc/edit?tab=t.0#heading=h.11jjjmeq00nq&quot;&gt;How protocols impact email marketing success&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://docs.google.com/document/d/1G2AoDgJV4fxcwSG6jmg4JwI1Ss0oajO2kIp81LZcbnc/edit?tab=t.0#heading=h.mxrflc7p1za5&quot;&gt;An email protocol security checklist for SMBs&lt;/a&gt;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A quick email glossary&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The terminology around emails all sounds very similar, but the distinctions are important. Here’s what we’ll be discussing in this guide:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Email client: &lt;/strong&gt;The software application you use to read, write, and manage your emails, such as Outlook, Apple Mail, and &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;Proton Mail&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Email protocol:&lt;/strong&gt; The set of rules that governs how emails are transmitted, received, and stored across the internet. Core protocols like &lt;strong&gt;SMTP&lt;/strong&gt;, &lt;strong&gt;IMAP&lt;/strong&gt;, and &lt;strong&gt;POP3&lt;/strong&gt; handle the mechanical movement of messages between servers and clients.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Email security protocol:&lt;/strong&gt; A protective layer of standards that sits on top of core email protocols to ensure privacy and data integrity. These include encryption methods like &lt;strong&gt;TLS&lt;/strong&gt; (for transit) and &lt;strong&gt;S/MIME&lt;/strong&gt; or &lt;strong&gt;PGP&lt;/strong&gt; (for end-to-end content), as well as mechanisms to detect malware or spam.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/mail/email-authentication&quot;&gt;&lt;strong&gt;Email authentication&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;:&lt;/strong&gt; The process of verifying that an email truly originates from the domain it claims to represent. It relies on the trio of SPF, DKIM, and DMARC to instruct receiving servers on whether to trust, flag, or reject a message, preventing spoofing and &lt;a href=&quot;https://proton.me/business/mail/phishing-email&quot;&gt;phishing&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Email marketing tool:&lt;/strong&gt; A platform designed to create, send, and track bulk email campaigns, such as Mailchimp, HubSpot, or SendGrid. These tools utilize SMTP to deliver messages and depend heavily on proper email authentication to ensure high deliverability rates.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Email protocols explained&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. Simple Mail Transfer Protocol (SMTP)&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;What it is:&lt;/strong&gt; The standard protocol for &lt;strong&gt;sending&lt;/strong&gt; emails. SMTP handles the transfer from your email client to the server, and between servers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;How it works:&lt;/strong&gt; Your email client connects to an &lt;strong&gt;SMTP server&lt;/strong&gt;, authenticates, and hands off the message. The server then routes it to the recipient&amp;#8217;s domain. It’s not possible to send an email without SMTP.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Security note:&lt;/strong&gt; Standard SMTP sends data in plain text. Without encryption (STARTTLS), sensitive business data can be intercepted.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. Internet Message Access Protocol (IMAP)&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;What it is:&lt;/strong&gt; The modern standard for &lt;strong&gt;receiving and managing&lt;/strong&gt; emails. IMAP keeps messages on the server and syncs them across all your devices.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;How it works:&lt;/strong&gt; When you check your email on your phone, laptop, or tablet, IMAP fetches the latest status from the central server. Because the email is stored on the server, if a laptop is lost, the email history remains safe. Similarly, deleting an email on one device deletes it everywhere.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Security note:&lt;/strong&gt; Because data resides on the server, strong authentication and encryption are non-negotiable.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. Post Office Protocol v3 (POP3)&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;What it is:&lt;/strong&gt; An older protocol that downloads emails to a single device and typically deletes them from the server.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;How it works:&lt;/strong&gt; The email client connects, downloads all new messages, and disconnects. The server is left empty. This protocol is rarely recommended for modern businesses; it creates data silos (if your device crashes, your email history is gone), and because all emails are downloaded to your device, it can create storage issues on your computer.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Security note:&lt;/strong&gt; Lack of server-side redundancy makes it vulnerable to hardware failure and theft. This high-risk protocol is not recommended, especially for businesses.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;&lt;em&gt;Read more:&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; &lt;/em&gt;&lt;a href=&quot;https://proton.me/blog/smtp-imap-pop3&quot;&gt;&lt;em&gt;What are SMTP, IMAP, and POP3?&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;SMTP and IMAP serve opposite purposes, but &lt;strong&gt;a functional email setup requires both protocols&lt;/strong&gt;. SMTP sends messages out, while IMAP retrieves incoming messages. Most modern email providers hide this complexity, and the software automatically configures both the SMTP and IMAP settings in the background. You rarely have to think about which one you’re using—the software simply handles both simultaneously.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Email security protocols&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Email protocols move and store messages, but email security protocols are the systems that keep emails, senders, and recipients safe. They fall into two categories: those that encrypt data to keep it private, and those that authenticate senders to prove identity.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Encryption protocols&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Transport Layer Security (TLS)&lt;/strong&gt;: Encrypts the connection between mail servers as emails travel across the internet. Most modern email providers enforce TLS by default.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;STARTTLS&lt;/strong&gt;: A command that upgrades an existing unencrypted connection to a secure TLS connection. If the other side doesn&amp;#8217;t support it, the connection falls back to plain text, which is a potential vulnerability.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Secure/Multipurpose Internet Mail Extensions (S/MIME)&lt;/strong&gt;: Provides &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end encryption&lt;/a&gt; and digital signatures at the message level. It requires both sender and recipient to exchange digital certificates, which makes it more common in enterprise environments.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Pretty Good Privacy (PGP) / GNU Privacy Guard (GPG)&lt;/strong&gt;: Another method of end-to-end encryption and digital signing that offers strong privacy. Instead of certificates, PGP uses a web-of-trust model where users exchange public keys directly.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Authentication protocols&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Sender Policy Framework (SPF)&lt;/strong&gt;: Lets a domain owner publish a list of authorized IP addresses that are permitted to send emails on behalf of that domain. When a receiving server gets a message, it checks the sender&amp;#8217;s IP against this list. If the IP isn&amp;#8217;t on it, the email fails SPF.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;DomainKeys Identified Mail (DKIM)&lt;/strong&gt;: Adds a cryptographic signature to each outgoing email, tied to the sending domain. The receiving server verifies this signature against a public key published in the sender&amp;#8217;s DNS records.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Domain-based Message Authentication, Reporting, and Conformance (DMARC)&lt;/strong&gt;: Ties SPF and DKIM together and gives domain owners control over what happens when authentication fails. Through a DMARC policy, you can instruct receiving servers to accept, quarantine, or reject failed messages, and you receive reports showing who is attempting to send unauthorized emails from your domain.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Why this matters for SMBs&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Without security protocols layered on top of your core protocols, you’re at risk of:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Spoofing:&lt;/strong&gt; Attackers can easily impersonate your domain to scam your customers&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Interception:&lt;/strong&gt; Unencrypted traffic allows hackers to read emails in transit&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Blacklisting:&lt;/strong&gt; Poor authentication leads to your domain being flagged as spam&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Together, these email security protocols create a layered defense—&lt;a href=&quot;https://proton.me/learn/encryption&quot;&gt;encryption&lt;/a&gt; keeps prying eyes off the content, and authentication ensures the email actually came from who it claims to be from.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How protocols impact email marketing success&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For SMBs, email marketing introduces a wrinkle: you may not be the one sending the emails. Whether you use a marketing tool or run campaigns yourself determines what you&amp;#8217;re responsible for securing.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;If you&amp;#8217;re using a marketing tool&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Platforms like Mailchimp, HubSpot, and SendGrid handle the sending infrastructure, including SMTP servers and encryption. But they can&amp;#8217;t authenticate your domain on your behalf. That part is yours.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When a marketing tool sends an email using your domain, for example, newsletter@yourcompany.com, the recipient&amp;#8217;s server still checks your domain&amp;#8217;s authentication records:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;SPF&lt;/strong&gt;: Must include the marketing tool&amp;#8217;s sending IPs so the recipient&amp;#8217;s server knows they&amp;#8217;re authorized to send on your behalf.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;DKIM&lt;/strong&gt;: The marketing tool signs the email with a cryptographic key, but you must publish the corresponding public key in your DNS records so the recipient can verify it.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;DMARC&lt;/strong&gt;: Tells receiving servers what to do if SPF or DKIM fails, and sends you reports so you can monitor for unauthorized use of your domain.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most reputable marketing tools walk you through this DNS setup during onboarding. If yours doesn&amp;#8217;t, that&amp;#8217;s a red flag.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;If you&amp;#8217;re running your own campaign&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sending bulk emails from your own SMTP server puts the full responsibility on you. You need to:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Configure your SMTP server to use TLS/STARTTLS for encrypted transmission&lt;/li&gt;



&lt;li&gt;Set up SPF, DKIM, and DMARC records for your domain&lt;/li&gt;



&lt;li&gt;Monitor your sender reputation—shared or poorly managed SMTP servers are a common route to blocklisting&lt;/li&gt;



&lt;li&gt;Start with a low sending volume and increase it slowly over time to build trust with inbox providers&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This approach gives you more control but requires significantly more technical expertise and ongoing maintenance. For most SMBs, a reputable marketing tool is the safer and simpler path.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Data ownership and business continuity&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For an SMB, email isn&amp;#8217;t just communication; it&amp;#8217;s a record of transactions, agreements, and client relationships.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;The POP3 trap:&lt;/strong&gt; If your team uses POP3 and an employee&amp;#8217;s laptop crashes, you may lose years of correspondence permanently because the data was never saved on the server.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;The IMAP advantage:&lt;/strong&gt; By keeping emails on the server, you ensure that data survives hardware failures and employee turnover. It also allows administrators to archive and search communications for compliance audits.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even if POP3 feels cheaper or simpler, the risk of losing critical business data makes IMAP the safest option for a growing company.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;An email protocol security checklist for SMBs&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ready to secure your email infrastructure? Follow this step-by-step guide:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Audit your current setup:&lt;/strong&gt;
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Are you using &lt;strong&gt;TLS/STARTTLS&lt;/strong&gt; for all connections? (Check your provider settings).&lt;/li&gt;



&lt;li&gt;Are you still using POP3? If so, plan a migration to IMAP immediately.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Implement authentication records:&lt;/strong&gt;
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Log in to your &lt;a href=&quot;https://proton.me/business/blog/dns-security-for-business&quot;&gt;DNS&lt;/a&gt; provider.&lt;/li&gt;



&lt;li&gt;Add your &lt;strong&gt;SPF&lt;/strong&gt; record (include all authorized sending IPs).&lt;/li&gt;



&lt;li&gt;Generate and publish your &lt;strong&gt;DKIM&lt;/strong&gt; key.&lt;/li&gt;



&lt;li&gt;Set up a &lt;strong&gt;DMARC&lt;/strong&gt; policy (start with monitoring).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Secure your marketing stack:&lt;/strong&gt;
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Ensure your email marketing platform is configured to send via your &lt;a href=&quot;https://proton.me/business/mail/custom-email-domain&quot;&gt;custom email domain&lt;/a&gt;, not a generic subdomain.&lt;/li&gt;



&lt;li&gt;Verify that your domain passes all three authentication checks before sending bulk campaigns.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Test and monitor:&lt;/strong&gt;
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Send test emails to Gmail, Outlook, and Yahoo.&lt;/li&gt;



&lt;li&gt;View the email headers to confirm authentication passed.&lt;/li&gt;



&lt;li&gt;Subscribe to DMARC aggregate reports to monitor for unauthorized usage.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Don&amp;#8217;t wait for a breach or a blacklisting event to audit your email infrastructure. Start with the checklist above, and build a system that supports your business growth securely.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;em&gt;Need help implementing end-to-end encryption or securing your business email? Explore Proton’s &lt;/em&gt;&lt;a href=&quot;https://proton.me/business&quot;&gt;&lt;em&gt;business solutions&lt;/em&gt;&lt;/a&gt;&lt;em&gt; for enterprise-grade privacy and security.&lt;/em&gt;&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>How to attach an email to an email</title><link>https://proton.me/business/blog/how-to-attach-email-to-email</link><guid isPermaLink="true">https://proton.me/business/blog/how-to-attach-email-to-email</guid><description>Your comprehensive step-by-step guide on how to attach emails in Gmail, Outlook, and Proton Mail.</description><pubDate>Fri, 31 Jul 2026 16:09:32 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;When you forward an email, formatting can get messy, and metadata, such as timestamps and subject lines, are sometimes stripped out. If you’re forwarding a &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;business email&lt;/a&gt; as a verifiable record or want the recipient to see exactly what you received, attaching the email keeps the original message fully intact.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most email services attach emails as .eml files, which preserve original formatting and attachments. You can attach an email to an email in Gmail, Outlook, and Proton Mail.&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.google.com/document/d/1EsLZzwOL8dloKLtVOtia4raHZXgQx6kcxf0QpIHECKg/edit?tab=t.0#heading=h.xt0qv7nctvbq&quot;&gt;How to attach an email in Gmail&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;https://docs.google.com/document/d/1EsLZzwOL8dloKLtVOtia4raHZXgQx6kcxf0QpIHECKg/edit?tab=t.0#heading=h.u5x2hhwsojpm&quot;&gt;How to attach an email in Outlook&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;https://docs.google.com/document/d/1EsLZzwOL8dloKLtVOtia4raHZXgQx6kcxf0QpIHECKg/edit?tab=t.0#heading=h.wv2em1vcam3l&quot;&gt;How to attach an email in Proton Mail&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to attach an email to an email in Gmail&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Forward an email as an attachment&amp;nbsp;&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Select the checkbox next to the emails you want to forward as an attachment.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;More &lt;/strong&gt;(or the three vertical dots) and select &lt;strong&gt;Forward as attachment.&lt;/strong&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;Add your recipients, compose your message, and click &lt;strong&gt;Send.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can forward as many emails as attachments as you want, but if the total exceeds 25 MB, Gmail will attach them via a Google Drive link.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Find out more about &lt;a href=&quot;https://proton.me/business/blog/gmail-attachment-size-limit&quot;&gt;Gmail’s attachment size limits&lt;/a&gt; and how to send large files via email.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Download and attach an email&amp;nbsp;&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the email you want to send as an attachment.&lt;/li&gt;



&lt;li&gt;Click the three vertical dots in the email and select:&lt;br&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;740&quot; height=&quot;53&quot; src=&quot;blob:https://pme.protonblog.tech/7c3552d4-7b05-4f28-95fd-b63b02546191&quot;&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Download message: &lt;/strong&gt;To save the email as an .eml file.&lt;br&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;219&quot; height=&quot;464&quot; src=&quot;blob:https://pme.protonblog.tech/bcad66e0-5dda-42e1-8669-f920f50b220e&quot;&gt;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Print: &lt;/strong&gt;To save the email as a .pdf file.&lt;br&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;219&quot; height=&quot;464&quot; src=&quot;blob:https://pme.protonblog.tech/26f7e7be-e13b-4545-952b-8a18e66e8f56&quot;&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;ol start=&quot;3&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;In your new email, select &lt;strong&gt;Attach files &lt;/strong&gt;(the paperclip icon) to attach the downloaded email. You can also drag and drop a previously downloaded email directly into the message body.&lt;/li&gt;



&lt;li&gt;Add your recipients, compose your message, and click &lt;strong&gt;Send.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Note:&lt;/strong&gt; To ensure the email appears as the original when saving as .pdf, check that Headers and footers and Background graphics are selected. You can do this by selecting &lt;strong&gt;More settings&lt;/strong&gt; from the pop-up.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;381&quot; height=&quot;622&quot; src=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/07/image-27.png&quot; alt=&quot;&quot; class=&quot;wp-post-244509 wp-image-244511&quot; srcset=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/07/image-27.png 381w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-27-184x300.png 184w&quot; sizes=&quot;auto, (max-width: 381px) 100vw, 381px&quot; /&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to attach an email to an email in Outlook&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There are two versions of &lt;a href=&quot;https://proton.me/business/mail/outlook-alternative&quot;&gt;Outlook&lt;/a&gt;: New Outlook and Classic Outlook. The steps are broadly similar, with differences marked below.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Forward an email as an attachment&amp;nbsp;&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the email you want to forward as an attachment.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;More actions &lt;/strong&gt;(the three horizontal dots) → &lt;strong&gt;Other reply actions &lt;/strong&gt;→ &lt;strong&gt;Forward as attachment&lt;/strong&gt;.&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;A new email window opens with the email attached as an .eml or .msg file, depending on your Outlook version.&lt;/li&gt;



&lt;li&gt;Add your recipients, compose your message, and click &lt;strong&gt;Send.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Download and attach an email&amp;nbsp;&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the email you want to send as an attachment.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;More &lt;/strong&gt;(the three horizontal dots) and select:
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Download: &lt;/strong&gt;To save the email as an .eml (or .msg if using classic Outlook).&lt;br&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;375&quot; height=&quot;461&quot; src=&quot;blob:https://pme.protonblog.tech/eefdf5b8-d4a8-4d3f-a355-7488d9a89b9b&quot;&gt;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Print: &lt;/strong&gt;To save the email as a .pdf file.&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;397&quot; height=&quot;483&quot; src=&quot;blob:https://pme.protonblog.tech/884f8d58-1756-4d93-b36c-ce6414cba874&quot;&gt;&lt;br&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;In your new email, select &lt;strong&gt;Attach a file to this item&lt;/strong&gt; (the paperclip icon) to attach the downloaded email. You can also drag and drop a previously downloaded email directly into the message body.&lt;/li&gt;



&lt;li&gt;Add your recipients, compose your message, and click &lt;strong&gt;Send.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to attach an email to an email in Proton Mail&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To attach an email in &lt;a href=&quot;https://proton.me/mail&quot;&gt;Proton Mail&lt;/a&gt;, you must download and upload the email to your draft.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Download and attach an email&amp;nbsp;&amp;nbsp;&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the email you want to send as an attachment.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;More&lt;/strong&gt; (the three horizontal dots) and select:
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Export&lt;/strong&gt;: To save the email as an .eml file.&lt;br&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;428&quot; height=&quot;554&quot; src=&quot;blob:https://pme.protonblog.tech/7b4af9cc-7bff-4b38-b4f1-16894e73d315&quot;&gt;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Print: &lt;/strong&gt;To save the email as a .pdf file.&lt;br&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;428&quot; height=&quot;554&quot; src=&quot;blob:https://pme.protonblog.tech/0026185d-54b1-4534-b28e-8003ae2541ca&quot;&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;In your new email, select &lt;strong&gt;Attachments&lt;/strong&gt; (the paperclip icon) to attach the downloaded email. You can also drag and drop a previously downloaded email directly into the message body.&lt;/li&gt;



&lt;li&gt;Add your recipients, compose your message, and click &lt;strong&gt;Send.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton’s privacy-first design means all your emails are &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end encrypted&lt;/a&gt; by default, so that they remain secure and private. When you export an email from Proton Mail, the exported file is decrypted locally on your device so it can be viewed in other email clients or applications.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Attaching emails works better than forwarding&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Attaching an email instead of forwarding it helps preserve the original message, including formatting, timestamps, attachments, and sender details. Whether you use Gmail, Outlook, or Proton Mail, attaching emails can make conversations clearer and provide a more reliable record of what was originally sent.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you regularly share sensitive &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;business emails&lt;/a&gt; or documents, using a privacy-first email service like Proton Mail helps keep your communications secure with end-to-end encryption by default.&lt;/p&gt;
</content:encoded><category>For business</category><author>Greg Ng</author></item><item><title>Fix your internal documentation before it becomes a liability</title><link>https://proton.me/business/blog/internal-documentation</link><guid isPermaLink="true">https://proton.me/business/blog/internal-documentation</guid><description>Here&apos;s how to organize and secure the most sensitive data in your internal documentation without slowing your business down.</description><pubDate>Fri, 31 Jul 2026 16:02:58 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Done properly, internal documentation is how a business stays consistent and coherent as it grows. Done badly, it becomes a liability.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When internal documentation is an afterthought, two problems result.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The first is disorganization, which results in wrong versions, buried policies, &lt;a href=&quot;https://proton.me/business/drive/templates/onboarding-checklist&quot;&gt;onboarding&lt;/a&gt; materials nobody has updated since the company was half its current size. The second is data exposure: sensitive data sitting in places it shouldn’t be.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most teams are managing the first issue (even if they feel overwhelmed by it). The second issue is harder to solve, but considerably more dangerous when it isn’t.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sensitive internal data is a common breach vector across industries. Proton research shows that&amp;nbsp;&lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;39% of businesses&lt;/a&gt;&amp;nbsp;report experiencing a cybersecurity incident caused by human error. Often, it&amp;#8217;s just well-meaning colleagues making mistakes with sensitive files.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s a practical framework for internal knowledge management that keeps sensitive data secure without making it harder for your team to do their jobs.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;&lt;strong&gt;The organization problem&lt;/strong&gt;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When internal documents are disorganized, you’ll soon know about it. Mostly due to the frustration and confusion it causes across your business.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For example, let’s say there are three versions of the employee handbook in your drive, plus onboarding materials that haven&amp;#8217;t been updated since the company had 10 people on the payroll. This makes onboarding slow and inconsistent, and gives new starters the wrong impression about how your business functions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Or let’s say that several important company policies aren’t in a clearly marked folder, but buried somewhere in an email thread. Managers are left making best guesses about policies and can’t enforce them consistently. One employee gets one answer, another gets a different answer.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Disorganization is fixable with the right system (we’ll get to that shortly). But there’s a second problem that you can’t solve with a better folder structure.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;&lt;strong&gt;The security problem&lt;/strong&gt;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;However well organized your document storage is, if the processes and tools that deal with those documents are lacking, &lt;a href=&quot;https://proton.me/business/blog/sensitive-information&quot;&gt;sensitive information&lt;/a&gt; will be exposed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It might be salary bands stored in a shared &lt;a href=&quot;https://proton.me/business/drive/google-sheets-alternative&quot;&gt;Google Sheet&lt;/a&gt;, source code or API keys pasted into a Slack channel, a client contract emailed as an attachment, or candidate interview notes containing &lt;a href=&quot;https://proton.me/business/blog/pii&quot;&gt;personally identifiable information&lt;/a&gt;, carelessly forwarded and now sitting in six inboxes.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When easily overlooked practices like these cause a &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;&lt;u&gt;data breach&lt;/u&gt;&lt;/a&gt;, you’re no longer contending with frustrated colleagues and obstructed processes. Instead, you’re looking at reputational damage and severe financial penalties.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Much of this data, whether it&amp;#8217;s employee records, customer information, or financial details, is personal or sensitive data under GDPR. That means whoever handles it is responsible for how it&amp;#8217;s stored, accessed, and shared. And accidents don&amp;#8217;t remove culpability.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In 2022, a UNIQLO HR staff member responded to a payroll request by accidentally emailing a PDF containing the salary data of 446 employees. The Spanish data protection authority &lt;a href=&quot;https://www.edpb.europa.eu/news/national-news/2024/spanish-supervisory-authority-fined-uniqlo-europe-ltd-violations-article_en&quot;&gt;&lt;u&gt;fined UNIQLO €270,000&lt;/u&gt;&lt;/a&gt;. The breach wasn&amp;#8217;t caused by hackers. It was caused by the absence of organizational measures around a routine HR process.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;&lt;strong&gt;How to build an inernal documentation system that solves both problems&lt;/strong&gt;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Think of what you’re building as a secure company wiki. You’re going to need four categories of internal documentation, each with different sensitivity levels and access requirements.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;&lt;strong&gt;Category 1: Reference knowledge&lt;/strong&gt;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is the material every employee should be able to find on their own: company policies, brand guidelines, how-to guides, tool documentation, org charts. Securing this category isn&amp;#8217;t about restricting access — it&amp;#8217;s about accuracy. Focus on version control (one current version, not five conflicting copies floating around) and clear ownership (one named person responsible for keeping each document up to date).&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;&lt;strong&gt;Category 2: Team and project knowledge&lt;/strong&gt;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is where most day-to-day work actually lives: project plans, process documentation, &lt;a href=&quot;https://proton.me/business/drive/templates/meeting-minutes-templates&quot;&gt;meeting notes&lt;/a&gt;, roadmaps, internal playbooks. It doesn&amp;#8217;t need company-wide access, so protect it with team-level or project-level permissions instead. Like reference knowledge, each document needs a named owner and a review cadence, or it quietly goes stale.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;&lt;strong&gt;Category 3: Confidential and regulated data&lt;/strong&gt;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is the highest-risk category, and it exists in every department: financial reports and forecasts, legal contracts, employee and customer records, strategic plans, security credentials. These need tightly restricted access, limited to the specific individuals or team who need them. (A password isn&amp;#8217;t enough here. You need&amp;nbsp;&lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end encryption&lt;/a&gt;.)&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This kind of data also shouldn&amp;#8217;t be attached to emails, saved to personal drives, or shared via links with no expiration date.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Drive is a&amp;nbsp;&lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt;&amp;nbsp;that handles this category with zero-knowledge&amp;nbsp;&lt;a href=&quot;https://proton.me/learn/encryption&quot;&gt;encryption&lt;/a&gt;&amp;nbsp;— not even Proton can read the contents — plus granular access controls that keep sensitive data where it&amp;#8217;s supposed to stay.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;&lt;strong&gt;Category 4: Externally shared materials&lt;/strong&gt;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some documents need to leave your internal system temporarily: onboarding packs for new hires, files shared with contractors or vendors, materials sent to clients during a project. This is tricky precisely because access often has to be granted before a relationship is fully vetted. The fix is straightforward: set links to expire, pre-stage access rather than granting it ad hoc, and revoke it the moment it&amp;#8217;s no longer needed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Drive sets expiration dates for links by default, so shared materials expire automatically without anyone needing to remember to revoke them.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Choosing the right platform for secure internal knowledge management&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The framework we’ve outlined can be used on any platform. But not just &lt;em&gt;any&lt;/em&gt; platform can ensure that the framework enforces itself instead of relying on people remembering to follow it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Human error inevitably creeps in when you rely on manual processes to set expiration dates on shared links, review access at &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;&lt;u&gt;offboarding&lt;/u&gt;&lt;/a&gt;, and maintain permission tiers as the team grows. But with the right platform, your framework can be enforced through automation.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There’s a second requirement for your platform: a privacy-first design. Many consumer-grade platforms aren’t designed to store sensitive information: in fact, by default &lt;a href=&quot;https://proton.me/business/blog/google-docs-ai-scraping&quot;&gt;&lt;u&gt;they harvest document content&lt;/u&gt;&lt;/a&gt; to feed into their search indexing and AI features.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most companies wouldn&amp;#8217;t dream of storing &lt;em&gt;customer&lt;/em&gt; data in an unsecured &lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt; folder. Employee data deserves the same standard. The right platform will handle both enforcement and end-to-end encryption.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;&lt;strong&gt;Three decisions that will keep your system running&lt;/strong&gt;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A good &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;cloud platform&lt;/a&gt; will enforce your security framework, but even the best platforms can’t check and update your documents for you.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unmaintained documentation creates two types of risk.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There’s legal risk: an outdated disciplinary procedure can invalidate a tribunal case, for example.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There’s cultural risk: when official documentation doesn&amp;#8217;t reflect reality, employees notice, and conclude nobody is in control.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Follow these three rules and you can avoid both:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Every document has a named owner (not a team). &lt;/strong&gt;Responsibility shared across a team is a responsibility nobody feels&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Review dates are set at creation, not added later.&lt;/strong&gt; It’s difficult to defend a document at a tribunal when it hasn’t been reviewed in three years (or there’s no record of when it was last checked)&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Archive documents, don’t delete them. &lt;/strong&gt;Deleting documents spells trouble if you (or a regulator) ever need to access them. Archiving them in a clearly labeled folder keeps your system clean without making documents irretrievable&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;None of this requires a dedicated knowledge manager. Just three decisions, made once (and revisited quarterly).&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;&lt;strong&gt;A compliance checklist for &lt;/strong&gt;&lt;strong&gt;internal &lt;/strong&gt;&lt;strong&gt;HR documentation&lt;/strong&gt;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Remember: you are the data controller. The responsibility doesn&amp;#8217;t sit with your cloud provider, it sits with you.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Do you know who has access to your most sensitive documents — financial, legal, employee, or customer data — and is that list current?&lt;/li&gt;



&lt;li&gt;Are sensitive documents encrypted at rest, not just in transit?&lt;/li&gt;



&lt;li&gt;Do shared links on sensitive documents have expiration dates?&lt;/li&gt;



&lt;li&gt;Is there a documented process for revoking access when someone leaves or a project ends?&lt;/li&gt;



&lt;li&gt;Can you produce an audit trail of who accessed what and when?&lt;/li&gt;



&lt;li&gt;Is sensitive data stored in a jurisdiction with strong privacy laws, &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;like Switzerland&lt;/a&gt;?&lt;/li&gt;



&lt;li&gt;Does every document have a named owner and a review date?&lt;/li&gt;



&lt;li&gt;Are superseded documents archived rather than deleted?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you can answer yes to all of these, your documentation system is in good shape.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;&lt;strong&gt;A secure knowledge base your employees can trust, and a platform to deliver it&lt;/strong&gt;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The framework in this guide gives you the structure. You need a platform that enforces it, so the security standards you&amp;#8217;ve set don&amp;#8217;t depend on humans remembering to apply them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Look no further than Proton Workspace. A &lt;a href=&quot;https://proton.me/business&quot;&gt;&lt;u&gt;secure collaboration&lt;/u&gt;&lt;/a&gt; suite, built on end-to-end encryption and hosted in Switzerland, one of the world&amp;#8217;s &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;&lt;u&gt;strongest privacy jurisdictions&lt;/u&gt;&lt;/a&gt;, Proton Workspace gives your team:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Real-time &lt;a href=&quot;https://proton.me/business/drive/docs&quot;&gt;&lt;u&gt;collaborative editing&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;Encrypted &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;Secure &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;&lt;u&gt;professional email&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;Secure &lt;a href=&quot;https://proton.me/business/meet&quot;&gt;video conferencing&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;Admin controls designed to scale with your business&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your employees trust you with their most sensitive data. It’s time to build an internal documentation system that’s worthy of that trust.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
  &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/business/smb-cybersecurity-report#download-report&quot;&gt;Start free trial of Proton Workspace&lt;/a&gt;
&lt;/div&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>Are AI detectors accurate?</title><link>https://proton.me/business/blog/are-ai-detectors-accurate</link><guid isPermaLink="true">https://proton.me/business/blog/are-ai-detectors-accurate</guid><description>Find out whether AI detectors are accurate, how they work, and the security risks they may expose your business to.</description><pubDate>Fri, 31 Jul 2026 15:55:21 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI presents businesses with real opportunities to improve efficiency. It also brings new challenges, which is why businesses are increasingly looking to use a specific form of AI against AI: AI detectors.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There are legitimate reasons to use AI detectors: protecting brand voice, fraud detection, spotting plagiarism, getting value for money from contractors, and more.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But AI detectors aren&amp;#8217;t infallible, and for most businesses the risks of using them outweigh the benefits. Here&amp;#8217;s what you need to know before you use one.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How do AI detectors work?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI detectors are specialized software that mathematically analyze patterns to estimate the probability that text was machine-generated. Popular detectors include GPTZero, Copyleaks, Originality.ai, Sapling, Turnitin, and Grammarly AI Detector.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;What AI detectors look for, in technical terms, comes down to two metrics:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Perplexity&lt;/strong&gt; measures how predictable a sequence of words is. Lower predictability means less likelihood of AI involvement, because AI models are trained to guess and use the most statistically probable words. Humans make more varied and eccentric word choices.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Burstiness &lt;/strong&gt;measures&lt;strong&gt; &lt;/strong&gt;variation in sentence length and complexity. Human writing “bursts” with a mixture of sentence-types, whereas probability-seeking AI tends to write in a regular, smooth, almost mathematical way. Low burstiness writing strongly indicates AI-involvement to a detector.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some AI detectors also use stylometric analysis, evaluating vocabulary choice and grammar, hunting down suspiciously rigid and formal structures.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A handful of AI models are starting to use watermarking, which involves embedding invisible and detectable patterns into AI-generated text at the point of creation. But because most models don’t currently leave a trail, you can’t yet rely on this solution.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Are AI detectors reliable?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI detectors are never 100% reliable, and they’re often significantly less reliable than that.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Accuracy varies significantly between tools, content type, and (critically) exactly how AI was used to create the analyzed content, if it was used at all.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;When detectors work&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Paste unchanged (or ‘raw’) AI output into any AI detector and the detector will detect it. Raw output is easy for the detector to identify because the statistically probable pattern it&amp;#8217;s looking for hasn’t been broken.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For example, we pasted text generated directly from Claude Sonnet 4.6 into Sapling. Sapling had &lt;strong&gt;99.5%&lt;/strong&gt; confidence that this AI-generated text was AI-generated.&amp;nbsp;&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1024&quot; height=&quot;579&quot; src=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/07/image-22-1024x579.png&quot; alt=&quot;&quot; class=&quot;wp-post-244337 wp-image-244356&quot; srcset=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/07/image-22-1024x579.png 1024w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-22-300x170.png 300w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-22-768x434.png 768w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-22.png 1054w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;figcaption class=&quot;wp-element-caption&quot;&gt;Sapling correctly flags the raw AI-generated paragraph.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Originality (another leading AI detector) flagged the same paragraph as AI with even greater confidence: &lt;b style=&quot;white-space: normal;&quot;&gt;&lt;strong class=&quot;Lexical__textBold&quot; style=&quot;white-space: pre-wrap;&quot;&gt;100%&lt;/strong&gt;&lt;/b&gt;.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1024&quot; height=&quot;504&quot; src=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/07/image-23-1024x504.png&quot; alt=&quot;&quot; class=&quot;wp-post-244337 wp-image-244386&quot; srcset=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/07/image-23-1024x504.png 1024w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-23-300x148.png 300w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-23-768x378.png 768w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-23.png 1219w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;figcaption class=&quot;wp-element-caption&quot;&gt;Originality is even surer that our raw AI text is AI-generated.&lt;/figcaption&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Detectors can also identify AI-writing when the text submitted isn’t 100% AI generated, although significantly less reliably, especially when the text is short (less than 300 words) and the patterns detectors are looking for don’t have time to establish themselves.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;When detectors fail&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It&amp;#8217;s well-documented that AI detectors find false positives: signals of AI use in text entirely written by humans. One recent &lt;a href=&quot;https://www.researchgate.net/publication/400351168_Evaluating_the_accuracy_and_reliability_of_AI_content_detectors_in_academic_contexts&quot;&gt;&lt;u&gt;peer-reviewed study of academic writing&lt;/u&gt;&lt;/a&gt; rated the overall accuracy of Originality and Turnitin when identifying AI-generated academic texts as only 69% and 61% respectively.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One issue is that humans often naturally write like AI, particularly if they’re non-native language speakers, who (like LLMs) use simple, highly grammatical phrasing. &lt;a href=&quot;https://hai.stanford.edu/news/ai-detectors-biased-against-non-native-english-writers&quot;&gt;&lt;u&gt;A Stanford study&lt;/u&gt;&lt;/a&gt; had seven popular AI detectors analyze Test of English as a Foreign Language essays by Chinese students. The average false positive rate was 61.22%.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s also hard for detectors to spot when humans deliberately disrupt the statistical patterns they’re looking for. AI-assisted authors don’t have to do much to break those patterns: rewrite a few sentences, vary sentence structure, use less predictable words.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If this seems like too much work, they can get it done for them by one of the increasing array of ‘humanizer’ tools that have inevitably arisen to outsmart detectors.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;They can also simply stick to their chosen LLM and use smarter prompts. A &lt;a href=&quot;https://arxiv.org/pdf/2502.15666&quot;&gt;&lt;u&gt;2025 study of 12 AI detectors&lt;/u&gt;&lt;/a&gt; found that “minimal polishing with GPT-4o can lead to detection rates ranging from 10% to 75%, depending on the detector”.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We asked Claude Sonnet 4.6 to write a 300 word essay about AI detector accuracy, and asked it to write like a human, with varied sentence lengths, direct opinion, and unexpected word choices. Sapling scored the text as only &lt;strong&gt;12%&lt;/strong&gt; likely to be generated by AI.&amp;nbsp;&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1024&quot; height=&quot;579&quot; src=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/07/image-25-1024x579.png&quot; alt=&quot;&quot; class=&quot;wp-post-244337 wp-image-244425&quot; srcset=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/07/image-25-1024x579.png 1024w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-25-300x170.png 300w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-25-768x434.png 768w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-25.png 1054w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;figcaption class=&quot;wp-element-caption&quot;&gt;Sapling fails to identify cleverly-prompted Claude text.&lt;/figcaption&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Originality analyzed the same text and declared that it was &lt;strong&gt;&lt;strong&gt;100%&lt;/strong&gt;&lt;/strong&gt; confident that the text was AI generated. &lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1024&quot; height=&quot;501&quot; src=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/07/image-26-1024x501.png&quot; alt=&quot;&quot; class=&quot;wp-post-244337 wp-image-244458&quot; srcset=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/07/image-26-1024x501.png 1024w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-26-300x147.png 300w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-26-768x376.png 768w, https://pme.protonblog.tech/wp-content/uploads/2026/07/image-26.png 1266w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;figcaption class=&quot;wp-element-caption&quot;&gt;Originality scores the same text 100% AI: the opposite verdict, with equal confidence.&lt;/figcaption&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Originality looks to be the superior tool based on this test, but it’s important to recognize that both tools were equally confident in their analysis. If you wrote the analyzed text, you’ll know which detector is correct. If you didn’t, then you can never be sure.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How AI detectors endanger your data &lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The bigger issue with AI detectors is one that many businesses overlook entirely: the risks they present to the privacy and security of your data. These are similar risks to those posed by &lt;a href=&quot;https://proton.me/lumo/ai&quot;&gt;AI &lt;strong&gt;in general&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Compliance risks: &lt;/strong&gt;Detection models inherit biases from training data, creating potential for discriminatory outcomes and breaking equal opportunity laws. Many detectors are “black boxes”, and frameworks like the &lt;a href=&quot;https://artificialintelligenceact.eu/&quot;&gt;&lt;u&gt;EU AI Act&lt;/u&gt;&lt;/a&gt; and the &lt;a href=&quot;https://www.nist.gov/itl/ai-risk-management-framework&quot;&gt;&lt;u&gt;NIST AI Risk Management Framework&lt;/u&gt;&lt;/a&gt; demand organizations must provide meaningful logic for AI outputs.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;IP and training data risks: &lt;/strong&gt;Many AI detectors have Terms of Service (ToS) that grant the provider the right to store, analyze, and use submitted data to train future models.This can mean that your provider has the legal right to use whatever product roadmaps, financial projections, and proprietary research you&amp;#8217;ve submitted with no obligation to guarantee its privacy or prevent it surfacing in a competitor&amp;#8217;s output.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Data security risks: &lt;/strong&gt;AI detectors are vulnerable to cyberattacks, and submitting content to a third-party detector extends your attack surface to include your provider&amp;#8217;s. If your provider suffers a breach, your data will be in it. Free, unvetted tools — the very type employees can be tempted to reach for — won&amp;#8217;t let you audit a provider&amp;#8217;s security practices in advance.&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;https://proton.me/business/blog/data-sovereignty&quot;&gt;&lt;u&gt;&lt;strong&gt;Data sovereignty&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt;&lt;strong&gt; risks: &lt;/strong&gt;Submitting a document to a detector can mean transferring text to foreign servers, potentially stripping it of local protections and exposing it to extraterritorial government surveillance under &lt;a href=&quot;https://www.congress.gov/crs-product/R45173#_Toc512609177&quot;&gt;&lt;u&gt;the CLOUD act&lt;/u&gt;&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For most businesses, the question isn&amp;#8217;t whether AI detectors work: it&amp;#8217;s whether the risks of using them are worth taking. If you&amp;#8217;re working with any sensitive, original, or confidential data, the answer is no.&lt;/p&gt;



&lt;hr class=&quot;wp-block-separator has-alpha-channel-opacity&quot;/&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;FAQ on AI detectors&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;How do AI detectors work?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI detectors scan text looking for patterns they’ve been trained to associate with AI-generated text. These patterns appear because AI generates text by algorithmically predicting and using the most probable next word.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;What do AI detectors look for?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The main indicators of AI-generated text that detectors look for are low levels of ‘perplexity’ (unpredictable word choices) and ‘burstiness’ (variation in sentence length and structure).&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some AI models are starting to experiment with watermarking, which means embedding invisible (but detectable) patterns into text at the point of generation. However, since only a few models have started to do this, watermarking doesn’t yet provide a foolproof test for AI-generated text.&amp;nbsp;&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Do AI detectors work?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Accuracy depends on the detector used, the type of text being analyzed, and how (if at all) AI has been used to generate the text. Detectors perform well on raw, unedited AI output. On anything more complex — edited content, human writing by non-native speakers, AI output that’s been lightly paraphrased — accuracy drops significantly.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Accuracy aside, the bigger problem with AI detectors is the threat that using them can pose to your data security. Submitting content to a third-party detector means transferring it to external servers, potentially exposing it to cyberattacks, data harvesting, extraterritorial surveillance, and handing a provider legal rights to your submitted content.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For most businesses, especially those working with any sensitive, original, or confidential content, the data risks that come with third-party AI detection outweigh the benefits.&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>We’ve improved autofill for Proton Pass</title><link>https://proton.me/blog/pass-improved-autofill</link><guid isPermaLink="true">https://proton.me/blog/pass-improved-autofill</guid><description>Update to the latest version of Proton Pass to get access to improved autofill, smoother 2FA verification, and easier business rollout.</description><pubDate>Thu, 30 Jul 2026 15:50:49 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;The latest version of Proton Pass includes a few updates our community has been anticipating.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Improving &lt;a href=&quot;https://proton.me/support/pass-autotype&quot;&gt;autofill&lt;/a&gt; has been one of the main community requests for Proton Pass. We heard you, and we&amp;#8217;ve worked hard to deliver a significant improvement: The new version resolves 80% of the autofill issues users reported to us.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We&amp;#8217;ve also improved the &lt;a href=&quot;https://proton.me/support/pass-2fa&quot;&gt;2FA autofill&lt;/a&gt;. On the business side, we made it easier to roll out Proton Pass across an organization.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We&amp;#8217;ll explain below how each update works and what to expect.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Easier, faster logins with improved autofill&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass now autofills on sites where it previously couldn&amp;#8217;t, including shopping platforms, social media sites, forums, and banking websites.&lt;/p&gt;



&lt;figure class=&quot;wp-block-video aligncenter&quot;&gt;&lt;video height=&quot;1080&quot; style=&quot;aspect-ratio: 1920 / 1080;&quot; width=&quot;1920&quot; controls src=&quot;https://res.cloudinary.com/dbulfrlrz/video/upload/f_auto,q_auto/v1785419244/wp-pme/proton-pass-autofill-update-video.mp4?_i=AA&quot;&gt;&lt;/video&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This improvement comes from an upgrade to how Proton Pass detects forms on the website you&amp;#8217;re visiting. Some websites don&amp;#8217;t put login forms directly on the page, instead loading them inside a separate frame known as an iframe. Autofill can now accurately detect those frames, so Proton Pass can autofill more of the forms you encounter.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We&amp;#8217;re continuing to improve autofill over the coming months, including URL matching, support for native autofill on Mac, and adding more supported languages.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A more robust 2FA autofill&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/what-is-two-factor-authentication-2fa&quot;&gt;Two-factor authentication (2FA)&lt;/a&gt; is one of the best ways to protect your online accounts, which is why you can create and store 2FA codes within Proton Pass.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When you&amp;#8217;re logging into an account, you&amp;#8217;ll usually see a prompt to autofill your 2FA code. However, in some cases the prompt doesn&amp;#8217;t appear, forcing you to switch apps to manually copy and paste the code.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can now choose to automatically copy your 2FA codes to your clipboard, so even if the 2FA autofill isn&amp;#8217;t prompted, the code is ready to paste.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With this improvement, you won&amp;#8217;t have to switch apps to find the code you need. 2FA won&amp;#8217;t slow you down anymore, and signing in stays easy and secure.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Roll out Proton Pass with ease&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The Proton Pass Windows installer has now moved from .exe to .msix, which works natively with Microsoft Intune. .msix gives users a cleaner, safer install — it&amp;#8217;s sandboxed, easy to fully uninstall, and offers automatic delta updates.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This means admins can deploy and maintain Proton Pass across all company devices centrally, instead of machine by machine. It&amp;#8217;s also an easier experience for individual users, offering a more predictable and contained installation than .exe.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you&amp;#8217;re an IT admin, making changes to your IT infrastructure can often take significant time and effort. With this change, deploying and managing a new &lt;a href=&quot;https://proton.me/pass&quot;&gt;password manager&lt;/a&gt; is now quicker, lower-effort, and more reliable, not a manual task you need to repeat on every machine.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;More improvements in this release&lt;/h2&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Check for updates in the desktop app:&lt;/strong&gt; A new button in Settings on macOS and Windows makes it easy to check whether you&amp;#8217;re on the latest version.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Liquid glass animations:&lt;/strong&gt; The iOS app now uses Apple&amp;#8217;s latest design language, with a more refined and modern visual experience&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Username generator: &lt;/strong&gt;You can now &lt;a href=&quot;https://proton.me/pass/username-generator&quot;&gt;generate usernames&lt;/a&gt; on iOS, alongside passwords and email &lt;a href=&quot;https://proton.me/pass/aliases&quot;&gt;aliases&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Your feedback is important&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your feedback has helped us make these changes, and we want to know what else you need from Proton Pass. Let us know what you&amp;#8217;d like to see on &lt;a href=&quot;https://www.reddit.com/r/ProtonPass/&quot;&gt;Reddit&lt;/a&gt;, &lt;a href=&quot;https://protonmail.uservoice.com/forums/953584-proton-pass-authenticator&quot;&gt;UserVoice&lt;/a&gt;, and &lt;a href=&quot;https://x.com/ProtonPrivacy&quot;&gt;X&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Thank you for being part of our community and supporting us as we build this privacy-first password manager.&lt;/p&gt;
</content:encoded><category>Proton Pass</category><author>Son Nguyen Kim</author></item><item><title>Data classification for businesses: how to organize and protect company
information</title><link>https://proton.me/business/blog/data-classification-business</link><guid isPermaLink="true">https://proton.me/business/blog/data-classification-business</guid><description>Learn how to classify business data, define protection levels, control access, and reduce exposure with a data classification framework.</description><pubDate>Tue, 28 Jul 2026 13:44:10 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data classification helps businesses stop treating every piece of information as if it carries the same risk. A supplier email, an internal process note, a customer payment record, and an admin recovery code should not move through the business under the same rules.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sensitive data is stored throughout your business network: It moves through CRMs, inboxes, cloud storage, spreadsheets, HR systems, support platforms, finance software, and vendor tools. Without a shared system for classifying it, teams often rely on instinct: if something looks safe to share, or probably needs approval, they’ll take the quicker, easier route.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This may work for a while, but it doesn’t scale. A clear data classification policy gives your business a common language for deciding which information can be public, which should stay internal, which needs tighter controls, and which should only be available to specific roles.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-is-data-classification&quot;&gt;What is data classification?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#why-data-classification&quot;&gt;Why data classification matters &lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#simple-classification-framework&quot;&gt;A simple data classification framework &lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#data-classification-examples&quot;&gt;Data classification examples for business teams&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#classification-access-control&quot;&gt;How classification drives access control&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#sharing-classified-data&quot;&gt;Sharing classified data safely&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#data-audit&quot;&gt;Start with a data audit&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#create-data-classification-policy&quot;&gt;How to create a data classification policy&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#proton-pass-business&quot;&gt;How Proton Pass for Business supports data classification&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#classification-everyday&quot;&gt;Make classification part of everyday data protection&lt;/a&gt;&lt;/p&gt;



&lt;h2 id=&quot;what-is-data-classification&quot; class=&quot;wp-block-heading&quot;&gt;What is data classification?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data classification is the process of labeling business data by how sensitive it is and how much harm it could cause if it is exposed, changed, lost, or misused. In practice, it means grouping information into clear levels so people know how to store it, share it, protect it, and eventually delete it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A useful classification system fits into daily work. It gives employees a quick way to understand when information can move freely, when it needs approval, and when access should be limited to a small group. The goal is to make the safer decision obvious before data is copied, shared, exported, or stored somewhere it should not be.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The UK National Cyber Security Centre’s guidance on&lt;a href=&quot;https://www.ncsc.gov.uk/guidance/asset-management&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; asset management&lt;/a&gt; treats information as an asset that needs visibility, ownership, and protection. This is a useful way to frame classification: before deciding who can access sensitive data, you need to know what that data is and where it lives.&lt;/p&gt;



&lt;h2 id=&quot;why-data-classification&quot; class=&quot;wp-block-heading&quot;&gt;Why data classification matters&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can’t protect what your business hasn’t identified. This is especially true for SMBs, which usually do not have the resources to protect every system and every type of information with the same level of control. Before a business can decide who should access sensitive data, which systems need stronger protections, or where MFA and secure sharing are most urgent, it needs to know what information it holds and which data matters most.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data classification is the first step in a practical &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection&lt;/a&gt; strategy. It separates routine business information from data that could create real harm if exposed, changed, lost, or shared with the wrong person.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is especially useful as information spreads across CRMs, inboxes, cloud storage, HR systems, support tools, finance software, exports, and vendor platforms. Classification gives employees a clear signal: what can be handled normally, what needs approval, and what should only be available to specific roles.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It also supports compliance. The UK’s Information Commissioner’s Office (ICO), the authority responsible for data protection enforcement and &lt;a href=&quot;https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;UK GDPR guidance&lt;/a&gt;, expects organizations to apply appropriate technical and organizational measures. Classification helps make that practical by matching protection to the sensitivity of the data.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For breach prevention, the principle is simple: sensitive data should not be accessible to more people than necessary. Proton’s guide to data loss prevention for businesses explains how reducing unnecessary exposure before an incident can limit the damage afterward.&lt;/p&gt;



&lt;h2 id=&quot;simple-classification-framework&quot; class=&quot;wp-block-heading&quot;&gt;A simple data classification framework&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A classification framework doesn’t need to be complicated. Four levels are usually enough for small and midsize businesses:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Public&lt;/li&gt;



&lt;li&gt;Internal&lt;/li&gt;



&lt;li&gt;Confidential&lt;/li&gt;



&lt;li&gt;Restricted&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Public&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Public data is information approved for external use. A published version of this article you are reading, for example, would be Public data: it can be read, safe to share openly, and indexed without creating meaningful security or privacy risk.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Other examples include:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Website copy&lt;/li&gt;



&lt;li&gt;Press releases&lt;/li&gt;



&lt;li&gt;Public job descriptions&lt;/li&gt;



&lt;li&gt;Approved sales materials&lt;/li&gt;



&lt;li&gt;Product pages&lt;/li&gt;



&lt;li&gt;Public company descriptions. &lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Public information still needs accuracy and brand review, but it doesn’t usually need strict access control once it has been approved.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Internal&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Internal data is meant for employees and approved collaborators only, but not for public distribution. Exposure may not cause severe damage, but it can create confusion, reputational risk, or operational issues.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Examples include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Internal process documents &lt;/li&gt;



&lt;li&gt;Team notes&lt;/li&gt;



&lt;li&gt;Standard operating procedures&lt;/li&gt;



&lt;li&gt;Training materials&lt;/li&gt;



&lt;li&gt;Non-sensitive project plans&lt;/li&gt;



&lt;li&gt;Internal calendars &lt;/li&gt;



&lt;li&gt;General vendor contact lists.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Internal data should stay in approved business systems. For example, a draft campaign brief, an onboarding checklist, or notes from a team planning meeting may not be highly sensitive, but they still belong in the company’s approved workspace, not in a personal folder, private inbox, or unmanaged download.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Confidential&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Confidential data is sensitive business or &lt;a href=&quot;https://proton.me/business/blog/pii&quot;&gt;personally identifiable information&lt;/a&gt; (PII) that could harm the company, customers, employees, or partners if exposed. Access should be restricted to approved roles with a clear business need.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Examples include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Customer records &lt;/li&gt;



&lt;li&gt;Employee files&lt;/li&gt;



&lt;li&gt;Contracts&lt;/li&gt;



&lt;li&gt;Commercial terms&lt;/li&gt;



&lt;li&gt;Financial reports&lt;/li&gt;



&lt;li&gt;Sales pipeline details&lt;/li&gt;



&lt;li&gt;Support tickets containing personal data&lt;/li&gt;



&lt;li&gt;Unpublished business plans&lt;/li&gt;



&lt;li&gt;Non-public vendor agreements&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Confidential data should only be accessible to approved roles. It shouldn’t live in personal drives, open shared folders, unmanaged spreadsheets, or inboxes where nobody reviews access. If it needs to be shared externally, the business should use end-to-end encrypted (E2EE) &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt; and limit sharing to authorized recipients with a clear business purpose.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Restricted&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Restricted data is the most sensitive category. If it is exposed, misused, or changed, the business could face serious financial, legal, operational, or security consequences.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Examples include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Admin credentials&lt;/li&gt;



&lt;li&gt;Recovery codes&lt;/li&gt;



&lt;li&gt;Authentication secrets&lt;/li&gt;



&lt;li&gt;Customer payment details&lt;/li&gt;



&lt;li&gt;Highly sensitive HR records&lt;/li&gt;



&lt;li&gt;Legal dispute files&lt;/li&gt;



&lt;li&gt;Security incident reports&lt;/li&gt;



&lt;li&gt;Privileged access logs&lt;/li&gt;



&lt;li&gt;Encryption keys&lt;/li&gt;



&lt;li&gt;Backup access details&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Restricted data needs the strongest controls: limited access, strong authentication and &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt;, end-to-end encrypted cloud storage, &lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;secure sharing&lt;/a&gt;, and auditability.&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Classification level&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Sensitivity&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Examples&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Access level&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Sharing rules&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Public&lt;/td&gt;&lt;td&gt;Low&lt;/td&gt;&lt;td&gt;Published articles, website copy, press releases, public job posts, approved sales materials&lt;/td&gt;&lt;td&gt;Approved for external use&lt;/td&gt;&lt;td&gt;Can be shared publicly once reviewed and approved&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Internal&lt;/td&gt;&lt;td&gt;Moderate&lt;/td&gt;&lt;td&gt;Team notes, draft campaign briefs, onboarding checklists, internal process documents&lt;/td&gt;&lt;td&gt;Employees and approved collaborators&lt;/td&gt;&lt;td&gt;Keep inside approved business systems&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Confidential&lt;/td&gt;&lt;td&gt;High&lt;/td&gt;&lt;td&gt;Customer records, employee files, contracts, financial reports, support tickets with personal data&lt;/td&gt;&lt;td&gt;Approved roles only&lt;/td&gt;&lt;td&gt;Share only with authorized recipients and a clear business purpose&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Restricted&lt;/td&gt;&lt;td&gt;Highest&lt;/td&gt;&lt;td&gt;Admin credentials, recovery codes, payment details, security incident reports, privileged access logs&lt;/td&gt;&lt;td&gt;Named users or tightly controlled groups&lt;/td&gt;&lt;td&gt;Do not share through email, chat, screenshots, or unmanaged documents&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;data-classification-examples&quot; class=&quot;wp-block-heading&quot;&gt;Data classification examples for business teams&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Classification becomes easier when teams can recognize it in their own work. Finance teams may treat a public pricing page as public, while invoices, payroll files, tax documents, and payment records are usually confidential. Banking credentials and payment platform admin access should be restricted because they can expose information, change settings, or move money.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In practice, that access should be controlled through role-based permissions, strong authentication, regular access reviews, and a business password manager that helps teams manage and control the credentials behind sensitive systems.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;HR data follows a similar pattern. A job posting can be public, while employment contracts, salary information, sickness records, benefits details, and candidate data are usually confidential. Sensitive investigations, HR admin credentials, and broad access to employee records should be restricted.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is not a historical anomaly: &lt;a href=&quot;https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2022/10/ico-fines-interserve-44-million-for-failing-to-keep-staff-information-secure/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;the 2022 ICO fine against Interserve&lt;/a&gt;, totaling £4.4 million, is a stark warning that employee data should be classified and protected as sensitive business information, not treated like ordinary internal documentation.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sales, customer success, marketing, and IT teams also need clear boundaries. Customer records and support tickets that contain personal or account-level information are often confidential. Internal segmentation work, campaign planning, and performance reports may be internal or confidential depending on whether they include customer-level data, commercial sensitivity, or non-public business strategy.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Vendor documentation should be classified based on what it contains, especially if it includes access details, commercial terms, or security information. Exported customer datasets, CRM admin access, admin access to advertising platforms such as Google Ads or Meta Business Manager, backup credentials, recovery codes, privileged access logs, and security tooling credentials should be restricted because one exposed file or account can affect far more than one person.&lt;/p&gt;



&lt;h2 id=&quot;classification-access-control&quot; class=&quot;wp-block-heading&quot;&gt;How classification drives access control&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once data is classified, access stops being a generic permission setting and becomes a business decision. The question is no longer only whether someone can open a system, but whether their role justifies access to the information inside it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A support team may need customer conversations, but not every exported customer file. Finance may need payment and accounting records, but not HR investigations. A contractor may need access to one project workspace, not the company’s full archive of client files.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For confidential and restricted data, access must leave an audit trail. The business should know who accessed what, why access exists, and whether permissions are revoked immediately after a role change or &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass/for-it-teams&quot;&gt;password manager for IT teams&lt;/a&gt; supports centralized management, secure sharing, policies, admin reporting and logs, SCIM provisioning, and SSO integrations. This helps teams scope access to the credentials that unlock sensitive systems, instead of leaving passwords in browsers, spreadsheets, or chat threads.&lt;/p&gt;



&lt;h2 id=&quot;sharing-classified-data&quot; class=&quot;wp-block-heading&quot;&gt;Sharing classified data safely&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sharing rules should follow the sensitivity of the information. A published asset can circulate freely once approved, but a contract, customer file, payment record, or recovery code needs more control. The more sensitive the data, the fewer people should receive it, and the more deliberate the sharing method should be.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is especially important for email. Many businesses still send sensitive information through attachments, screenshots, or copied text, then lose track of where that information goes. Proton’s guide on how to&lt;a href=&quot;https://proton.me/business/blog/securely-send-sensitive-information-via-email&quot;&gt; securely send sensitive information via email&lt;/a&gt; explains safer ways to handle sensitive information when email is necessary.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Credentials and secrets need stricter rules than ordinary documents. Passwords, recovery codes, &lt;a href=&quot;https://proton.me/pass/passkeys&quot;&gt;passkeys&lt;/a&gt;, and admin access details shouldn’t be sent through email, chat, screenshots, or shared documents. They should be stored and shared through a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; such as Proton Pass for Business⁠ where access can be controlled, reviewed, and revoked more safely.&lt;/p&gt;



&lt;h2 id=&quot;data-audit&quot; class=&quot;wp-block-heading&quot;&gt;Start with a data audit&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before writing a data classification policy, map where business data already lives. The first audit doesn’t need to be perfect. It just needs to show which systems hold sensitive information, who can access them, and where uncontrolled copies may exist.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Start with everyday locations such as CRMs, HR platforms, finance software, cloud storage, email inboxes, shared drives, support tools, password managers, vendor portals, downloads, exports, and backups.&amp;nbsp;&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Field&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;What to record&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Location&lt;/td&gt;&lt;td&gt;Where the data lives&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Data type&lt;/td&gt;&lt;td&gt;Customer, employee, financial, credential, or operational data&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Classification level&lt;/td&gt;&lt;td&gt;Public, internal, confidential, or restricted&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Owner&lt;/td&gt;&lt;td&gt;Person or team responsible&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Access&lt;/td&gt;&lt;td&gt;Who can view, edit, export, or share it&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;MFA&lt;/td&gt;&lt;td&gt;Whether multi-factor authentication is enabled&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Vendor sharing&lt;/td&gt;&lt;td&gt;Whether third parties can access it&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Retention status&lt;/td&gt;&lt;td&gt;Keep, review, delete, or anonymize&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;create-data-classification-policy&quot; class=&quot;wp-block-heading&quot;&gt;How to create a data classification policy&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A data classification policy should be short enough for employees to use and specific enough to guide real decisions. It should define the classification levels, explain who owns sensitive data, and connect each level to access, storage, sharing, retention, and review.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A simple policy can include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Purpose and scope:&lt;/strong&gt; What the policy covers and who it applies to.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Classification levels:&lt;/strong&gt; Public, internal, confidential, and restricted, with examples.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Ownership:&lt;/strong&gt; Who approves access and handles review for sensitive data categories.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Access rules:&lt;/strong&gt; Who can access each level and how access is approved or removed.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Sharing rules:&lt;/strong&gt; Which channels are approved for each classification level.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Storage and retention:&lt;/strong&gt; Where each type of data should live and how long it should be kept.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Review cadence:&lt;/strong&gt; How often the policy and access rules are reviewed.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Legal hold process:&lt;/strong&gt; When deletion or retention rules must be paused during active investigations, disputes, or litigation.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The policy should also make room for judgment. Not every document will fit neatly into a category. When in doubt, employees should know who to ask and what default to follow. For sensitive data, the safer default is usually to restrict access until the right owner confirms otherwise.&lt;/p&gt;



&lt;h2 id=&quot;proton-pass-business&quot; class=&quot;wp-block-heading&quot;&gt;How Proton Pass for Business supports data classification&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data classification tells your business which information needs stronger protection. Access control turns that decision into daily practice.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Credentials are part of that access layer. If a password gives access to restricted data, such as admin settings, customer exports, finance systems, recovery codes, or security logs, that credential needs stricter handling than a login for a low-risk internal service.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A secure &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business helps teams apply those access decisions in practice. Credentials can be stored in encrypted vaults, organized by team or function, and shared only with the people who need them.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Admins also get better visibility into credential access through reporting and logs, while policies, SSO integrations, and SCIM provisioning help IT teams manage onboarding and offboarding more consistently.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This makes classification easier to enforce in daily work. Finance credentials can stay with finance. HR admin access can stay with authorized HR leads. Backup recovery codes and privileged admin logins can be limited to the people responsible for recovery and security.&lt;/p&gt;



&lt;h2 id=&quot;classification-everyday&quot; class=&quot;wp-block-heading&quot;&gt;Make classification part of everyday data protection&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data classification is not paperwork for its own sake. It is a way to make &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection&lt;/a&gt; easier to follow in daily work.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once your business knows which data is most sensitive, the next step is controlling who can reach it. A password manager can help teams control and monitor the credentials that unlock sensitive systems and restricted data.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Control access to classified data across your organization with a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>For business</category><author>Ben Wolford</author></item><item><title>IT disaster recovery plan: how to build one for your SMB</title><link>https://proton.me/business/blog/it-disaster-recovery-plan</link><guid isPermaLink="true">https://proton.me/business/blog/it-disaster-recovery-plan</guid><description>Learn how to build an IT disaster recovery plan for your SMB, including RTO, RPO, backup testing, system priorities, and credential recovery.</description><pubDate>Tue, 28 Jul 2026 13:10:57 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;When a key system within your business goes down, the hardest parts are knowing what to restore first, who has the access to do it, which backup can be trusted, and how long your business can keep working without that system.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That is where many small and midsize businesses (SMBs) discover the gap between having backups and having an actual recovery plan. A backup may contain the data you need, but it doesn’t decide the recovery order, assign responsibilities, validate whether the restore works, or solve the problem of missing admin credentials during an outage.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An IT disaster recovery plan gives this process structure before a disruption happens. It defines which systems matter most, how quickly they need to be restored, how much data loss the business can tolerate, what &lt;a href=&quot;https://proton.me/business/pass/data-loss-prevention&quot;&gt;data loss prevention&lt;/a&gt; strategies to implement, who owns each recovery step, and how critical credentials are protected. This clarity can prevent an IT incident from turning into prolonged downtime, lost revenue, or a wider operational crisis.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-is&quot;&gt;What is an IT disaster recovery plan?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#business-continuity&quot;&gt;Business continuity vs. IT disaster recovery&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-disaster-plan&quot;&gt;What your IT disaster recovery plan must cover&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-plan-defines&quot;&gt;What your IT disaster recovery plan needs to define&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#credential-recovery&quot;&gt;Credential recovery: the overlooked disaster recovery scenario&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#plan-template&quot;&gt;Disaster recovery plan template &lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#test-plan&quot;&gt;How to test your IT disaster recovery plan&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#build-recovery&quot;&gt;Build recovery around systems, data, and access&lt;/a&gt;&lt;/p&gt;



&lt;h2 id=&quot;what-is&quot; class=&quot;wp-block-heading&quot;&gt;What is an IT disaster recovery plan?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An IT disaster recovery plan is a documented process for restoring technology systems after a disruption. It focuses on the IT layer of the business: data, applications, devices, infrastructure, cloud services, admin access, backups, and the people responsible for recovery.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A practical IT recovery plan should answer questions like:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Which systems must come back first?&lt;/li&gt;



&lt;li&gt;How much downtime can the business tolerate?&lt;/li&gt;



&lt;li&gt;How much data loss is acceptable?&lt;/li&gt;



&lt;li&gt;Where are backups stored?&lt;/li&gt;



&lt;li&gt;Who can restore systems?&lt;/li&gt;



&lt;li&gt;Which admin credentials are needed?&lt;/li&gt;



&lt;li&gt;How will the team confirm that restored systems are safe and usable?&lt;/li&gt;



&lt;li&gt;How will the business communicate with staff and customers if primary channels are down?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A disaster recovery plan should go beyond dealing with cyberattacks: it needs to cover everyday issues like hardware failure, lost credentials, and accidental deletion. It also needs to cover external service interruptions such as cloud platform or SaaS tool disruptions, misconfigurations, and key employees leaving without transferring critical access.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Recovery is not something to design during an outage. It needs to be planned, owned, communicated, and tested before your business needs to depend on it.&lt;/p&gt;



&lt;h2 id=&quot;business-continuity&quot; class=&quot;wp-block-heading&quot;&gt;Business continuity vs. IT disaster recovery&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Business continuity and IT disaster recovery often get treated as the same thing, but they solve different problems.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;Business continuity&lt;/a&gt; is about keeping the company operating during a disruption. It covers client communication, temporary workflows, staff responsibilities, supplier coordination, and decisions about which services need to continue even if normal systems are unavailable.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;IT disaster recovery focuses on the technology behind that work. It defines how systems, data, applications, backups, and admin access will be restored so the business can return to normal operations safely.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As an example, consider a CRM outage. A business continuity plan may explain how sales or support teams keep serving customers while the CRM is down. The IT recovery plan explains who contacts the vendor, which data needs to be restored, which backup or export is available, which credentials are required, and how the team confirms the system is safe to use again.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For many SMBs, the gap appears only during an incident. People know who would contact clients, but not who can restore the billing system. They know backups exist, but not whether a restore has ever been tested. They know one employee usually handles IT, but not what happens if that person is unavailable or where the admin passwords are stored if that person is out of contact.&lt;/p&gt;



&lt;h2 id=&quot;what-disaster-plan&quot; class=&quot;wp-block-heading&quot;&gt;What your IT disaster recovery plan must cover&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A strong IT disaster recovery plan doesn’t have to be overly long, but it needs to be specific enough to run during a stressful situation.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Recovery time objective&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Recovery time objective, or RTO, defines how quickly a system needs to be restored. A payment system may need to be back within hours, while an internal reporting dashboard may tolerate a longer outage.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Set RTOs by business impact, not by technical preference, because the cost of downtime is both a business and a technical problem. Ask which systems affect revenue, customer commitments, legal obligations, security, and employee productivity.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Recovery point objective&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Recovery point objective, or RPO, defines how much data loss is acceptable, which then helps set the right &lt;a href=&quot;https://proton.me/business/pass/data-loss-prevention&quot;&gt;data loss prevention&lt;/a&gt; (DLP) strategies. If a system has an RPO of one hour, backups or replication need to support recovery to roughly that point.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If the RPO is one day, the business is accepting a larger gap. RPO also helps determine backup frequency, because the shorter your RPO, the more frequent your backups need to be. Critical systems therefore need more frequent backups than low-priority systems.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;System priority tiers&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Not every system should be restored at the same time. A small business disaster recovery plan should divide systems into priority tiers.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Tier 1:&lt;/strong&gt; Systems required for core operations, security, communication, or revenue.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Tier 2:&lt;/strong&gt; Important systems that can tolerate short downtime.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Tier 3:&lt;/strong&gt; Lower-priority systems that can be restored after the business is stable.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Typical tier 1 systems may include email, identity provider, password manager, finance systems, customer database, cloud storage, and communication platforms.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Backup strategy&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your backup strategy should define:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;What is backed up and how often&lt;/li&gt;



&lt;li&gt;Where backups are stored&lt;/li&gt;



&lt;li&gt;Who can access them&lt;/li&gt;



&lt;li&gt;How restoration is tested&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The &lt;a href=&quot;https://www.ncsc.gov.uk/collection/ransomware-resistant-backups&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;NCSC has also published&lt;/a&gt; ransomware-resistant backup principles for cloud and on-premises backup solutions, noting that backed-up data is not resistant to ransomware by default and should be assessed against the ransomware threat.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A strong backup strategy usually includes offline or immutable backups for critical data, regular testing, documented restore steps, and separate credentials for backup administration.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Roles and responsibilities&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A disaster recovery plan should name owners, not just tasks. If one person holds all recovery knowledge, the business has a people risk as well as an IT risk. Define who:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Leads recovery&lt;/li&gt;



&lt;li&gt;Restores systems&lt;/li&gt;



&lt;li&gt;Contacts vendors&lt;/li&gt;



&lt;li&gt;Approves emergency access&lt;/li&gt;



&lt;li&gt;Communicates internally&lt;/li&gt;



&lt;li&gt;Documents decisions&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;what-plan-defines&quot; class=&quot;wp-block-heading&quot;&gt;What your IT disaster recovery plan needs to define&lt;/h2&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Component&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;What it answers&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;RTO&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;How quickly does each system need to be restored?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;RPO&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;How much data can the business afford to lose?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Priority tiers&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Which systems come back first, and which can wait?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Backup strategy&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;What is backed up, where is it stored, and has restoration been tested?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Roles and responsibilities&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Who leads recovery, restores systems, contacts vendors, and approves emergency changes?&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;credential-recovery&quot; class=&quot;wp-block-heading&quot;&gt;Credential recovery: the overlooked disaster recovery scenario&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Disaster recovery often focuses on data, servers, and backups. But in practice, recovery can fail because the team cannot access the systems needed to restore operations.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Credential recovery asks:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Who has access to admin accounts?&lt;/li&gt;



&lt;li&gt;Where are backup credentials stored?&lt;/li&gt;



&lt;li&gt;Which accounts can restore critical systems?&lt;/li&gt;



&lt;li&gt;What happens if a password is lost, compromised, or held by someone unavailable?&lt;/li&gt;



&lt;li&gt;Are emergency credentials protected and reviewed?&lt;/li&gt;



&lt;li&gt;Can access be revoked and reassigned quickly?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If backup credentials are stored in one employee’s browser, recovery codes are kept in a private note, or shared admin passwords circulate through chat, the business may not be able to recover cleanly during an incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; helps reduce that risk by centralizing critical credentials in encrypted vaults, assigning access by role, and making it easier to revoke or reassign access when someone leaves or responsibilities change. Proton Pass for Business helps teams &lt;a href=&quot;https://proton.me/pass/password-generator&quot;&gt;generate strong passwords&lt;/a&gt;, store credentials securely, use secure sharing, and keep sensitive access out of chats and spreadsheets.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As a &lt;a href=&quot;https://proton.me/business/pass/for-it-teams&quot;&gt;password manager for IT teams&lt;/a&gt;, Proton Pass supports centralized &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/pass/password-policy&quot;&gt;password policies&lt;/a&gt;, &lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;secure sharing&lt;/a&gt;, reporting and logs, SCIM provisioning, and SSO integrations. That makes credential recovery more manageable because access to critical systems is not dependent on one person, one browser profile, or one undocumented password.&lt;/p&gt;



&lt;h2 id=&quot;plan-template&quot; class=&quot;wp-block-heading&quot;&gt;Disaster recovery plan template&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A disaster recovery plan works best when it is specific enough to guide action during an outage, but simple enough for the team to use under pressure. For SMBs, the template should focus on the essentials: what needs to be restored, how quickly, from which backup, by whom, and with which credentials.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. Scope&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define which systems, services, locations, devices, and data the plan covers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;This IT disaster recovery plan covers the systems, data, services, credentials, and vendors required to restore [Company Name]’s critical operations after a technology disruption.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. Critical systems inventory&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;List the systems your business relies on and assign priority tiers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Critical systems will be grouped into Tier 1, Tier 2, and Tier 3 based on business impact, recovery time objective, recovery point objective, and dependency on other systems.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. Recovery objectives&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define RTO and RPO for each priority system.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Each system must have a documented recovery time objective and recovery point objective. These targets should be reviewed at least annually and after major system changes.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;4. Backup and restore process&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Document where backups are stored, how often they run, who can access them, and how restore testing works.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Backups must be protected from unauthorized access, stored separately from primary systems where appropriate, and tested on a regular schedule. Restore procedures must be documented for Tier 1 systems.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;5. Credential and access recovery&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define where critical credentials are stored and who can access them during recovery.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Admin credentials, backup credentials, recovery codes, and vendor access required for disaster recovery must be stored in an approved encrypted vault. Access must be limited to authorized roles and reviewed after role changes, offboarding, and recovery exercises.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;6. Roles and escalation&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define recovery owners, alternates, and escalation paths.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Each recovery role must have a primary owner and a backup owner. The plan must identify who leads recovery, who restores systems, who contacts vendors, who communicates updates, and who approves emergency changes.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;7. Communication plan&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define how the business communicates internally and externally during an IT outage.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;During a recovery event, internal updates will be shared through [approved channel]. External communications to customers, vendors, insurers, or regulators must be approved by [role/team].&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;8. Testing and review cadence&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define how often the plan is tested and updated.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;This disaster recovery plan will be tested at least [annually/twice a year] and reviewed after major incidents, system changes, vendor changes, or failed recovery exercises.&lt;/em&gt;&lt;/p&gt;



&lt;h2 id=&quot;test-plan&quot; class=&quot;wp-block-heading&quot;&gt;How to test your IT disaster recovery plan&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A disaster recovery plan only becomes useful when it has been tested under conditions that resemble real disruption. A backup that exists but has never been restored is still an assumption. A recovery role that only one person understands is still a dependency. An admin credential that no one can find during an outage is still a blocker.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Testing does not need to be complex at first. For most SMBs, the goal is to prove that the business can restore the right systems, with the right people, using the right credentials, within a realistic timeframe.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. Tabletop exercise&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Choose a likely scenario, such as ransomware affecting shared files, a cloud storage outage, accidental deletion of customer data, or the sudden loss of access to an admin account. Walk through what the team would do in the first hour, who would lead, which vendors would be contacted, which systems would be prioritized, and what information would be missing.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. Test restoration&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Select a critical file, database, mailbox, or system export and confirm that it can be restored to a usable state. Check whether the restored data is recent enough, whether permissions still work, and whether the team knows where the backup lives.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. Test regularly&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As a practical baseline, SMBs should test the plan at least once a year, in line with NIST guidance in&lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf&quot;&gt; Special Publication 800-34 Revision 1&lt;/a&gt;⁠￼, and more often after major system or vendor changes.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;4. Test credential recovery&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Confirm that authorized people can access backup admin accounts, cloud admin accounts, vendor portals, recovery codes, and emergency credentials without relying on one employee’s browser, private notes, or memory. The goal is not to expose sensitive passwords unnecessarily. It is to confirm that the access model still works when the business is under pressure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;After every test, document what failed, what took too long, and assign a specific person and deadline for each fix. A good test is not one where everything goes perfectly. It is one that reveals the gaps while the business still has time to fix them.&lt;/p&gt;



&lt;h2 id=&quot;build-recovery&quot; class=&quot;wp-block-heading&quot;&gt;Build recovery around systems, data, and access&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A useful IT disaster recovery plan gives the business a recovery order, a set of owners, a realistic view of acceptable downtime, and a way to maintain &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;business continuity&lt;/a&gt; and regain access to the systems that keep work moving.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For SMBs, this might make the difference between a short disruption and a prolonged outage. If email, finance software, cloud storage, customer systems, or admin accounts are unavailable, the team needs to know what comes first, who can act, and which credentials are required to restore access safely.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is why recovery planning should cover systems, data, and access together. Backups may restore files, but credentials are what let the team regain control of the systems needed to recover. Admin logins, vendor portals, backup accounts, recovery codes, and shared operational credentials all need to be protected, organized, and available to the right people when something goes wrong.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; helps strengthen that part of the plan. With critical credentials stored in encrypted &lt;a href=&quot;https://proton.me/business/pass/password-vault&quot;&gt;password vaults&lt;/a&gt; and shared only with authorized people, the business is less dependent on one employee’s browser, private notes, or memory during a recovery event.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item></channel></rss>