# Small Business AI Security and Customer Data Basics

> Small Business · AI Course · SB-9
> Source: https://ibl.ai/solutions/small-business/course/small-business-ai-security
> Last updated: 2026-08-25

**The security work you genuinely have to do before pointing AI at customer data — access control, vendor terms, state privacy law, and a one-page breach plan.**

## The Short Answer

**Small businesses hold real customer data, have no security staff, and AI adoption widens the exposure. ibl.ai answers the vendor question that matters most — your data is not used to train anyone's model, because you own all the code and the data and it runs where you put it.**

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

[Request Access](https://ibl.ai/contact) · [Explore Small Business](https://ibl.ai/solutions/small-business)

## Course facts

- **Level:** Foundational
- **Duration:** 3.5 hours across 8 modules
- **Format:** Self-paced with an audit lab
- **Modules:** 8
- **Catalog code:** SB-9
- **Frameworks covered:** State privacy law, PCI DSS, GLBA, NIST small business guidance

## What is this course about?

Small businesses hold real customer data and have no security staff, and AI adoption increases the exposure. This course covers what you actually hold and where, the one vendor question that matters most, offboarding when someone leaves, the state privacy laws that reach far smaller businesses than owners assume, and a breach plan that fits on a page.

## Who is this course for?

- Owner-operators
- Office and operations managers
- Anyone responsible for customer data in a small firm
- Bookkeepers and administrators with system access

### What do I need before starting?

- A list of the software your business uses
- No technical background required

## What will I be able to do afterwards?

- Inventory what customer data you hold and where it lives
- Ask AI vendors the one question that matters most
- Control access and offboard departing staff completely
- Determine which state privacy laws apply to your business
- Write a breach response plan that fits on one page

## What does each module cover?

### Module 1 — What data do you actually hold?

The inventory that reveals data in places nobody remembered. _(35 min)_

**Objectives**

- Inventory customer data across every system
- Find data in personal accounts and old exports
- Classify by sensitivity

**Topics:** Data inventory · Shadow storage · Personal account risk · Sensitivity classification

**Activity:** Build the inventory and find at least one place you had forgotten about.

### Module 2 — Is your data training their model?

The single vendor question that separates acceptable AI tools from unacceptable ones. _(35 min)_

**Objectives**

- Locate training-rights terms in vendor agreements
- Interpret ambiguous language correctly
- Decide what to do when the terms are unacceptable

**Topics:** Training rights · Ambiguous terms · Free tier differences · Decision criteria

**Activity:** Check the training terms for every AI tool your business currently uses.

### Module 3 — Who has access to what?

Access control in a business where everyone has always had everything. _(35 min)_

**Objectives**

- Map current access across systems
- Reduce access to what each role needs
- Handle shared accounts

**Topics:** Access mapping · Least privilege · Shared accounts · Role definition

**Activity:** Map access and remove at least three unnecessary grants.

### Module 4 — What happens when someone leaves?

Offboarding that actually removes access, including the accounts nobody tracks. _(30 min)_

**Objectives**

- Build a complete offboarding checklist
- Cover personal devices and shared credentials
- Verify removal rather than assuming it

**Topics:** Offboarding checklist · Credential rotation · Personal devices · Verification

**Activity:** Build the checklist and run it against your last departure to find what was missed.

### Module 5 — Which privacy laws apply to a business your size?

State privacy laws reach far smaller businesses than most owners assume. _(35 min)_

**Objectives**

- Determine which state laws apply to you
- Identify obligations triggered by your data volume
- Handle multi-state customer bases

**Topics:** State law thresholds · Applicability analysis · Multi-state operation · Consumer rights

**Activity:** Determine which state laws apply given your customer base.

### Module 6 — How do you stay out of PCI scope?

Payment data handling that keeps compliance burden minimal by not touching card data. _(30 min)_

**Objectives**

- Understand what brings you into PCI scope
- Structure payments to minimize scope
- Avoid the practices that expand it

**Topics:** PCI scope · Scope minimization · Payment processor structure · Scope-expanding practices

**Activity:** Assess your payment flow for anything that expands PCI scope.

### Module 7 — How are small businesses actually attacked?

Phishing, invoice fraud, and social engineering — the attacks that hit businesses this size. _(35 min)_

**Objectives**

- Recognize the attacks aimed at small businesses
- Implement controls proportionate to the risk
- Train staff on the specific patterns

**Topics:** Phishing · Invoice and payment fraud · Social engineering · Proportionate controls

**Activity:** Run a tabletop on an invoice fraud attempt and check where it would have succeeded.

### Module 8 — Writing a one-page breach plan

The plan that gets used because it is short enough to read during an incident. _(35 min)_

**Objectives**

- Write a one-page response plan
- Identify who to call before you need them
- Know your notification obligations

**Topics:** One-page plan · Contact list · Notification obligations · Evidence preservation

**Activity:** Write the one-page plan and test it in a five-minute tabletop.

## What is the capstone project?

**Small business data and AI security package.** Produce a complete data inventory, an AI vendor review covering every tool in use, a reduced-access map, an offboarding checklist verified against a real departure, an applicable-law determination, and a one-page breach plan.

_Deliverable:_ A security package a small business can maintain without dedicated staff.

## How are learners assessed?

- Inventory must surface at least one forgotten data location
- Vendor review completed for every AI tool currently in use
- Breach plan tested in a timed tabletop

## What ships with the course?

- **Facilitator guide.** Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
- **Learner workbook.** Exercises, checklists, and the templates each module's activity produces.
- **Hands-on lab environment.** A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
- **Assessment bank.** Scenario questions and rubric criteria mapped to each stated learning outcome.
- **Source bibliography.** Every primary regulation and standard cited on this page, linked and dated.

## Which AI agents does this course use?

- [Bookkeeping Agent](https://ibl.ai/solutions/small-business/agent/bookkeeping-agent)
- [Customer Support Agent](https://ibl.ai/solutions/small-business/agent/customer-support-agent)
- [Invoicing Agent](https://ibl.ai/solutions/small-business/agent/invoicing-agent)
- [Onboarding Agent](https://ibl.ai/solutions/small-business/agent/onboarding-agent)

## Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

- [Small Business Cybersecurity Corner](https://www.nist.gov/itl/smallbusinesscyber) — NIST. The baseline control guidance this course is built around.
- [Gramm-Leach-Bliley Act guidance](https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act) — Federal Trade Commission. Safeguards obligations for businesses handling financial information.
- [U.S. State Privacy Legislation Tracker](https://iapp.org/resources/article/us-state-privacy-legislation-tracker/) — IAPP. Current state law applicability analysis in Module 5.
- [PCI Security Standards Council](https://www.pcisecuritystandards.org/) — PCI SSC. PCI scope definitions used in Module 6.

## Delivery notes

Binding guidance for anyone preparing and delivering this course:

- Every control must be achievable without dedicated security staff. A course that recommends enterprise controls to a five-person business will be abandoned in the first module.
- Module 5's applicability analysis must be current — state privacy laws are added and amended annually and thresholds vary. Re-verify at each revision.
- Module 7 should use real attack patterns aimed at businesses this size. Enterprise threat material does not describe what actually happens to small firms.
- The one-page constraint in Module 8 is the point. Longer plans are not read during an incident, and the exercise should force cutting.
- Recommend legal review for the applicability determination. Owners should not conclude a state law does not apply based on a course.

## Why run AI training on a platform you own?

- **You own the course, not a licence to it.** Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
- **Model-agnostic delivery.** Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
- **No per-seat training licences.** Usage-based or self-hosted, so cost tracks actual use rather than headcount.
- **Deploy anywhere.** Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

## Frequently asked questions

### What does the Small Business AI Security and Customer Data Basics course cover?

Small businesses hold real customer data and have no security staff, and AI adoption increases the exposure. This course covers what you actually hold and where, the one vendor question that matters most, offboarding when someone leaves, the state privacy laws that reach far smaller businesses than owners assume, and a breach plan that fits on a page. It runs 3.5 hours across 8 modules across 8 modules, at foundational level, and closes with a capstone: Small business data and AI security package.

### Who should take Small Business AI Security and Customer Data Basics?

It is written for Owner-operators, Office and operations managers, Anyone responsible for customer data in a small firm, Bookkeepers and administrators with system access. Prerequisites: A list of the software your business uses; No technical background required.

### Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for small business teams that cannot send work to a public AI tool.

### How do we get access to Small Business AI Security and Customer Data Basics?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

### How much does AI training for small business cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

## More Small Business courses

- [Your First Five AI Agents in Thirty Days](https://ibl.ai/solutions/small-business/course/first-five-ai-agents-in-30-days): A practical sequence for an owner-operator with no IT department — which five agents to deploy first, in what order, and how to tell within a month if each earns its keep.
- [AI Customer Support That Does Not Sound Like a Robot](https://ibl.ai/solutions/small-business/course/ai-customer-support-not-a-robot): Automate the first response without losing the relationship — tone, escalation thresholds, and the questions a small business should never let an agent answer.
- [AI Bookkeeping and Cash-Flow Forecasting for Owner-Operators](https://ibl.ai/solutions/small-business/course/ai-bookkeeping-cash-flow): Use AI for categorization, reconciliation, and a cash-flow forecast you can trust — plus a clear line for where your accountant still has to sign.
- [Lead Follow-Up Agents: Responding in Minutes, Not Days](https://ibl.ai/solutions/small-business/course/lead-follow-up-agents): Speed-to-lead is the highest-leverage automation a small business can make — answer every inquiry immediately without sounding automated or breaking consent law.
- [AI Marketing for Local Business: Content, Search, and Ads](https://ibl.ai/solutions/small-business/course/ai-marketing-for-local-business): Produce marketing that ranks locally and does not read as generated — local search fundamentals, review-driven content, and ad testing on a small budget.
- [Quoting and Estimating with AI for Trades and Services](https://ibl.ai/solutions/small-business/course/quoting-estimating-with-ai): Get accurate quotes out the same day — pulling from your historical jobs, current material pricing, and margin rules, with your approval before anything goes out.
