What is this course about?
Small businesses hold real customer data and have no security staff, and AI adoption increases the exposure. This course covers what you actually hold and where, the one vendor question that matters most, offboarding when someone leaves, the state privacy laws that reach far smaller businesses than owners assume, and a breach plan that fits on a page.
Who is this course for?
- Owner-operators
- Office and operations managers
- Anyone responsible for customer data in a small firm
- Bookkeepers and administrators with system access
What do I need before starting?
- A list of the software your business uses
- No technical background required
What will I be able to do afterwards?
- Inventory what customer data you hold and where it lives
- Ask AI vendors the one question that matters most
- Control access and offboard departing staff completely
- Determine which state privacy laws apply to your business
- Write a breach response plan that fits on one page
What does each module cover?
What data do you actually hold?
35 minThe inventory that reveals data in places nobody remembered.
Objectives
- Inventory customer data across every system
- Find data in personal accounts and old exports
- Classify by sensitivity
Topics
Activity. Build the inventory and find at least one place you had forgotten about.
Is your data training their model?
35 minThe single vendor question that separates acceptable AI tools from unacceptable ones.
Objectives
- Locate training-rights terms in vendor agreements
- Interpret ambiguous language correctly
- Decide what to do when the terms are unacceptable
Topics
Activity. Check the training terms for every AI tool your business currently uses.
Who has access to what?
35 minAccess control in a business where everyone has always had everything.
Objectives
- Map current access across systems
- Reduce access to what each role needs
- Handle shared accounts
Topics
Activity. Map access and remove at least three unnecessary grants.
What happens when someone leaves?
30 minOffboarding that actually removes access, including the accounts nobody tracks.
Objectives
- Build a complete offboarding checklist
- Cover personal devices and shared credentials
- Verify removal rather than assuming it
Topics
Activity. Build the checklist and run it against your last departure to find what was missed.
Which privacy laws apply to a business your size?
35 minState privacy laws reach far smaller businesses than most owners assume.
Objectives
- Determine which state laws apply to you
- Identify obligations triggered by your data volume
- Handle multi-state customer bases
Topics
Activity. Determine which state laws apply given your customer base.
How do you stay out of PCI scope?
30 minPayment data handling that keeps compliance burden minimal by not touching card data.
Objectives
- Understand what brings you into PCI scope
- Structure payments to minimize scope
- Avoid the practices that expand it
Topics
Activity. Assess your payment flow for anything that expands PCI scope.
How are small businesses actually attacked?
35 minPhishing, invoice fraud, and social engineering โ the attacks that hit businesses this size.
Objectives
- Recognize the attacks aimed at small businesses
- Implement controls proportionate to the risk
- Train staff on the specific patterns
Topics
Activity. Run a tabletop on an invoice fraud attempt and check where it would have succeeded.
Writing a one-page breach plan
35 minThe plan that gets used because it is short enough to read during an incident.
Objectives
- Write a one-page response plan
- Identify who to call before you need them
- Know your notification obligations
Topics
Activity. Write the one-page plan and test it in a five-minute tabletop.
What is the capstone project?
Small business data and AI security package
Produce a complete data inventory, an AI vendor review covering every tool in use, a reduced-access map, an offboarding checklist verified against a real departure, an applicable-law determination, and a one-page breach plan.
Deliverable: A security package a small business can maintain without dedicated staff.
How are learners assessed?
- Inventory must surface at least one forgotten data location
- Vendor review completed for every AI tool currently in use
- Breach plan tested in a timed tabletop
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for small business.
Where does the course material come from?
Every module is grounded in primary sources โ the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- Small Business Cybersecurity Corner
NIST
The baseline control guidance this course is built around.
- Gramm-Leach-Bliley Act guidance
Federal Trade Commission
Safeguards obligations for businesses handling financial information.
- U.S. State Privacy Legislation Tracker
IAPP
Current state law applicability analysis in Module 5.
- PCI Security Standards Council
PCI SSC
PCI scope definitions used in Module 6.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- Every control must be achievable without dedicated security staff. A course that recommends enterprise controls to a five-person business will be abandoned in the first module.
- Module 5's applicability analysis must be current โ state privacy laws are added and amended annually and thresholds vary. Re-verify at each revision.
- Module 7 should use real attack patterns aimed at businesses this size. Enterprise threat material does not describe what actually happens to small firms.
- The one-page constraint in Module 8 is the point. Longer plans are not read during an incident, and the exercise should force cutting.
- Recommend legal review for the applicability determination. Owners should not conclude a state law does not apply based on a course.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter โ you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM โ Claude, GPT, Llama, Gemini, Command โ and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped โ including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the Small Business AI Security and Customer Data Basics course cover?
Small businesses hold real customer data and have no security staff, and AI adoption increases the exposure. This course covers what you actually hold and where, the one vendor question that matters most, offboarding when someone leaves, the state privacy laws that reach far smaller businesses than owners assume, and a breach plan that fits on a page. It runs 3.5 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: Small business data and AI security package.
Who should take Small Business AI Security and Customer Data Basics?
It is written for Owner-operators, Office and operations managers, Anyone responsible for customer data in a small firm, Bookkeepers and administrators with system access. Prerequisites: A list of the software your business uses; No technical background required.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere โ cloud, private VPC, on-premise, or fully air-gapped โ and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for small business teams that cannot send work to a public AI tool.
How do we get access to Small Business AI Security and Customer Data Basics?
Request access and we will set it up for your cohort โ hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for small business cost on ibl.ai?
There is no per-seat pricing โ you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.