Business software · 3 min read
Internal software security: questions to ask
An internal application still needs strong access controls, maintained dependencies and a recovery plan. Being used only by staff does not make it automatically safe. Ask for evidence of permission testing, secure account handling and backup restoration rather than accepting a general claim that the system is secure.
By Raja Wahab, Co-founder, Fixby Studios · Published · 3 min read
Start with the information and the consequences
List what the application contains and what could happen if it is exposed, changed or unavailable. A staff lunch planner and an operational system containing customer records have different risks. Use that assessment to decide which controls need specialist review.
This checklist helps you ask procurement questions. It is not a security audit, certification or a guarantee of compliance.
Define access by job need
Users should receive the access necessary for their tasks. Separate everyday work from administration and review access when roles change. Shared accounts make it harder to remove access and understand who made a change.
Ask how the system handles an employee leaving, a lost device and a compromised account. The answers should describe actions someone can actually take.
Ask for concrete evidence
| Area | Evidence to request |
|---|---|
| Permissions | Tests showing one user cannot access another's restricted records |
| Authentication | Appropriate account recovery and stronger protection for sensitive access |
| Secrets | Credentials kept out of public code and browser responses |
| Updates | Named responsibility for dependencies and patches |
| Backups | A tested restoration process |
| Monitoring | A way to notice failures and suspicious activity |
Check the less obvious routes
Downloads, exports and integrations need the same access thinking as ordinary pages. A hidden navigation link is not protection. Ask what happens if a user changes a record identifier in a request or keeps an old document link after their access is removed.
Logs should help investigate an incident without unnecessarily collecting passwords, tokens or sensitive content. Agree who can read them and how long they are retained.
Plan a response before an incident
Name the person who can disable access, contact the supplier and coordinate recovery. Keep the information available outside the affected application. Consider the impact of third-party outages and how essential work continues.
Use established guidance
The NCSC small business guidance provides practical starting points, and OWASP's verification standard can inform a developer's testing approach. Higher-risk systems may need independent security testing. Ask what has actually been assessed and what remains untested; a checklist tick should not replace evidence.
Sources
Raja Wahab is co-founder of Fixby Studios, a Huddersfield studio building websites, SEO, social media and business software for small, owner-managed businesses across West Yorkshire.
Next step
Let's get your business seen.
Get a free Blueprint with a clear plan, honest pricing and no jargon.
Tell us which task takes too much time and we'll assess a focused software or automation project. Business software and automation
Prefer to talk it through? Contact Fixby Studios, email info@fixbystudios.co.uk or call 07737 067552.
