๐Ÿ“… Book a 30-min Demo๐Ÿ“ž Call/text (571) 293-0242
Small Business ยท AI Course ยท SB-9

Small Business AI Security and Customer Data Basics

The security work you genuinely have to do before pointing AI at customer data โ€” access control, vendor terms, state privacy law, and a one-page breach plan.

Last updated:

The Short Answer

Small businesses hold real customer data, have no security staff, and AI adoption widens the exposure. ibl.ai answers the vendor question that matters most โ€” your data is not used to train anyone's model, because you own all the code and the data and it runs where you put it.

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing โ€” so you can deploy anywhere, from your own cloud to a fully air-gapped network.

The full course design is published below โ€” every module, its objectives and hands-on activity, the capstone, and every source it cites.

What is this course about?

Small businesses hold real customer data and have no security staff, and AI adoption increases the exposure. This course covers what you actually hold and where, the one vendor question that matters most, offboarding when someone leaves, the state privacy laws that reach far smaller businesses than owners assume, and a breach plan that fits on a page.

Who is this course for?

  • Owner-operators
  • Office and operations managers
  • Anyone responsible for customer data in a small firm
  • Bookkeepers and administrators with system access

What do I need before starting?

  • A list of the software your business uses
  • No technical background required

What will I be able to do afterwards?

  • Inventory what customer data you hold and where it lives
  • Ask AI vendors the one question that matters most
  • Control access and offboard departing staff completely
  • Determine which state privacy laws apply to your business
  • Write a breach response plan that fits on one page

What does each module cover?

1

What data do you actually hold?

35 min

The inventory that reveals data in places nobody remembered.

Objectives

  • Inventory customer data across every system
  • Find data in personal accounts and old exports
  • Classify by sensitivity

Topics

Data inventoryShadow storagePersonal account riskSensitivity classification

Activity. Build the inventory and find at least one place you had forgotten about.

2

Is your data training their model?

35 min

The single vendor question that separates acceptable AI tools from unacceptable ones.

Objectives

  • Locate training-rights terms in vendor agreements
  • Interpret ambiguous language correctly
  • Decide what to do when the terms are unacceptable

Topics

Training rightsAmbiguous termsFree tier differencesDecision criteria

Activity. Check the training terms for every AI tool your business currently uses.

3

Who has access to what?

35 min

Access control in a business where everyone has always had everything.

Objectives

  • Map current access across systems
  • Reduce access to what each role needs
  • Handle shared accounts

Topics

Access mappingLeast privilegeShared accountsRole definition

Activity. Map access and remove at least three unnecessary grants.

4

What happens when someone leaves?

30 min

Offboarding that actually removes access, including the accounts nobody tracks.

Objectives

  • Build a complete offboarding checklist
  • Cover personal devices and shared credentials
  • Verify removal rather than assuming it

Topics

Offboarding checklistCredential rotationPersonal devicesVerification

Activity. Build the checklist and run it against your last departure to find what was missed.

5

Which privacy laws apply to a business your size?

35 min

State privacy laws reach far smaller businesses than most owners assume.

Objectives

  • Determine which state laws apply to you
  • Identify obligations triggered by your data volume
  • Handle multi-state customer bases

Topics

State law thresholdsApplicability analysisMulti-state operationConsumer rights

Activity. Determine which state laws apply given your customer base.

6

How do you stay out of PCI scope?

30 min

Payment data handling that keeps compliance burden minimal by not touching card data.

Objectives

  • Understand what brings you into PCI scope
  • Structure payments to minimize scope
  • Avoid the practices that expand it

Topics

PCI scopeScope minimizationPayment processor structureScope-expanding practices

Activity. Assess your payment flow for anything that expands PCI scope.

7

How are small businesses actually attacked?

35 min

Phishing, invoice fraud, and social engineering โ€” the attacks that hit businesses this size.

Objectives

  • Recognize the attacks aimed at small businesses
  • Implement controls proportionate to the risk
  • Train staff on the specific patterns

Topics

PhishingInvoice and payment fraudSocial engineeringProportionate controls

Activity. Run a tabletop on an invoice fraud attempt and check where it would have succeeded.

8

Writing a one-page breach plan

35 min

The plan that gets used because it is short enough to read during an incident.

Objectives

  • Write a one-page response plan
  • Identify who to call before you need them
  • Know your notification obligations

Topics

One-page planContact listNotification obligationsEvidence preservation

Activity. Write the one-page plan and test it in a five-minute tabletop.

What is the capstone project?

Small business data and AI security package

Produce a complete data inventory, an AI vendor review covering every tool in use, a reduced-access map, an offboarding checklist verified against a real departure, an applicable-law determination, and a one-page breach plan.

Deliverable: A security package a small business can maintain without dedicated staff.

How are learners assessed?

  • Inventory must surface at least one forgotten data location
  • Vendor review completed for every AI tool currently in use
  • Breach plan tested in a timed tabletop

What ships with the course?

Facilitator guide

Session-by-session running order, discussion prompts, and the questions that reliably derail a room.

Learner workbook

Exercises, checklists, and the templates each module's activity produces.

Hands-on lab environment

A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.

Assessment bank

Scenario questions and rubric criteria mapped to each stated learning outcome.

Source bibliography

Every primary regulation and standard cited on this page, linked and dated.

Which AI agents does this course use?

The hands-on modules run against agents already deployable on the ibl.ai platform for small business.

Where does the course material come from?

Every module is grounded in primary sources โ€” the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

Delivery notes

Binding guidance for anyone preparing and delivering this course.

  • Every control must be achievable without dedicated security staff. A course that recommends enterprise controls to a five-person business will be abandoned in the first module.
  • Module 5's applicability analysis must be current โ€” state privacy laws are added and amended annually and thresholds vary. Re-verify at each revision.
  • Module 7 should use real attack patterns aimed at businesses this size. Enterprise threat material does not describe what actually happens to small firms.
  • The one-page constraint in Module 8 is the point. Longer plans are not read during an incident, and the exercise should force cutting.
  • Recommend legal review for the applicability determination. Owners should not conclude a state law does not apply based on a course.

Why run AI training on a platform you own?

You own the course, not a licence to it

Course content, learner data, and the platform run inside your perimeter โ€” you own all the code and the data.

Model-agnostic delivery

Run the course's AI components on any LLM โ€” Claude, GPT, Llama, Gemini, Command โ€” and switch anytime.

No per-seat training licences

Usage-based or self-hosted, so cost tracks actual use rather than headcount.

Deploy anywhere

Cloud, private VPC, on-premise, or fully air-gapped โ€” including for cohorts that cannot use public AI tools.

Frequently asked questions

What does the Small Business AI Security and Customer Data Basics course cover?

Small businesses hold real customer data and have no security staff, and AI adoption increases the exposure. This course covers what you actually hold and where, the one vendor question that matters most, offboarding when someone leaves, the state privacy laws that reach far smaller businesses than owners assume, and a breach plan that fits on a page. It runs 3.5 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: Small business data and AI security package.

Who should take Small Business AI Security and Customer Data Basics?

It is written for Owner-operators, Office and operations managers, Anyone responsible for customer data in a small firm, Bookkeepers and administrators with system access. Prerequisites: A list of the software your business uses; No technical background required.

Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere โ€” cloud, private VPC, on-premise, or fully air-gapped โ€” and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for small business teams that cannot send work to a public AI tool.

How do we get access to Small Business AI Security and Customer Data Basics?

Request access and we will set it up for your cohort โ€” hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

How much does AI training for small business cost on ibl.ai?

There is no per-seat pricing โ€” you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

More Small Business courses

See all Small Business courses

Request access to Small Business AI Security and Customer Data Basics

Tell us about your cohort and we will set it up โ€” hosted by ibl.ai, or running against your own deployment, where you own all the code and the data.