Business software · 3 min read

Internal software security: questions to ask

An internal application still needs strong access controls, maintained dependencies and a recovery plan. Being used only by staff does not make it automatically safe. Ask for evidence of permission testing, secure account handling and backup restoration rather than accepting a general claim that the system is secure.

Get a free Website Blueprint. A tailored plan for your site and search — free, no obligation.

By Raja Wahab, Co-founder, Fixby Studios · Published · 3 min read

Start with the information and the consequences

List what the application contains and what could happen if it is exposed, changed or unavailable. A staff lunch planner and an operational system containing customer records have different risks. Use that assessment to decide which controls need specialist review.

This checklist helps you ask procurement questions. It is not a security audit, certification or a guarantee of compliance.

Define access by job need

Users should receive the access necessary for their tasks. Separate everyday work from administration and review access when roles change. Shared accounts make it harder to remove access and understand who made a change.

Ask how the system handles an employee leaving, a lost device and a compromised account. The answers should describe actions someone can actually take.

Ask for concrete evidence

AreaEvidence to request
PermissionsTests showing one user cannot access another's restricted records
AuthenticationAppropriate account recovery and stronger protection for sensitive access
SecretsCredentials kept out of public code and browser responses
UpdatesNamed responsibility for dependencies and patches
BackupsA tested restoration process
MonitoringA way to notice failures and suspicious activity

Check the less obvious routes

Downloads, exports and integrations need the same access thinking as ordinary pages. A hidden navigation link is not protection. Ask what happens if a user changes a record identifier in a request or keeps an old document link after their access is removed.

Logs should help investigate an incident without unnecessarily collecting passwords, tokens or sensitive content. Agree who can read them and how long they are retained.

Plan a response before an incident

Name the person who can disable access, contact the supplier and coordinate recovery. Keep the information available outside the affected application. Consider the impact of third-party outages and how essential work continues.

Use established guidance

The NCSC small business guidance provides practical starting points, and OWASP's verification standard can inform a developer's testing approach. Higher-risk systems may need independent security testing. Ask what has actually been assessed and what remains untested; a checklist tick should not replace evidence.

Sources

Raja Wahab is co-founder of Fixby Studios, a Huddersfield studio building websites, SEO, social media and business software for small, owner-managed businesses across West Yorkshire.

Next step

Let's get your business seen.

Get a free Blueprint with a clear plan, honest pricing and no jargon.

Tell us which task takes too much time and we'll assess a focused software or automation project. Business software and automation

Prefer to talk it through? Contact Fixby Studios, email info@fixbystudios.co.uk or call 07737 067552.

Related reading