<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>The Proton Blog</title><description>News from the front lines of privacy and security</description><link>https://proton.me/</link><language>en</language><feed_url>https://proton.me/feed</feed_url><item><title>How to know if you have a virus on your phone</title><link>https://proton.me/blog/phone-virus</link><guid isPermaLink="true">https://proton.me/blog/phone-virus</guid><description>We look at how to know if you have a virus or other malware on your phone and what you can do to clean your phone.</description><pubDate>Fri, 12 Jun 2026 11:55:30 GMT</pubDate><content:encoded>
&lt;p&gt;If your phone is behaving in unusual ways, like unexpected data usage spikes or rapid battery drain, there’s a chance it might have a virus. Here are some of the telltale signs that your phone is infected, what you can do to clean it, and how to ensure your phone is protected in the future.&amp;nbsp;&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#what&quot;&gt;What is a phone virus?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#signs&quot;&gt;Signs your phone has a virus&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#check&quot;&gt;How to check if your phone has a virus&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#antivirus-software&quot;&gt;Should you use additional antivirus software?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#protect&quot;&gt;How to protect your phone from viruses&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;what&quot;&gt;What is a phone virus?&lt;/h2&gt;



&lt;p&gt;A phone virus is a type of software that is designed to spread throughout the files, apps, and data on your phone. Once a user opens an infected file the virus can infect the host and set out to replicate itself, infecting other files and devices in the same way a biological virus infects other people who come into contact with the host.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;Many people use the terms “virus” and “malware” interchangeably, but a virus is a &lt;em&gt;type&lt;/em&gt; of &lt;a href=&quot;https://protonvpn.com/blog/what-is-malware&quot;&gt;malware&lt;/a&gt;. Malware is an umbrella term for software that steals, disrupts, or deletes data, and also includes things like &lt;a href=&quot;https://proton.me/blog/what-is-ransomware&quot;&gt;ransomware&lt;/a&gt; and spyware.&amp;nbsp;&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;signs&quot;&gt;Signs your phone has a virus&lt;/h2&gt;



&lt;p&gt;There are a number of symptoms that might indicate your phone has a virus.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Unusual performance issues&lt;/h3&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Rapid battery drain:&lt;/strong&gt; Your battery life has suddenly dropped without a change in your usage habits.&amp;nbsp;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Overheating:&lt;/strong&gt; Your phone feels hot to the touch, even when you aren&amp;#8217;t using energy-intensive apps like games or video streaming.&amp;nbsp;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Sluggish performance:&lt;/strong&gt; Apps take a long time to open, the home screen freezes, or your phone lags significantly when scrolling or typing.&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;em&gt;Malware often runs hidden background processes, draining your battery and slowing down your device. If your phone feels sluggish or hot when you’re not&amp;nbsp; performing processor-intensive tasks, it&amp;#8217;s a major red flag.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Strange data or billing activity&lt;/h3&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Spike in data usage: &lt;/strong&gt;You experience an unexplained jump in cellular or Wi-Fi data consumption.&amp;nbsp;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Mysterious charges: &lt;/strong&gt;Your phone bill shows premium SMS messages you didn’t send, unexpected subscriptions, or calls to unknown international numbers.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;em&gt;Malware often sends data to remote servers or joins your device to a botnet; a group of internet-connected devices that have been breached and are being controlled by a third party, often to perform &lt;/em&gt;&lt;a href=&quot;https://protonvpn.com/blog/types-of-cyberattacks#ddos&quot;&gt;&lt;em&gt;DDoS attacks&lt;/em&gt;&lt;/a&gt;&lt;em&gt;. &lt;/em&gt;&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/toll-fraud-malware-disables-your-wifi-to-force-premium-subscriptions/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;&lt;em&gt;Toll fraud&lt;/em&gt;&lt;/a&gt;&lt;em&gt; is a type of malware that is predominantly used to target Android systems. Users are secretly subscribed to premium-rate SMS or telephone services, racking up charges without their knowledge or consent.&amp;nbsp;&amp;nbsp;&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Pop-ups and ads&lt;/h3&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Unexpected advertising:&lt;/strong&gt; You have ads popping up on your home screen, inside apps where they shouldn&amp;#8217;t be, or even when your browser is closed.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;em&gt;These ads are likely what’s known as adware, and can slow down your device. Adware often gets downloaded automatically with “free” software.&lt;/em&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Fake security alerts:&lt;/strong&gt; You’re seeing pop-ups and alerts claiming your phone is infected and urging you to download a &amp;#8220;cleaner&amp;#8221; app.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;em&gt;These alerts are almost always scams designed to install more malware.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;App behavior anomalies&lt;/h3&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Unknown apps:&lt;/strong&gt; You notice apps installed on your device that you don&amp;#8217;t remember downloading.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Apps crashing frequently:&lt;/strong&gt; Legitimate apps start crashing or freezing unexpectedly.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Unusual permissions:&lt;/strong&gt; Apps are requesting permissions they don&amp;#8217;t need, such as access to contacts, camera, or microphone.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;em&gt;These irregularities could indicate that malicious software is masquerading as legitimate apps, hijacking system resources, or seeking access to your private data.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Network and connectivity issues&lt;/h3&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Slow internet speeds:&lt;/strong&gt; Your connection seems slower than usual, even on strong WiFi.&amp;nbsp;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Random reboots: &lt;/strong&gt;Your phone restarts itself without your input.&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;em&gt;Hidden malware processes frequently consume your bandwidth to transmit stolen data or join botnets, causing slowdowns and system instability that triggers unexpected restarts.&lt;/em&gt;&lt;/p&gt;



&lt;p&gt;It should be noted that many of these issues can also be caused by aging hardware, software bugs, or simply by too many apps running in the background, rather than a virus. Regardless of the cause, there are steps you can take to resolve the underlying issue.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;check&quot;&gt;How to check if your phone has a virus&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Android phone virus checks&lt;/h3&gt;



&lt;p&gt;&lt;a href=&quot;https://support.google.com/pixelphone/answer/2812853?hl=en&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Google Play Protect&lt;/a&gt; is your first line of defense against viruses and malware on Android devices. &lt;strong&gt;Play Protect runs continuously in the background&lt;/strong&gt; and performs several types of automatic scans:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;App installation scan&lt;/strong&gt;: Every time you install an app from Google Play Store.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Periodic device scan&lt;/strong&gt;: Automatically checks all installed apps regularly (usually daily or weekly).&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Web protection&lt;/strong&gt;: Scans websites you visit through Chrome for known threats.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Harmful app removal&lt;/strong&gt;: Can automatically uninstall detected malware.&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;Automatic scans happen as long as Play Protect is enabled, which it is by default on most devices.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Manual Play Protect scan&lt;/h4&gt;



&lt;p&gt;You can trigger a &lt;strong&gt;manual scan&lt;/strong&gt; any time you want by following these steps:&amp;nbsp;&lt;/p&gt;



&lt;p&gt;1. Open the Google Play Store app.&lt;/p&gt;



&lt;p&gt;2. Tap your profile icon.&lt;/p&gt;



&lt;p&gt;3. Select &lt;strong&gt;Play Protect&lt;/strong&gt;.&lt;/p&gt;



&lt;p&gt;4. Tap &lt;strong&gt;Scan&lt;/strong&gt; to run an immediate check.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;400&quot; height=&quot;724&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_400,h_724,c_scale/f_auto,q_auto/v1781256088/wp-pme/android-scan/android-scan.png?_i=AA&quot; alt=&quot;Manual Play Protect scan on an Android phone
&quot; class=&quot;wp-post-153893 wp-image-153957&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;66 KB&quot; data-optsize=&quot;18 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;72&quot; data-version=&quot;1781256088&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1781256088/wp-pme/android-scan/android-scan.png?_i=AA 400w, https://res.cloudinary.com/dbulfrlrz/images/w_166,h_300,c_scale/f_auto,q_auto/v1781256088/wp-pme/android-scan/android-scan.png?_i=AA 166w&quot; sizes=&quot;auto, (max-width: 400px) 100vw, 400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p&gt;This is useful if you&amp;#8217;ve recently installed an app from outside the Play Store (known as sideloading) or if you&amp;#8217;re experiencing suspicious behavior.&lt;/p&gt;



&lt;p&gt;While Play Protect is helpful, it&amp;#8217;s not foolproof. Because it’s not a full antivirus tool, it may struggle to recognize new malware variants. It may also give false negatives in some cases.&amp;nbsp;&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Review app permissions&lt;/h4&gt;



&lt;p&gt;Review which apps have access to your information by using Permission Manager.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;1. Go to &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;Security and Privacy&lt;/strong&gt; → &lt;strong&gt;More privacy settings&lt;/strong&gt; → &lt;strong&gt;Permission Manager&lt;/strong&gt;.&lt;/p&gt;



&lt;p&gt;2. Revoke access for any apps that don&amp;#8217;t need it.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Use a third-party anti-virus app&lt;/h3&gt;



&lt;p&gt;You can download antivirus and anti-malware apps from the Play Store. Just be sure to only download apps from reputable vendors. See Should you use additional antivirus software? below for more details.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;iPhone virus check&lt;/h3&gt;



&lt;p&gt;Because of how iOS is designed, traditional antivirus apps that scan your entire file system for malware don’t exist on the App Store (and Apple wouldn&amp;#8217;t allow them to function that way anyway). Instead, iOS’s architecture protects you from phone viruses by ensuring that:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Apps are sandboxed&lt;/strong&gt;: Every app on an iPhone runs in its own isolated sandbox. An app can’t access the files, data, or code of another app.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Apps are reviewed:&lt;/strong&gt; Apple manually reviews every app before it reaches the App Store. While bad actors sometimes slip through, it’s extremely rare.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Apps can’t be sideloaded:&lt;/strong&gt; &lt;a href=&quot;https://developer.apple.com/support/dma-and-apps-in-the-eu/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Outside the EU&lt;/a&gt;, you can only install apps from the App Store, which drastically reduces infection risk (unless you’ve jailbroken your phone).&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;To do a &lt;strong&gt;manual diagnosis and cleanup&lt;/strong&gt;, try these steps:&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Do a safety check (iPhone with iOS 16 or later)&lt;/h4&gt;



&lt;p&gt;Review which people and apps have access to your information and devices by using &lt;strong&gt;Safety Check&lt;/strong&gt;.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;1. Go to &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;Privacy &amp;amp; Security&lt;/strong&gt; → &lt;strong&gt;Safety Check&amp;nbsp; &lt;/strong&gt;→ &lt;strong&gt;Manage Sharing &amp;amp; Access&lt;/strong&gt;.&lt;/p&gt;



&lt;p&gt;2. Follow the steps to reset or manage access to your information.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;400&quot; height=&quot;679&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_400,h_679,c_scale/f_auto,q_auto/v1781257005/wp-pme/ios-safety-check/ios-safety-check.png?_i=AA&quot; alt=&quot;Perform a safety check on iOS&quot; class=&quot;wp-post-153893 wp-image-154002&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;105 KB&quot; data-optsize=&quot;28 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;73&quot; data-version=&quot;1781257005&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1781257005/wp-pme/ios-safety-check/ios-safety-check.png?_i=AA 400w, https://res.cloudinary.com/dbulfrlrz/images/w_177,h_300,c_scale/f_auto,q_auto/v1781257005/wp-pme/ios-safety-check/ios-safety-check.png?_i=AA 177w&quot; sizes=&quot;auto, (max-width: 400px) 100vw, 400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h4 class=&quot;wp-block-heading&quot;&gt;Clear Safari data&amp;nbsp;&lt;/h4&gt;



&lt;p&gt;What seems like malware is often “just” adware or browser redirects trapped in your Safari cache.&lt;/p&gt;



&lt;p&gt;1. Go to &lt;strong&gt;Settings &lt;/strong&gt;→&lt;strong&gt;Apps &lt;/strong&gt;→ &lt;strong&gt;Safari&lt;/strong&gt;.&lt;/p&gt;



&lt;p&gt;2. Scroll down and tap &lt;strong&gt;Clear History and Website Data&lt;/strong&gt;.&lt;/p&gt;



&lt;p&gt;This removes cookies and cached scripts that might be causing pop-ups.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;400&quot; height=&quot;691&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_400,h_691,c_scale/f_auto,q_auto/v1781257001/wp-pme/ios-clear-history/ios-clear-history.png?_i=AA&quot; alt=&quot;Clear history and website data on iOS&quot; class=&quot;wp-post-153893 wp-image-153981&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;85 KB&quot; data-optsize=&quot;22 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;74.6&quot; data-version=&quot;1781257001&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1781257001/wp-pme/ios-clear-history/ios-clear-history.png?_i=AA 400w, https://res.cloudinary.com/dbulfrlrz/images/w_174,h_300,c_scale/f_auto,q_auto/v1781257001/wp-pme/ios-clear-history/ios-clear-history.png?_i=AA 174w&quot; sizes=&quot;auto, (max-width: 400px) 100vw, 400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h4 class=&quot;wp-block-heading&quot;&gt;Review configuration profiles&lt;/h4&gt;



&lt;p&gt;Malware sometimes installs a configuration profile to force settings changes or redirect traffic.&lt;/p&gt;



&lt;p&gt;1. Go to &lt;strong&gt;Settings &lt;/strong&gt;→&lt;strong&gt; General &lt;/strong&gt;→&lt;strong&gt; VPN &amp;amp; Device Management.&lt;/strong&gt;&lt;/p&gt;



&lt;p&gt;2. From here:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;If you don’t see any profiles, then no device management profiles are installed on your device.&lt;/li&gt;



&lt;li&gt;If you do see unfamiliar profiles, select the profile, tap &lt;strong&gt;Delete Profile&lt;/strong&gt; and follow the instructions, then restart your device.&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Do a factory reset&lt;/h4&gt;



&lt;p&gt;If you still suspect a virus, you can &lt;a href=&quot;https://support.apple.com/en-us/118107&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;restore your phone to factory settings&lt;/a&gt;. This will completely wipe your phone and enable you to set it up again as new.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;&lt;em&gt;Warning: Before resetting, follow &lt;/em&gt;&lt;/strong&gt;&lt;a href=&quot;https://support.apple.com/en-us/118426&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;&lt;strong&gt;&lt;em&gt;Apple’s recommended steps &lt;/em&gt;&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;em&gt;to ensure you’ve backed up your phone correctly.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;antivirus-software&quot;&gt;Should you use additional antivirus software?&lt;/h2&gt;



&lt;p&gt;Regardless of whether you have an Android or iOS device, good security habits are generally sufficient to prevent phone viruses. However, you could consider additional antivirus software if you:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Frequently sideload apps (Android devices)&lt;/li&gt;



&lt;li&gt;Download files from untrusted sources&lt;/li&gt;



&lt;li&gt;Handle sensitive financial or business data on your phone&lt;/li&gt;



&lt;li&gt;Want extra peace of mind&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;Popular options include Bitdefender, Malwarebytes, Norton, and Kaspersky.&lt;/p&gt;



&lt;p&gt;If you have an Android device, these apps can actively scan files, monitor app behavior, and block malicious downloads in real-time.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;However, if you’re an iPhone user, these apps won’t scan for viruses in the traditional sense. Instead, they focus heavily on web protection (blocking phishing sites), Wi-Fi security, and identity theft monitoring, so iPhone users may prefer to opt for other protections.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;protect&quot;&gt;How to protect your phone from viruses&lt;/h2&gt;



&lt;p&gt;Maximizing phone security requires a layered approach. Combining the built-in security measures of your phone with a password manager and a VPN creates a strong line of defense against phishing, credential theft, and network surveillance.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Set up automatic updates&lt;/h3&gt;



&lt;p&gt;Automatic software updates ensure that Apple and Google can swiftly patch critical vulnerabilities.&amp;nbsp;&amp;nbsp;&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;iPhone software updates&lt;/h4&gt;



&lt;p&gt;1. Select &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;General&lt;/strong&gt; → &lt;strong&gt;Software Update&lt;/strong&gt;.&lt;/p&gt;



&lt;p&gt;2. Toggle on &lt;strong&gt;Automatic Updates&lt;/strong&gt;.&lt;/p&gt;



&lt;p&gt;You can also turn on Background Security Improvements to provide additional protection in between software updates.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;1. Select &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;Privacy &amp;amp; Security&lt;/strong&gt; → &lt;strong&gt;Background Security Improvements&lt;/strong&gt;.&lt;/p&gt;



&lt;p&gt;2. Toggle on &lt;strong&gt;Automatically Install&lt;/strong&gt;.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Android software updates&lt;/h4&gt;



&lt;p&gt;1. Go to &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;System&lt;/strong&gt; → &lt;strong&gt;System Update&lt;/strong&gt; and enable automatic updates.&lt;/p&gt;



&lt;p&gt;2. Disable &lt;strong&gt;Install Unknown Apps&lt;/strong&gt; (keep this setting off for all apps unless absolutely necessary).&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Install a password manager&lt;/h3&gt;



&lt;p&gt;A password manager generates and stores unique, complex passwords for every account, eliminating the single biggest cause of breaches: password reuse. It also guards against credential stuffing and phishing by autofilling credentials only on legitimate sites.&lt;/p&gt;



&lt;p&gt;Proton Pass protects your logins with zero-knowledge, end-to-end encryption and goes further with built-in 2FA authenticator codes, unlimited hide-my-email aliases to shield your identity, and Dark Web Monitoring that alerts you if your credentials are leaked.&lt;/p&gt;



&lt;div class=&quot;text-center&quot;&gt;&lt;a class=&quot;inline-block py-2 px-4 rounded-full no-underline font-bold bg-purple-500 text-white hover:text-white focus:text-white&quot; href=&quot;https://proton.me/pass/pricing&quot;&gt;Get Proton Pass&lt;/a&gt;&lt;/div&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Use a VPN&lt;/h3&gt;



&lt;p&gt;A VPN encrypts your internet traffic, shielding it from &lt;a href=&quot;https://protonvpn.com/blog/isp/&quot;&gt;ISPs&lt;/a&gt; and other third parties. It also hides your IP address so websites and trackers can&amp;#8217;t identify or profile you.&lt;/p&gt;



&lt;p&gt;Proton VPN is open-source and independently audited, with a strict no-logs policy backed by Swiss privacy law. If you have a Plus plan, our &lt;a href=&quot;https://protonvpn.com/blog/netshield-ad-blocker&quot;&gt;NetShield Ad-blocker&lt;/a&gt; DNS filtering solution can block connections to adware and malware domains&lt;/p&gt;



&lt;div class=&quot;text-center&quot;&gt;&lt;a class=&quot;inline-block py-2 px-4 rounded-full no-underline font-bold bg-purple-500 text-white hover:text-white focus:text-white&quot; href=&quot;/pricing/&quot;&gt;Get Proton VPN Plus&lt;/a&gt;&lt;/div&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Stay legit&lt;/h3&gt;



&lt;p&gt;If you’re on Android, &lt;strong&gt;stick to apps available in the Google Play Store or a reputable app store like &lt;/strong&gt;&lt;a href=&quot;https://protonvpn.com/blog/what-is-f-droid&quot;&gt;&lt;strong&gt;F-droid&lt;/strong&gt;&lt;/a&gt;. If you do need to sideload an app, only download APKs from the developer’s official website and verify where possible. If you’re on an iPhone, &lt;strong&gt;don’t jailbreak your phone&lt;/strong&gt;. This opens you up to viruses and other malware, and negates many of the protections that Apple products otherwise offer.&amp;nbsp;&lt;/p&gt;
</content:encoded><category>Privacy guides</category><author>Jessica Bernard</author></item><item><title>The law that lets the US government spy without warrants is about to expire.
Here’s what comes next</title><link>https://proton.me/blog/fisa-702-expiring-surveillance-reform</link><guid isPermaLink="true">https://proton.me/blog/fisa-702-expiring-surveillance-reform</guid><description>Congress has all but assured the warrantless surveillance law will lapse. The fight for surveillance reform now has real leverage.</description><pubDate>Thu, 11 Jun 2026 23:06:04 GMT</pubDate><content:encoded>
&lt;p&gt;&lt;a href=&quot;https://proton.me/blog/us-warrantless-surveillance#section-702-loophole&quot;&gt;Section 702 of the Foreign Intelligence Surveillance Act&lt;/a&gt; lets US intelligence agencies collect communications from foreigners abroad without a warrant, and routinely sweeps in Americans&amp;#8217; emails, messages, and calls in the process. &lt;/p&gt;



&lt;p&gt;It’s set to expire Saturday. And Congress has all but assured it will.&lt;/p&gt;



&lt;p&gt;In a &lt;a href=&quot;https://www.nytimes.com/2026/06/11/us/politics/house-spy-program-bill.html&quot;&gt;218-to-198 vote&lt;/a&gt;, the House rejected a short-term extension, and Senate Democrats blocked a parallel effort hours later. For years, a growing bloc in both parties had demanded one thing before agreeing to renew: a warrant requirement. On Thursday, they finally had the votes to hold the line. Speaker Mike Johnson called the lapse &amp;#8220;dangerous, and very, very shameful.&amp;#8221;&lt;/p&gt;



&lt;p&gt;Privacy advocates have argued for years that renewing Section 702 without reform is the real danger. &lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1074&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1074,c_scale/f_auto,q_auto/v1737756597/wp-pme/section702/section702.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-153516 wp-image-81895&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;2 MB&quot; data-optsize=&quot;83 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;95.4&quot; data-version=&quot;1737756597&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1737756597/wp-pme/section702/section702.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_134,c_scale/f_auto,q_auto/v1737756597/wp-pme/section702/section702.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_458,c_scale/f_auto,q_auto/v1737756597/wp-pme/section702/section702.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_344,c_scale/f_auto,q_auto/v1737756597/wp-pme/section702/section702.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_687,c_scale/f_auto,q_auto/v1737756597/wp-pme/section702/section702.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_916,c_scale/f_auto,q_auto/v1737756597/wp-pme/section702/section702.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_702,c_scale/f_auto,q_auto/v1737756597/wp-pme/section702/section702.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h2 class=&quot;wp-block-heading&quot;&gt;Surveillance doesn&amp;#8217;t stop when the law does&lt;/h2&gt;



&lt;p&gt;The Foreign Intelligence Surveillance Court &lt;a href=&quot;https://www.nextgov.com/policy/2026/04/judge-renews-procedures-702-surveillance-program-could-soon-lapse/412767/&quot;&gt;renewed its procedures for the Section 702 program in March&lt;/a&gt;. On Thursday, Representative Jamie Raskin said &amp;#8220;government surveillance activities will continue unchanged&amp;#8221; and that &amp;#8220;current FISA authorizations will continue unaffected, at least through March 17, 2027,&amp;#8221; &lt;a href=&quot;https://www.cbsnews.com/news/house-vote-extension-fisa-702-spy-power-bill-pulte-uproar-trump/&quot;&gt;according to CBS News&lt;/a&gt;. Even Representative Rick Crawford, the Republican chairman of the House Intelligence Committee and a supporter of renewal, confirmed the 702 database &amp;#8220;would remain available to search.&amp;#8221; The concern is that data grows stale over time, not that collection stops.&lt;/p&gt;



&lt;p&gt;The more immediate problem is that &lt;a href=&quot;https://www.cnn.com/2026/04/13/politics/fisa-section-702-suveillance-law-expiration-congress&quot;&gt;some carriers have privately warned&lt;/a&gt; they will stop cooperating once the statute lapses, fearing legal liability without an active law behind the government&amp;#8217;s requests. &lt;a href=&quot;https://www.axios.com/2026/06/11/fisa-section-702-expiration-pulte-trump-johnson&quot;&gt;Intelligence agencies and telecoms face uncertainty&lt;/a&gt; about what collection can legally continue. Reform legislation would have resolved that. Congress chose not to pass it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A warrant requirement needed three more votes&lt;/h2&gt;



&lt;p&gt;&lt;a href=&quot;https://www.axios.com/2026/06/11/fisa-section-702-expiration-pulte-trump-johnson&quot;&gt;Axios reported&lt;/a&gt; that lawmakers in both parties were close to a longer-term extension. What they couldn&amp;#8217;t agree on was whether to attach the reforms a substantial bloc of lawmakers has demanded for years.&lt;/p&gt;



&lt;p&gt;Conservative Republicans who have long pushed back on FBI abuses of the Section 702 database refused to vote for a clean renewal. Democrats who previously supported the program did the same.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;The warrant requirement is not a fringe position: when it came to a House vote in 2024, it &lt;a href=&quot;https://clerk.house.gov/Votes/2024114&quot;&gt;failed 212-212&lt;/a&gt;. This week, a clean extension couldn&amp;#8217;t reach a majority. The reform bloc, for the first time, had enough votes to block renewal outright.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1074&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1074,c_scale/f_auto,q_auto/v1737985647/wp-pme/geofencing_warrants/geofencing_warrants.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-153516 wp-image-81926&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;2 MB&quot; data-optsize=&quot;185 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;92&quot; data-version=&quot;1737985647&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1737985647/wp-pme/geofencing_warrants/geofencing_warrants.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_134,c_scale/f_auto,q_auto/v1737985647/wp-pme/geofencing_warrants/geofencing_warrants.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_458,c_scale/f_auto,q_auto/v1737985647/wp-pme/geofencing_warrants/geofencing_warrants.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_344,c_scale/f_auto,q_auto/v1737985647/wp-pme/geofencing_warrants/geofencing_warrants.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_687,c_scale/f_auto,q_auto/v1737985647/wp-pme/geofencing_warrants/geofencing_warrants.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_916,c_scale/f_auto,q_auto/v1737985647/wp-pme/geofencing_warrants/geofencing_warrants.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_702,c_scale/f_auto,q_auto/v1737985647/wp-pme/geofencing_warrants/geofencing_warrants.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h2 class=&quot;wp-block-heading&quot;&gt;Both parties expand surveillance when in power&lt;/h2&gt;



&lt;p&gt;We&amp;#8217;ve &lt;a href=&quot;https://proton.me/blog/trump-controls-nsa-fbi&quot;&gt;documented this pattern for years&lt;/a&gt;. Section 702 has grown under every administration that has touched it. The party in power defends and extends these authorities. The party out of power raises objections, until it wins.&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;https://www.history.com/this-day-in-history/october-26/george-w-bush-signs-the-patriot-act&quot;&gt;President Bush signed the Patriot Act into law on October 26, 2001&lt;/a&gt;, expanding domestic surveillance authority. Once in power, &lt;a href=&quot;https://www.washingtonpost.com/politics/patriot-act-extension-signed-into-law-despite-bipartisan-resistance-in-congress/2011/05/27/AGbVlsCH_story.html&quot;&gt;the Obama administration signed a four-year reauthorization&lt;/a&gt; of those same provisions, despite bipartisan resistance in Congress.&lt;/p&gt;



&lt;p&gt;The 2024 renewal also made this plain. As a candidate, President Trump said &lt;a href=&quot;https://proton.me/blog/trump-controls-nsa-fbi&quot;&gt;&amp;#8220;KILL FISA&amp;#8221;&lt;/a&gt; days before Congress passed a renewal that &lt;a href=&quot;https://proton.me/blog/us-warrantless-surveillance&quot;&gt;President Biden signed into law&lt;/a&gt;, expanding Section 702 by broadening which companies can be compelled to assist with surveillance. The warrant amendment failed. Surveillance expanded. Both parties voted for it.&lt;/p&gt;



&lt;p&gt;The case for reform doesn&amp;#8217;t depend on who is in office. These powers have no meaningful checks on how they are used.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;When searching Americans&amp;#8217; private communications requires no warrant, the only protection users have is whether the people in charge choose to exercise restraint.&lt;/p&gt;



&lt;p&gt;That is not a protection.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The warrant requirement is the specific reform that matters&lt;/h2&gt;



&lt;p&gt;The &lt;a href=&quot;https://www.lee.senate.gov/2026/3/lee-introduces-bipartisan-government-surveillance-reform-act&quot;&gt;Government Surveillance Reform Act&lt;/a&gt;, backed by a bipartisan coalition including senators Ron Wyden and Mike Lee, would require a warrant before agencies can search Americans&amp;#8217; data collected under Section 702.&lt;/p&gt;



&lt;p&gt;It would close the loophole that lets the government &lt;a href=&quot;https://proton.me/blog/data-brokers&quot;&gt;buy personal data from brokers&lt;/a&gt; instead of going to court, so location data and browsing history can&amp;#8217;t be purchased to avoid judicial oversight. It would also roll back the expanded definition of who can be forced to assist with surveillance, with direct implications for how &lt;a href=&quot;https://proton.me/blog/fisa-702-vpn-surveillance-risk&quot;&gt;VPN traffic is classified&lt;/a&gt; under the law.&lt;/p&gt;



&lt;p&gt;Reauthorization will come back. This time, reformers have leverage.&lt;/p&gt;
</content:encoded><category>Privacy news</category><author>Edward Komenda</author></item><item><title>Your business’s practical multi-factor authentication implementation guide</title><link>https://proton.me/business/blog/multi-factor-authentication-business</link><guid isPermaLink="true">https://proton.me/business/blog/multi-factor-authentication-business</guid><description>Learn how to plan an MFA rollout, choose the right authentication methods, reduce employee resistance, and enforce MFA across your business.</description><pubDate>Wed, 10 Jun 2026 12:05:11 GMT</pubDate><content:encoded>
&lt;p&gt;Multi-factor authentication (MFA) is no longer just a security recommendation for large enterprises. It’s one of the most practical ways for businesses to reduce the risk of &lt;a href=&quot;https://proton.me/business/blog/account-takeover-attacks&quot;&gt;account takeover&lt;/a&gt; and make stolen passwords less useful. As access to business systems spreads across cloud apps, remote teams, shared devices, and third-party platforms, MFA is becoming a more useful tool.&lt;/p&gt;



&lt;p&gt;But during implementation, IT managers face the challenge of being able to assess whether MFA is useful or effective. Making MFA work across an organization requires making a lot of decisions: Which accounts need it first? Which MFA methods should be allowed? How do you avoid employee pushback? How do you make sure MFA is actually enforced, not just encouraged?&lt;/p&gt;



&lt;p&gt;This guide is written to help your business MFA implementation work. It explains what MFA is, why passwords alone are no longer enough, how common MFA methods compare for business use, and how to roll out MFA in a way your team can adopt. It also shows how a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; with built-in 2FA support can make stronger authentication practices easier to manage at scale.&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;#what-is&quot;&gt;What is multi-factor authentication?&lt;/a&gt;&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;#why-passwords&quot;&gt;Why passwords alone are no longer sufficient&lt;/a&gt;&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;#types&quot;&gt;Types of MFA and business trade-offs&lt;/a&gt;&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;#where&quot;&gt;Where MFA implementation fails&lt;/a&gt;&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;#employee&quot;&gt;The employee resistance problem&lt;/a&gt;&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;#how-to&quot;&gt;How to roll out MFA across your business&lt;/a&gt;&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;#proton-pass&quot;&gt;How Proton Pass for Business makes MFA manageable&lt;/a&gt;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;what-is&quot;&gt;What is multi-factor authentication?&lt;/h2&gt;



&lt;p&gt;MFA is a security process that requires more than one type of identity verification to access an account. Instead of relying only on a traditional password, MFA asks for an additional factor that makes unauthorized access harder.&lt;/p&gt;



&lt;p&gt;The three common authentication factors are:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Something you know&lt;/strong&gt;, such as a password or PIN.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Something you have&lt;/strong&gt;, such as a phone, &lt;a href=&quot;https://proton.me/authenticator&quot;&gt;authenticator app&lt;/a&gt;, hardware security key, or trusted device.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Something you are&lt;/strong&gt;, such as a fingerprint or facial recognition.&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;In practice, MFA usually means an employee enters a password and then verifies the login through another method, such as a time-based code (or &lt;a href=&quot;https://proton.me/blog/totp&quot;&gt;TOTP&lt;/a&gt;), push approval, &lt;a href=&quot;https://proton.me/pass/passkeys&quot;&gt;passkey&lt;/a&gt;, or hardware key. The goal is simple: if a password is stolen, guessed, phished, or reused, the attacker still needs another factor to get in.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Multi-factor authentication in business environments&lt;/h3&gt;



&lt;p&gt;For businesses, implementing MFA is a way to strengthen account security with an additional access control, not just to replace passwords. In business environments, the challenge is deciding where those methods are most needed and how to deploy them consistently across different systems, roles, and levels of risk.&lt;/p&gt;



&lt;p&gt;Nevertheless, not all MFAs are equally strong. A code sent by SMS is better than a password alone, but it does not offer the same protection as a hardware security key or a well-implemented passkey. The right choice depends on risk, usability, device access, compliance needs, and how much administrative control your business can maintain.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;why-passwords&quot;&gt;Why passwords alone are no longer sufficient&lt;/h2&gt;



&lt;p&gt;&lt;a href=&quot;https://proton.me/pass/password-strength-tester&quot;&gt;Strong passwords&lt;/a&gt; still matter, but they are no longer enough on their own. Employees manage more accounts than ever, and attackers know that business access often begins with one compromised credential.&lt;/p&gt;



&lt;p&gt;A password can be exposed through &lt;a href=&quot;https://proton.me/blog/what-is-phishing&quot;&gt;phishing&lt;/a&gt;, &lt;a href=&quot;https://protonvpn.com/blog/what-is-malware&quot;&gt;malware&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;data breaches&lt;/a&gt;, credential stuffing, password reuse, or unsafe sharing. Once attackers have a valid username and password, their activity may look like a normal login attempt unless another layer of verification is required.&lt;/p&gt;



&lt;p&gt;This is why &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection for businesses&lt;/a&gt; needs to include credential controls, &lt;a href=&quot;https://proton.me/business/vpn/endpoint-security&quot;&gt;endpoint security&lt;/a&gt;, and employee training. A strong &lt;a href=&quot;https://proton.me/business/pass/password-policy&quot;&gt;password policy&lt;/a&gt; helps, but it can’t stop every stolen password from being tested against &lt;a href=&quot;https://proton.me/mail&quot;&gt;email&lt;/a&gt;, &lt;a href=&quot;https://proton.me/drive&quot;&gt;cloud storage&lt;/a&gt;, finance tools, admin portals, or customer systems.&lt;/p&gt;



&lt;p&gt;The financial stakes are high. &lt;a href=&quot;https://www.ibm.com/reports/data-breach&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener nofollow&quot;&gt;IBM’s 2025 Cost of a Data Breach Report&lt;/a&gt; places &lt;strong&gt;the global average cost of a data breach at $4.4 million&lt;/strong&gt;. MFA can’t eliminate breach risk, but it does reduce one of the most common paths into business systems: unauthorized access through compromised credentials.&lt;/p&gt;



&lt;p&gt;MFA is especially important for accounts that control other accounts. Email, identity providers, password managers, admin consoles, developer platforms, payroll tools, and finance systems should be treated as high priority because gaining access to them can unlock further access elsewhere.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;types&quot;&gt;Types of MFA and business trade-offs&lt;/h2&gt;



&lt;p&gt;A good MFA implementation starts with choosing the right methods. The best option is not always the same for every business, team, or system. IT managers, for example, need to balance security strength, employee usability, device availability, administrative overhead, and support needs.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;SMS one-time passwords&lt;/h3&gt;



&lt;p&gt;SMS &lt;a href=&quot;https://proton.me/blog/one-time-password&quot;&gt;one-time passwords&lt;/a&gt; (OTPs) send a code to a phone number during login. This is one of the easiest MFA methods for employees to understand, and it can be useful where better options are not available.&lt;/p&gt;



&lt;p&gt;The downside is security. &lt;a href=&quot;https://proton.me/blog/stop-using-sms&quot;&gt;SMS&lt;/a&gt; can be vulnerable to SIM swapping, interception, &lt;a href=&quot;https://proton.me/blog/what-is-social-engineering&quot;&gt;social engineering&lt;/a&gt;, and phone number recovery attacks. It also creates operational problems when employees change numbers, travel internationally, have poor reception, or use personal phones for work.&lt;/p&gt;



&lt;p&gt;For businesses, SMS OTPs are best treated as a fallback option rather than the preferred MFA method. It is still better than passwords alone, but it should not be the default for high-risk accounts.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Authenticator apps and TOTP codes&lt;/h3&gt;



&lt;p&gt;Employees open an &lt;a href=&quot;https://proton.me/authenticator&quot;&gt;authenticator app&lt;/a&gt;, such as Proton Authenticator, copy the code generated for the service they’re logging into, and then enter it during login.&lt;/p&gt;



&lt;p&gt;This is usually stronger than SMS because the code is generated on the device and doesn’t depend on the mobile network. It is also widely supported across business tools, making it a practical baseline for many MFA rollouts.&lt;/p&gt;



&lt;p&gt;The trade-off is usability and recovery. Employees need to set up the app correctly, keep access to their device, and understand how recovery works if a phone is lost or replaced. IT teams also need to create clear policies for backup codes, device changes, and offboarding.&lt;/p&gt;



&lt;p&gt;TOTPs works well as a general business MFA method, especially when paired with strong password management and clear admin processes.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Hardware security keys&lt;/h3&gt;



&lt;p&gt;Hardware security keys, such as YubiKeys, provide strong authentication because the employee must physically possess the key to gain access to business accounts. Many security keys also protect against phishing because they verify that the website itself is legitimate before completing authentication.&lt;/p&gt;



&lt;p&gt;For high-risk roles, hardware keys can be one of the strongest MFA options. They are especially useful for administrators, executives, finance teams, developers, and anyone with access to sensitive systems.&lt;/p&gt;



&lt;p&gt;The trade-off is rollout complexity. Businesses need to purchase keys, distribute them, train employees, manage backups, and handle lost or damaged devices. A hardware key strategy also needs a recovery process that doesn’t weaken the security benefit.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Passkeys&lt;/h3&gt;



&lt;p&gt;Passkeys use cryptographic authentication instead of a traditional password. In many cases, employees unlock the passkey with a fingerprint, face recognition, PIN, or device approval. The private key stays on the device, which makes passkeys more resistant to phishing than many older authentication methods.&lt;/p&gt;



&lt;p&gt;For businesses, passkeys can improve both security and usability. They reduce reliance on shared secrets and can make login faster for employees. The main challenge is ecosystem readiness. Not every business tool supports passkeys yet, and IT teams need policies for device enrollment, recovery, shared workstations, and employee offboarding.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;For many organizations, the practical solution is a hybrid model: use passkeys where supported, keep strong passwords and MFA where they are still required, and manage both through clear access policies.&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;MFA method&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Security strength&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Business suitability&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Best-use scenario&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;SMS OTP&lt;/td&gt;&lt;td&gt;Basic&lt;/td&gt;&lt;td&gt;Easy to adopt, but weaker than other MFA methods&lt;/td&gt;&lt;td&gt;Fallback option when stronger MFA is not available&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Authenticator apps&lt;/td&gt;&lt;td&gt;Moderate to strong&lt;/td&gt;&lt;td&gt;Practical default for many teams&lt;/td&gt;&lt;td&gt;Everyday business accounts and SaaS tools&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Hardware security keys&lt;/td&gt;&lt;td&gt;Very strong&lt;/td&gt;&lt;td&gt;Best for high-risk roles, but requires device management&lt;/td&gt;&lt;td&gt;Admins, executives, finance teams, and sensitive systems&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Passkeys&lt;/td&gt;&lt;td&gt;Very strong&lt;/td&gt;&lt;td&gt;Secure and user-friendly where supported&lt;/td&gt;&lt;td&gt;Modern apps, passwordless workflows, and phishing-resistant access&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;where&quot;&gt;Where MFA implementation fails&lt;/h2&gt;



&lt;p&gt;MFA can still fail even when a business has implemented it. Implementation quality actually matters as much as the MFA method itself. Some of the reasons for failure can include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Weak recovery&lt;/strong&gt;. If employees can bypass MFA through easy account recovery, help desk shortcuts, or poorly protected backup codes, attackers may target the reset process instead of the login screen.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Inconsistent enforcement. &lt;/strong&gt;MFA may be enabled for some tools but left optional for email, admin accounts, finance systems, shared operational accounts, or certain employees. In that situation, MFA becomes an aspiration rather than a control, and attackers can still look for the weakest available path.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Poor usability&lt;/strong&gt;. If employees are constantly interrupted, locked out, or unclear about what to approve, they may become frustrated and more likely to make mistakes. Push fatigue is one example: repeated approval prompts can train people to accept requests without thinking.&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;A strong MFA rollout needs enforcement, monitoring, and support. It should be easy for employees to do the right thing and difficult to leave important accounts unprotected.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;employee&quot;&gt;The employee resistance problem&lt;/h2&gt;



&lt;p&gt;Employee resistance is one of the biggest barriers to MFA rollout. Employees may see it as an extra step, a productivity blocker, or another security rule added without context.&lt;/p&gt;



&lt;p&gt;This reaction is understandable, especially when MFA is introduced abruptly or with unclear instructions. Resistance often comes from poor implementation, not from opposition to security itself.&lt;/p&gt;



&lt;p&gt;The solution to this problem is to make MFA predictable and easy to follow. Explain to employees that it protects business accounts even if a password is stolen, start with familiar tools such as email and shared business platforms, provide clear setup steps, and support employees through device changes.&lt;/p&gt;



&lt;p&gt;Avoid framing MFA as a punishment or a sign of distrust. It should feel like a practical safeguard for the company, its clients, and employees’ own work accounts.&lt;/p&gt;



&lt;p&gt;A &lt;a href=&quot;https://proton.me/business/blog/byod-policy&quot;&gt;bring your own device (BYOD) policy&lt;/a&gt; also helps. If employees use personal devices for work, clear rules for authentication apps, device security, lost-device reporting, and access revocation make MFA rollout smoother.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;how-to&quot;&gt;How to roll out MFA across your business&lt;/h2&gt;



&lt;p&gt;A successful MFA rollout is a change-management project. IT managers need to decide what gets protected first, how enforcement will work, how exceptions will be handled, and how adoption will be measured.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 1: Map your accounts and risk levels&lt;/h3&gt;



&lt;p&gt;Start with an access inventory. Identify the systems your business depends on and the accounts that create the most risk if compromised.&lt;/p&gt;



&lt;p&gt;Prioritize:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Email and identity provider accounts.&lt;/li&gt;



&lt;li&gt;Admin accounts and privileged roles.&lt;/li&gt;



&lt;li&gt;Password manager accounts.&lt;/li&gt;



&lt;li&gt;Finance, payroll, and billing tools.&lt;/li&gt;



&lt;li&gt;Cloud storage and file sharing.&lt;/li&gt;



&lt;li&gt;Developer, infrastructure, and production systems.&lt;/li&gt;



&lt;li&gt;Customer data platforms and CRMs.&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;This creates a rollout sequence for your business that’s based on risk rather than convenience.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 2: Choose approved MFA methods&lt;/h3&gt;



&lt;p&gt;Decide which MFA methods your business will allow. For many teams, authenticator apps or passkeys may become the default, while hardware security keys are reserved for high-risk roles. SMS can remain a fallback where necessary, but should not be the preferred method for sensitive systems.&lt;/p&gt;



&lt;p&gt;Document the decision clearly. Employees should know which methods are approved, which are discouraged, and what to do if they lose a device.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 3: Pilot before enforcing everywhere&lt;/h3&gt;



&lt;p&gt;Run a pilot with IT, operations, finance, leadership, or another group that can provide useful feedback. The goal is to test the setup process, support documentation, recovery flows, and policy settings before the rollout reaches the whole organization.&lt;/p&gt;



&lt;p&gt;A pilot also helps identify where MFA prompts are too frequent, where employees need clearer instructions, and which systems require special handling.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 4: Enforce MFA for high-risk accounts first&lt;/h3&gt;



&lt;p&gt;Encouragement is not enough for critical systems. Once the pilot is complete, enforce MFA for the accounts that create the highest risk.&lt;/p&gt;



&lt;p&gt;This includes admin accounts, email, identity systems, password managers, and financial tools. If these accounts remain optional, attackers may still find a path into the business.&lt;/p&gt;



&lt;p&gt;The key is to enforce with support. Give employees advance notice, setup guides, office hours, and recovery instructions. Enforcement works best when people aren’t surprised by it.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 5: Expand to the rest of the organization&lt;/h3&gt;



&lt;p&gt;After high-risk accounts are protected, expand MFA to remaining business tools. This can happen by department, tool category, or risk level.&lt;/p&gt;



&lt;p&gt;Track adoption as you go:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Which accounts have MFA enabled?&lt;/li&gt;



&lt;li&gt;Which employees haven’t enrolled?&lt;/li&gt;



&lt;li&gt;Which systems still allow password-only access? &lt;/li&gt;



&lt;li&gt;Which exceptions are open, and who owns them? &lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; can support this process by giving teams visibility into which accounts already have MFA enabled and which still need stronger authentication.&lt;/p&gt;



&lt;p&gt;This is where many rollouts stagger or fail. MFA needs ongoing governance after the rollout date.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 6: Review exceptions and recovery paths&lt;/h3&gt;



&lt;p&gt;Every exception should have an owner, reason, and expiration date. If MFA cannot be enabled for a tool, document why and decide whether a compensating control is needed.&lt;/p&gt;



&lt;p&gt;Recovery also deserves regular review. Backup codes, account recovery flows, admin overrides, and device resets can become weak points if they are not controlled. MFA implementation should make recovery safe, not simply convenient.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;proton-pass&quot;&gt;How Proton Pass for Business makes MFA manageable&lt;/h2&gt;



&lt;p&gt;MFA rollout becomes easier when &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt; is already controlled. If passwords are reused, shared informally, stored in browsers, or scattered across spreadsheets, MFA becomes harder to enforce consistently.&lt;/p&gt;



&lt;p&gt;A business password manager like Proton Pass for Business helps by doing more than strengthening the password layer. It can also support the second factor directly. The built-in 2FA support means teams can store TOTP codes securely and use the password manager itself as the MFA device, which makes stronger authentication easier to adopt and easier to share securely where appropriate. Employees can generate strong, unique passwords, store them in encrypted vaults, autofill logins, use built-in 2FA support for TOTP codes, and manage passkeys where supported.&lt;/p&gt;



&lt;p&gt;This also improves visibility. Administrators need to know not only whether employees have strong passwords, but also which accounts already have 2FA enabled and which still rely on password-only access. Proton Pass can help IT admins surface that information, making MFA adoption easier to track across the organization.&lt;/p&gt;



&lt;p&gt;Passkeys are also a key consideration. As businesses move toward stronger, phishing-resistant authentication, a password manager that supports passkeys like Proton Pass helps teams manage both traditional MFA flows and newer passwordless methods in one place. That makes rollout more practical in mixed environments where some systems still use passwords and TOTP, while others are ready for passkeys.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;For IT teams, Proton Pass for Business supports centralized management, policies, secure sharing, and visibility through reporting and logs. That makes MFA more operationally realistic because teams can reduce password sprawl while also making stronger authentication easier to deploy and govern across the organization.&lt;/p&gt;



&lt;p&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; doesn’t replace MFA. It makes MFA much easier to implement because it strengthens the first factor, supports the second, and gives the business a more manageable path toward stronger authentication overall.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item><item><title>A journalist’s safety guide to the 2026 FIFA World Cup</title><link>https://proton.me/blog/journalist-safety-guide-2026-fifa-world-cup</link><guid isPermaLink="true">https://proton.me/blog/journalist-safety-guide-2026-fifa-world-cup</guid><description>Covering the 2026 FIFA World Cup? Here&apos;s how journalists can stay safe from physical threats, border scrutiny, and digital surveillance.</description><pubDate>Tue, 09 Jun 2026 18:05:07 GMT</pubDate><content:encoded>
&lt;p&gt;Three countries and 16 cities are slated to host the 23rd FIFA World Cup this June. The event, which will be held in the United States, Mexico, and Canada, is expected to bring in more than 5 million fans from around the world, including an estimated 50,000 journalists.&lt;/p&gt;



&lt;p&gt;Large crowds and global security threats like cyber, drone, or mass-casualty attacks pose risks to reporters and fans at all locations. In the US, travel bans and increased ICE activity should also be considered. If you are a journalist or media professional covering the 2026 FIFA World Cup, there are ways to ensure your safety as you travel through the event&amp;#8217;s host cities.&lt;/p&gt;



&lt;p&gt;Proton has assembled a guide to assist journalists navigate the World Cup safely. The tips below can help protect journalists and media against security threats while reporting from the ground at the World Cup.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Reporting from the United States&lt;/h2&gt;



&lt;p&gt;11 cities in the United States are hosting FIFA World Cup games in 2026, including Atlanta, Boston, Dallas, Houston, Kansas City, Los Angeles, Miami, New York, Philadelphia, San Francisco, and Seattle.&lt;/p&gt;



&lt;p&gt;According to The Athletic, the Federal Emergency Management Agency granted $625 million in security funding toward those 11 US cities for operational exercises, staff background checks, and cybersecurity defense.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Travel restrictions and border crossings&lt;/h2&gt;



&lt;p&gt;Given the location, size, and scope of the World Cup, journalists traveling from outside the US should consider the risks when entering the country. In 2025, the Trump Administration announced a travel ban for citizens of Afghanistan, Myanmar, Chad, Republic of Congo, Guinea, Eritrea, Haiti, Iran, Libya, Somalia, Sudan, and Yemen. There are partial restrictions for residents of Burundi, Cuba, Laos, Sierra Leone, Togo, Turkmenistan, and Venezuela.&lt;/p&gt;



&lt;p&gt;According to the Committee to Protect Journalists, border agents in the US &amp;#8220;maintain broad discretionary authority to implement travel restrictions.&amp;#8221; Additionally, &amp;#8220;increased vetting, inconsistent enforcement, and sudden policy changes suggest an unpredictable environment,&amp;#8221; in which traveling journalists should prepare.&lt;/p&gt;



&lt;p&gt;Media personnel can anticipate being questioned at the border by Customs and Border Protection (CBP), especially if journalists represent a country on the travel ban list or have a history of covering politically sensitive issues. Journalists with dual citizenship from a country on the travel ban list should use the passport of their nation that does not appear on the banned list.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Protecting your devices and data&lt;/h2&gt;



&lt;p&gt;Precautions should be taken to encrypt or back up sensitive or personal information on electronic devices, as CBP does not need a warrant or probable cause to search your person or electronics. To protect your personal data and ensure it isn&amp;#8217;t copied or stored by CBP, journalists should:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Use strong passwords and store them in a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;password manager&lt;/a&gt; like Proton Pass.&lt;/li&gt;



&lt;li&gt;Use an &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end encrypted&lt;/a&gt; email service like Proton Mail so messages can&amp;#8217;t be surveilled.&lt;/li&gt;



&lt;li&gt;Employ &lt;a href=&quot;https://proton.me/pass/aliases&quot;&gt;email aliases&lt;/a&gt; so your personal or work email isn&amp;#8217;t exposed.&lt;/li&gt;



&lt;li&gt;Enable &lt;a href=&quot;https://proton.me/authenticator&quot;&gt;two-factor authentication&lt;/a&gt; so CBP can&amp;#8217;t access your accounts.&lt;/li&gt;



&lt;li&gt;Back up sensitive information on a &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;cloud storage service&lt;/a&gt; like Proton Drive, so privileged documents don&amp;#8217;t live on your phone or electronic devices.&lt;/li&gt;



&lt;li&gt;Make social media accounts private and/or delete any apps that may be subject to search.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Legal resources for journalists&lt;/h2&gt;



&lt;p&gt;If a legal concern should arise during your coverage of the FIFA World Cup, journalists can call the Reporters Committee for Freedom of the Press legal hotline at 1-800-336-4243.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;Media members can also text CPJ&amp;#8217;s chatbot for assistance using the number 1-206-590-6191 or email the committee at emergencies@cpj.org.&lt;/p&gt;



&lt;p&gt;If you are denied entry into the country or into the World Cup, are facing detention or arrest, have been assaulted, or had equipment damaged, you can file a report using the &lt;a href=&quot;https://pressfreedomtracker.us/submit-incident/&quot;&gt;U.S. Press Freedom Tracker&lt;/a&gt;.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;General safety tips for all host cities&lt;/h2&gt;



&lt;p&gt;Whether reporting from the United States, Mexico, or Canada, you should familiarize yourself with the country&amp;#8217;s local laws. Before heading to your destination, research the location and have an exit strategy should an emergency arise.&lt;/p&gt;



&lt;p&gt;Have an emergency contact on standby, work in pairs whenever possible, and designate meet-up locations ahead of time should cell service or Wi-Fi go down. Identify exits, medical tents, rideshare drop off and pickup locations and media areas before arrival.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Proton for journalists and newsrooms&lt;/h2&gt;



&lt;p&gt;To counter unprecedented threats toward journalists, Proton offers discounts on Proton for Business to &lt;a href=&quot;https://proton.me/business/media&quot;&gt;news media&lt;/a&gt;. Protect your emails, contacts, documents, sources, and other sensitive data with end-to-end encryption, so your team can work safely no matter where they are.&lt;/p&gt;



&lt;p&gt;Proton has been &lt;a href=&quot;https://proton.me/about/impact&quot;&gt;committed to press freedom&lt;/a&gt; for more than 10 years. Learn more about how Proton protects journalists and get &lt;a href=&quot;https://proton.me/business/contact?int=media&quot;&gt;Proton for your newsroom&lt;/a&gt; today.&lt;/p&gt;
</content:encoded><category>Privacy guides</category><author>Proton Team</author></item><item><title>Cybersecurity compliance 101: What small businesses need to know</title><link>https://proton.me/business/blog/blog-cybersecurity-compliance</link><guid isPermaLink="true">https://proton.me/business/blog/blog-cybersecurity-compliance</guid><description>Learn how your small businesses can build a compliance foundation that wins deals, protects data, and proves your security posture.</description><pubDate>Tue, 09 Jun 2026 17:34:04 GMT</pubDate><content:encoded>
&lt;p&gt;You&amp;#8217;ve likely experienced this scenario: You&amp;#8217;re in the final stages of a deal with a promising enterprise client. The contract is ready, the price is agreed upon, and then the conversation stalls. &lt;/p&gt;



&lt;p&gt;The reason? They asked for your &lt;a href=&quot;https://proton.me/business/blog/cybersecurity-compliance&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;cybersecurity compliance documentation&lt;/a&gt;, and you couldn&amp;#8217;t provide it.&lt;/p&gt;



&lt;p&gt;It&amp;#8217;s a frustrating moment. It&amp;#8217;s understandable to feel that cybersecurity compliance is a game for large corporations with dedicated security teams and massive budgets. For a growing startup or a small business, it can feel like an overwhelming administrative burden. &lt;/p&gt;



&lt;p&gt;The good news is that there are simple ways to prove you take data protection seriously. &lt;/p&gt;



&lt;p&gt;This guide breaks down what compliance actually means for your business, the key frameworks you&amp;#8217;ll encounter, and how to get started without needing a team of IT experts.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is cybersecurity compliance?&amp;nbsp;&lt;/h2&gt;



&lt;p&gt;Cybersecurity compliance is how you prove you are protecting sensitive data according to recognized standards. It&amp;#8217;s not just about having the right tools; it&amp;#8217;s about having the right processes and the documentation to back them up.  &lt;/p&gt;



&lt;p&gt;Think of it as your business&amp;#8217;s &amp;#8220;report card&amp;#8221; for security. It shows prospects and partners that you have rules in place, you follow them, and you can prove it.  &lt;/p&gt;



&lt;p&gt;It&amp;#8217;s not optional. Regulations like &lt;a href=&quot;https://proton.me/business/gdpr&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;GDPR&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/healthcare&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;HIPAA&lt;/a&gt; carry real legal weight. Fines, lawsuits, and operational restrictions are all on the table. And cybersecurity threats aren&amp;#8217;t theoretical. &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Four in five small businesses&lt;/a&gt; have suffered a recent data breach.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The risks of data non-compliance&lt;/h3&gt;



&lt;p&gt;Skipping compliance might seem like a way to save time and money, but it&amp;#8217;s a short-sighted gamble. The fallout hits in three critical areas:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Financial penalties:&lt;/strong&gt; A single GDPR violation can cost millions. For a small business, even a mid-range fine can mean layoffs, frozen growth, or closure.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Operational disruption:&lt;/strong&gt; A breach takes systems offline for weeks. Your staff gets pulled from revenue-generating work to manage the crisis. Recovery costs can easily exceed &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;$1 million&lt;/a&gt; when you factor in downtime, legal fees, and lost contracts.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Reputation damage: &lt;/strong&gt;Customers who trusted you with their data may not give you a second chance. In tight-knit industries, word travels fast. A compliance failure doesn&amp;#8217;t just hurt your brand; it can shrink your sales pipeline for years.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Key cybersecurity frameworks every business should know &lt;/h2&gt;



&lt;p&gt;These are the standards your customers, regulators, and enterprise partners will likely ask about.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;GDPR (General Data Protection Regulation)&lt;/h3&gt;



&lt;p&gt;If you have even one customer in the European Union, or if you collect email addresses from EU visitors on your website, &lt;a href=&quot;https://gdpr.eu/what-is-gdpr/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;GDPR&lt;/a&gt; applies to you—regardless of where your company is based. Non-compliance can result in fines of up to €20 million or 4% of your annual global revenue, whichever is higher.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;What it means: &lt;/strong&gt;You must be transparent about how you collect and use data. You must give people the right to access, correct, or delete their information.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;HIPAA (Health Insurance Portability and Accountability Act)&lt;/h3&gt;



&lt;p&gt;Are you a SaaS company serving a US healthcare provider? Or perhaps a clinic managing appointments? The moment patient data touches your systems, &lt;a href=&quot;https://www.hhs.gov/hipaa/index.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;HIPAA&lt;/a&gt; applies.Penalties range from thousands to millions of dollars, depending on the severity and whether negligence was involved&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;What it means:&lt;/strong&gt; You need strict safeguards like data encryption, controlled access, and clear procedures for reporting breaches.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;NIS2 (Network and Information Security Directive)&lt;/h3&gt;



&lt;p&gt;This is an EU directive strengthening cybersecurity in essential sectors like energy, transport, and digital infrastructure.Even if you aren&amp;#8217;t directly regulated, your enterprise customers may require you to meet &lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/policies/nis2-directive&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;NIS2&lt;/a&gt; standards as part of their vendor checks.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;What it means: &lt;/strong&gt;It requires risk management practices and strict incident reporting.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;ISO 27001 &amp;amp; SOC 2&lt;/h3&gt;



&lt;p&gt;These are international standards that evaluate how you manage and protect data. The stakes: For enterprise clients, having &lt;a href=&quot;https://proton.me/business/iso-27001-certification&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;ISO 27001&lt;/a&gt; certification or a &lt;a href=&quot;https://proton.me/blog/soc-2&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;SOC 2&lt;/a&gt; report is a massive trust signal. It tells them, &amp;#8220;We have been audited by independent experts, and our security is solid.&amp;#8221;&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;What it means: &lt;/strong&gt;You need to implement documented security controls, submit to independent audits, and maintain that certification on an ongoing basis.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to get started with compliance in cybersecurity&amp;nbsp;&amp;nbsp;&lt;/h2&gt;



&lt;p&gt;Compliance can feel like a long list of boxes to check, but the basics come down to five practical steps.&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Map out what data you have, where it lives, and who has access. You might be surprised to find a customer list saved on a contractor&amp;#8217;s personal Dropbox or a shared spreadsheet with sensitive info that anyone can edit.&lt;/li&gt;



&lt;li&gt;Write down your policies. Who can access what? How do you report a breach? How do you dispose of old data? If it isn&amp;#8217;t written down, it doesn&amp;#8217;t exist. Keep these documents clear, current, and ensure your team actually follows them.&lt;/li&gt;



&lt;li&gt;Give your team a &lt;a href=&quot;https://proton.me/pass/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;business password manager&lt;/a&gt;. It generates strong credentials, stores them securely, and makes good habits the default. It removes the friction of remembering complex passwords.&lt;/li&gt;



&lt;li&gt;Use a &lt;a href=&quot;https://proton.me/business/vpn&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;business VPN&lt;/a&gt;. It encrypts all your team&amp;#8217;s internet traffic, ensuring data stays protected no matter where they log in. This is a straightforward way to meet network security requirements for almost every major framework.&lt;/li&gt;



&lt;li&gt;Assign a specific person (even if it&amp;#8217;s part of their role) to be accountable for your compliance posture. They should track regulatory changes, keep documentation updated, and ensure leadership stays informed.&lt;/li&gt;
&lt;/ol&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to stay compliant with cybersecurity regulations&lt;/h2&gt;



&lt;p&gt;Regulations change, your team grows, and the tools you use evolve. That&amp;#8217;s why requires ongoing attention.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Review policies regularly:&lt;/strong&gt; Conduct quarterly reviews to ensure your documentation reflects how you actually work.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Monitor for exposure:&lt;/strong&gt; Don&amp;#8217;t wait for a breach to find out your credentials leaked. Use tools that &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;monitor the dark web&lt;/a&gt; and alert you if your company data appears in a breach.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Conduct internal audits:&lt;/strong&gt; Test your controls before an auditor does. Find the gaps yourself — it&amp;#8217;s always cheaper than having them exposed externally.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Train your team:&lt;/strong&gt; Policies only work if people follow them. Short, practical training on phishing and data handling keeps security habits sharp.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Use tools that enable good security: &lt;/strong&gt;Compliance is easier when security is the default. Choose tools that encrypt your business data, give you granular control over access, and flag risks like weak passwords automatically.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Make cybersecurity compliance a part of BAU&lt;/h2&gt;



&lt;p&gt;Compliance doesn&amp;#8217;t have to be a scramble. With the right tools, it becomes part of how your business operates, giving you concrete answers to security questionnaires and audits.&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;https://proton.me/business/pass&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Proton Pass&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/vpn&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Proton VPN&lt;/a&gt; are built for this. Setup takes minutes, and you don&amp;#8217;t need an IT team to manage them.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Proton VPN encrypts all company network traffic and restricts access to approved devices, meeting strict network security requirements.&lt;/li&gt;



&lt;li&gt;Proton Pass lets you enforce two-factor authentication, manage credentials securely, and pull activity logs directly from the admin panel for audits. When a new hire joins, you can provision access in clicks; when someone leaves, you revoke it instantly.&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;You also get to leverage our compliance for yours. When enterprise clients ask about the security of the software you use, you can point to our credentials. &lt;/p&gt;



&lt;p&gt;Proton is ISO 27001-certified and SOC 2 Type II-verified, based in &lt;a href=&quot;https://proton.me/blog/switzerland&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Switzerland&lt;/a&gt;, and fully open-source. This gives you verifiable, third-party proof that your data is protected by the highest global standards.&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;https://proton.me/business&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Proton for Business&lt;/a&gt; gives you the tools you need not just to start your compliance journey, but to maintain it long term.&lt;/p&gt;



&lt;p&gt;&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>How to use Google Photos Locked Folder (and a safer alternative)</title><link>https://proton.me/blog/locked-folder-google-photos</link><guid isPermaLink="true">https://proton.me/blog/locked-folder-google-photos</guid><description>Learn how to use Google Photos&apos; Locked Folder, how it exposes your photos to Google, and a safer way to store sensitive images privately.</description><pubDate>Tue, 09 Jun 2026 14:10:53 GMT</pubDate><content:encoded>
&lt;p&gt;Most people have images meant for their eyes only, like snapshots of personal documents or intimate &lt;a href=&quot;https://proton.me/drive/photo-storage&quot;&gt;photos&lt;/a&gt; they&amp;#8217;d rather keep out of the main gallery. These are the kinds of images people would not want to accidentally &lt;a href=&quot;https://proton.me/blog/best-way-to-share-photos&quot;&gt;share with someone else&lt;/a&gt; or have exposed to anyone who gains physical access to their phone.&lt;/p&gt;



&lt;p&gt;Traditional photo libraries like &lt;a href=&quot;https://proton.me/blog/is-google-photos-safe&quot;&gt;Google Photos aren’t safe for private photos&lt;/a&gt; because they are not built for privacy. They can help protect your pictures from &lt;a href=&quot;https://proton.me/business/blog/unauthorized-access&quot;&gt;unauthorized access&lt;/a&gt;, but that doesn’t necessarily mean your sensitive photos are hidden from the service provider. Because Google Photos is not &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end encrypted&lt;/a&gt;, Google can technically access and process your photos in accordance with its policies.&lt;/p&gt;



&lt;p&gt;The Locked Folder feature in &lt;a href=&quot;https://proton.me/drive/google-photos-alternative&quot;&gt;Google Photos&lt;/a&gt; can be useful, but it doesn&amp;#8217;t change the underlying privacy model of the app. So before relying on it for sensitive images, it’s worth understanding what Locked Folder does, how to use it, and what its privacy limits are.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#what-is&quot;&gt;What is the Google Photos Locked Folder feature?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#how-to&quot;&gt;How to hide photos in the Google Photos Locked Folder&lt;/a&gt;
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#managing&quot;&gt;Managing photos and videos&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#limitations&quot;&gt;Limitations&lt;/a&gt;
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#privacy-cost&quot;&gt;The privacy cost of backing up Locked Folder photos&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#proton-drive&quot;&gt;A more private way to store sensitive photos&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;what-is&quot;&gt;What is the Google Photos Locked Folder feature?&lt;/h2&gt;



&lt;p&gt;Locked Folder is a Google Photos feature that lets you store selected photos and videos in a separate, protected space on your device. When you add items to this hidden folder, they:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Don’t appear in your photo grid, albums, search results, Memories, or partner sharing&lt;/li&gt;



&lt;li&gt;Are hidden from other apps on your device that have access to your regular photo library&lt;/li&gt;



&lt;li&gt;Require your device screen lock to view and manage, such as your PIN, password, fingerprint, or face unlock&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;how-to&quot;&gt;How to hide photos in the Google Photos Locked Folder&lt;/h2&gt;



&lt;p&gt;Setting up the Google Photos Locked Folder to &lt;a href=&quot;https://proton.me/blog/hide-photos-ios-android&quot;&gt;hide your photos&lt;/a&gt; takes only a few moments:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open &lt;strong&gt;Google Photos.&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Collections.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;945&quot; height=&quot;1865&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_945,h_1865,c_scale/f_auto,q_auto/v1781006670/wp-pme/google-photos-locked-folder-1/google-photos-locked-folder-1.jpeg?_i=AA&quot; alt=&quot;How to use Locked folder in Google Photos&quot; class=&quot;wp-post-152354 wp-image-152356&quot; style=&quot;width:400px&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;104 KB&quot; data-optsize=&quot;28 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;72.6&quot; data-version=&quot;1781006670&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1781006670/wp-pme/google-photos-locked-folder-1/google-photos-locked-folder-1.jpeg?_i=AA 945w, https://res.cloudinary.com/dbulfrlrz/images/w_152,h_300,c_scale/f_auto,q_auto/v1781006670/wp-pme/google-photos-locked-folder-1/google-photos-locked-folder-1.jpeg?_i=AA 152w, https://res.cloudinary.com/dbulfrlrz/images/w_519,h_1024,c_scale/f_auto,q_auto/v1781006670/wp-pme/google-photos-locked-folder-1/google-photos-locked-folder-1.jpeg?_i=AA 519w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1516,c_scale/f_auto,q_auto/v1781006670/wp-pme/google-photos-locked-folder-1/google-photos-locked-folder-1.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_778,h_1536,c_scale/f_auto,q_auto/v1781006670/wp-pme/google-photos-locked-folder-1/google-photos-locked-folder-1.jpeg?_i=AA 778w&quot; sizes=&quot;auto, (max-width: 945px) 100vw, 945px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;ol start=&quot;3&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Scroll down, and tap &lt;strong&gt;Locked&lt;/strong&gt;. You will be prompted to open the Locked Folder using your device screen lock option.&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Move items.&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;Select the photos or videos you want to add, and tap &lt;strong&gt;Move&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;945&quot; height=&quot;1876&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_945,h_1876,c_scale/f_auto,q_auto/v1781006675/wp-pme/google-photos-locked-folder-2/google-photos-locked-folder-2.jpeg?_i=AA&quot; alt=&quot;How to use Locked folder in Google Photos&quot; class=&quot;wp-post-152354 wp-image-152377&quot; style=&quot;width:400px&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;288 KB&quot; data-optsize=&quot;91 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;68.3&quot; data-version=&quot;1781006675&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1781006675/wp-pme/google-photos-locked-folder-2/google-photos-locked-folder-2.jpeg?_i=AA 945w, https://res.cloudinary.com/dbulfrlrz/images/w_151,h_300,c_scale/f_auto,q_auto/v1781006675/wp-pme/google-photos-locked-folder-2/google-photos-locked-folder-2.jpeg?_i=AA 151w, https://res.cloudinary.com/dbulfrlrz/images/w_516,h_1024,c_scale/f_auto,q_auto/v1781006675/wp-pme/google-photos-locked-folder-2/google-photos-locked-folder-2.jpeg?_i=AA 516w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1525,c_scale/f_auto,q_auto/v1781006675/wp-pme/google-photos-locked-folder-2/google-photos-locked-folder-2.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_774,h_1536,c_scale/f_auto,q_auto/v1781006675/wp-pme/google-photos-locked-folder-2/google-photos-locked-folder-2.jpeg?_i=AA 774w&quot; sizes=&quot;auto, (max-width: 945px) 100vw, 945px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;ol start=&quot;6&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Confirm using your device screen lock option.
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;If Locked Folder backup is off, you can turn it on by tapping &lt;strong&gt;Manage backup&lt;/strong&gt; or skip by tapping &lt;strong&gt;Continue&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Move&lt;/strong&gt; to confirm.&lt;/li&gt;
&lt;/ol&gt;



&lt;p&gt;To add new items, tap the &lt;strong&gt;new photo icon 🖼&lt;/strong&gt; on the bottom left. It’s not possible to create subfolders in the Locked Folder feature for organization.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;managing&quot;&gt;Managing photos and videos in Locked Folder&lt;/h3&gt;



&lt;p&gt;To return a photo or video to your main Google Photos library, select it in &lt;strong&gt;Locked Folder&lt;/strong&gt;, tap &lt;strong&gt;Move&lt;/strong&gt;, and tap &lt;strong&gt;Move&lt;/strong&gt; again to confirm. The item will leave Locked Folder and reappear in its original position in your photo timeline.&lt;/p&gt;



&lt;p&gt;You can also permanently delete items by pressing &lt;strong&gt;Delete&lt;/strong&gt;, and again &lt;strong&gt;Delete&lt;/strong&gt; to confirm.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;limitations&quot;&gt;Limitations of the Locked Folder feature in Google Photos&lt;/h2&gt;



&lt;p&gt;The Locked Folder feature is useful for keeping private photos out of your main gallery, such as when you hand your phone to someone else and don’t want them scrolling into something sensitive. But it does not create a separate, end-to-end encrypted vault.&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;https://proton.me/drive/security&quot;&gt;End-to-end encryption&lt;/a&gt; means your data is encrypted on your device before it reaches a company’s servers, and only you hold the keys to decrypt it. Not even the service provider can read your files. Google Photos does not offer end-to-end encryption for your photo library — so Google retains access to your images&amp;nbsp;— and the Locked Folder tool is governed by the underlying policy of the Google Photos privacy policy.&lt;/p&gt;



&lt;p&gt;That matters because Google does not simply store photos passively. Its automated systems can scan content for policy violations, and mistakes can have serious consequences.&lt;/p&gt;



&lt;p&gt;In one widely reported case, a father in California &lt;a href=&quot;https://www.google.com/search?q=google+photos+toddler+california&amp;amp;oq=google+photos+toddler+california&amp;amp;sourceid=chrome&amp;amp;ie=UTF-8#:~:text=A%20Dad%20Took,08/21%20%E2%80%BA%20technology&quot;&gt;took medical photos of his toddler&lt;/a&gt; at a doctor’s request and sent them to the healthcare provider. Because the photos were also backed up to his Google account, Google’s systems flagged them as potential CSAM, reported him to law enforcement, and terminated his account. Police cleared him of wrongdoing, but Google still refused to restore the account, leaving him without access to years of emails, photos, purchase history, and other data.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;privacy-cost&quot;&gt;The privacy cost of backing up Locked Folder photos&lt;/h3&gt;



&lt;p&gt;By default, items you move to the Google Locked Folder only exist on your local device. If you don’t &lt;a href=&quot;https://proton.me/blog/how-to-back-up-files&quot;&gt;turn on backup&lt;/a&gt;, you could lose your photos if your device is damaged or lost.&lt;/p&gt;



&lt;p&gt;On the other hand, backing up your Locked Folder photos means keeping them stored on Google’s servers and giving the company broad access to your sensitive content that you don’t feel comfortable sharing with anyone else.&lt;/p&gt;



&lt;p&gt;That leaves you stuck between two bad options:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Keep photos on your local device only and risk losing them, or&lt;/li&gt;



&lt;li&gt;Back them up to Google Photos and accept they may be scanned by Google’s automated systems and reviewed by humans if an algorithm flags something, even by mistake.&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;If neither option sits right with you, there’s a better, safer way to store sensitive photos without risking that your &lt;a href=&quot;https://proton.me/drive&quot;&gt;cloud storage&lt;/a&gt; provider can take a sneak peek.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;proton-drive&quot;&gt;A more private way to store sensitive photos&lt;/h2&gt;



&lt;p&gt;If you want to safely store sensitive photos long-term, use Proton Drive. While Proton Drive does not have a direct equivalent to Google Photos’ Locked Folder, it approaches photo privacy differently by protecting your photos with &lt;a href=&quot;https://proton.me/drive/security&quot;&gt;end-to-end encryption&lt;/a&gt; so no one can see them except you and the people you choose to share them with — not even us.&lt;/p&gt;



&lt;p&gt;You can &lt;a href=&quot;https://proton.me/support/enable-photo-backup&quot;&gt;enable automatic photo backup&lt;/a&gt; on your phone to keep them synced across your devices, browse photos in a timeline, organize them into albums, mark favorites, filter by media type, and securely share individual photos or full albums with passwords and expiration dates. Shared links can be easily revoked anytime.&lt;/p&gt;



&lt;p&gt;Unlike Google Photos and &lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt;, Proton Drive is transparent when it comes to your data: All Drive apps are &lt;a href=&quot;https://proton.me/community/open-source&quot;&gt;open source&lt;/a&gt; and independently audited, which means anyone can verify our security. We never scan your files or photo library, show ads, use your photos for AI or product improvement, or share your information with anyone.&lt;/p&gt;



&lt;p&gt;When you’re ready to move on from Google Photos, you can &lt;a href=&quot;https://proton.me/support/how-to-import-from-google-photos&quot;&gt;easily migrate your memories to Proton Drive&lt;/a&gt;. And when you’re ready to &lt;a href=&quot;https://proton.me/degoogle&quot;&gt;deGoogle&lt;/a&gt; more broadly, you can take the next steps toward a &lt;a href=&quot;https://proton.me/&quot;&gt;privacy-first ecosystem&lt;/a&gt; built to protect your data rather than exploit it.&lt;br&gt;&lt;/p&gt;
</content:encoded><category>Privacy guides</category><author>Elena Constantinescu</author></item><item><title>Top 7 internal communication tools for companies</title><link>https://proton.me/business/blog/internal-communication-tools</link><guid isPermaLink="true">https://proton.me/business/blog/internal-communication-tools</guid><description>Compare internal communication software to find tools that keep every message, file, and meeting your team exchanges private.</description><pubDate>Tue, 09 Jun 2026 13:19:20 GMT</pubDate><content:encoded>
&lt;p&gt;Every internal communication tool was built simply to host workplace conversations. They do far more than that today.&lt;/p&gt;



&lt;p&gt;Platforms like Slack, Microsoft Teams, and Zoom have become the vaults for a company&amp;#8217;s most valuable intellectual property, retaining critical decisions, sensitive documents, and proprietary data. &lt;/p&gt;



&lt;p&gt;The problem is that all this valuable data is often protected only by basic encryption — a security measure that leaves the door wide open for providers, third parties, and even AI models to access it.&lt;/p&gt;



&lt;p&gt;This guide explores the top seven internal communication tools available in 2026, weighing their functionality against their privacy practices. &lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What are internal communication tools?&lt;/h2&gt;



&lt;p&gt;Internal communication tools are software platforms designed to facilitate real-time interaction and information sharing within an organization. &lt;/p&gt;



&lt;p&gt;They were designed to solve a specific friction point: the latency of poorly designed email platforms. A quick answer from a colleague would require hours of waiting and valuable ideas would get lost in a thread of replies.&lt;/p&gt;



&lt;p&gt;Businesses adopted internal communication tools with the hope that it would break down silos, enabling real-time collaboration across departments and time zones. It did. It’s now become the digital water cooler and the virtual conference room.&lt;/p&gt;



&lt;p&gt;Teams now use internal communication tools to make hiring decisions, finalize product roadmaps, store legal contracts, and conduct sensitive client negotiations — high stakes for a tool designed to facilitate the exchange of information, not secure it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why modern communication stacks are actually failing businesses&lt;/h2&gt;



&lt;p&gt;Fast and convenient internal communication often comes at a cost. Because many modern communication tools are built to prioritize speed and scale over security, they rely on basic &lt;a href=&quot;https://proton.me/learn/encryption&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;encryption&lt;/a&gt; that doesn’t adequately protect your data. &lt;/p&gt;



&lt;p&gt;This means providers can access your messages, calls, and files which can be shared, leaked, or sold to advertisers. In some cases, they’re even used to train AI models.&lt;/p&gt;



&lt;p&gt;This creates real business risks. These range from compliance violations to data exposure in a breach. Together, these risks make it even more important to choose the right internal communication tool. In addition to affordability and convenience, you should prioritize security.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What to look for in an internal communication tool&lt;/h2&gt;



&lt;p&gt;Internal communication software is essential to keeping teams aligned. When choosing a secure internal communication tool, look for:&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;End-to-end encryption &lt;/h4&gt;



&lt;p&gt;Most tools encrypt data in transit, but that&amp;#8217;s not enough. &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;End-to-end encryption&lt;/a&gt; ensures that only participants can access the content of your communications — not the provider, third parties, or AI models.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Data minimization&lt;/h4&gt;



&lt;p&gt;Every tool collects some data to function. The question is how much, and what happens to it. Look for tools that collect only what&amp;#8217;s necessary and don&amp;#8217;t share or monetize your data.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Open source transparency&lt;/h4&gt;



&lt;p&gt;If a provider publishes its code as open source, anyone can verify its security claims. Look for independent audits and clear privacy policies that explain exactly how your data is handled.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;&lt;strong&gt;The 7 best internal communication tools&lt;/strong&gt;&lt;/h2&gt;



&lt;p&gt;There’s no one-size-fits-all internal communication tool. The right one depends on your business needs, your existing software, and how you handle sensitive information. &lt;/p&gt;



&lt;p&gt;Here are seven of the best options you can find today.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Proton Meet&lt;/h3&gt;



&lt;p&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Private and secure business meetings&lt;/p&gt;



&lt;p&gt;Proton Meet combines the familiarity of &lt;a href=&quot;https://proton.me/business/meet&quot;&gt;video conferencing software&lt;/a&gt; with a privacy-first, web-based design. End-to-end encryption is enabled by default, so meetings remain confidential and only accessible to participants, not even Proton can access them.&lt;/p&gt;



&lt;p&gt;If your business is concerned about compliance and data exposure, Proton Meet offers additional protection through Swiss privacy laws. There&amp;#8217;s no ad-based business model, which means there’s no incentive to collect or monetize user data.&lt;/p&gt;



&lt;p&gt;Proton Meet includes all the video conferencing features you’ve come to expect — chat messaging, screen sharing, blurred backgrounds, noise reduction filters, and more. All in a single secure video conferencing tool, a part of a suite that helps you stay &lt;a href=&quot;https://proton.me/business/gdpr&quot;&gt;GDPR-&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/healthcare&quot;&gt;HIPAA-compliant&lt;/a&gt;.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;Strengths:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;End-to-end encrypted by default&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;https://proton.me/blog/zero-access-encryption&quot;&gt;Zero-knowledge architecture&lt;/a&gt; (your data is encrypted so only you can access it, not Proton)&lt;/li&gt;



&lt;li&gt;Guests can join calls without a Proton account&lt;/li&gt;



&lt;li&gt;Part of Proton’s privacy-first suite&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;strong&gt;Keep in mind:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Fewer integrations available&lt;/li&gt;



&lt;li&gt;Free plan limited to one-hour calls and 50 participants&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Proton Mail&lt;/h3&gt;



&lt;p&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Secure email communication&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;https://proton.me/business/mail&quot;&gt;Proton Mail&lt;/a&gt; is how emails should be — private by default. Email remains the backbone of business communication and should be appropriately protected. Unlike other email providers, Proton Mail is end-to-end encrypted by default. Your emails are fully secured whether in transit or at rest; only you and your intended recipient can read them.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;End-to-end encryption also ensures your emails can never be scanned, shared with third parties, or used to train AI. This ad-free business model means Proton does not benefit from your data.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;Strengths:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;End-to-end encrypted by default&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;https://proton.me/blog/zero-access-encryption&quot;&gt;Zero-knowledge architecture&lt;/a&gt; (your data is encrypted so only you can access it)&lt;/li&gt;



&lt;li&gt;Data is protected by Swiss privacy laws&lt;/li&gt;



&lt;li&gt;Part of the Proton ecosystem&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;strong&gt;Keep in mind:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Emails to non-Proton recipients aren&amp;#8217;t end-to-end encrypted unless &lt;a href=&quot;https://proton.me/support/password-protected-emails&quot;&gt;password-protected&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;Fewer native integrations than Gmail or Outlook&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Slack&lt;/h3&gt;



&lt;p&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Instant messaging and app integration&lt;/p&gt;



&lt;p&gt;Slack is the iMessage of the enterprise world. Slack simplifies workplace discussions; instead of drawn-out email threads, conversations happen in organized channels sorted by team, project, or however you choose.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;Slack features an extensive integration library that lets you connect to popular enterprise software, such as Jira and Google Calendar. These integrations turn Slack from a chat tool into a central hub for notifications and workflows. Additionally, Slack allows you to hold video and voice calls, making it a versatile communication tool.&lt;/p&gt;



&lt;p&gt;Slack has come under scrutiny for privacy concerns — from allowing admins to &lt;a href=&quot;https://nypost.com/2023/06/15/your-boss-can-read-all-your-slacks-even-private-ones-heres-how/&quot;&gt;read employee messages&lt;/a&gt; to the &lt;a href=&quot;https://slack.com/intl/en-gb/trust/privacy/privacy-policy&quot;&gt;sharing of identifiable information&lt;/a&gt; with advertisers. Depending on your location, you may not be able to opt out of this data sharing.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;Strengths:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Extensive app integration library&lt;/li&gt;



&lt;li&gt;Organized channels for teams and projects&lt;/li&gt;



&lt;li&gt;Supports chat, voice, and video functionality&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;strong&gt;Keep in mind:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Admins can read employee messages&lt;/li&gt;



&lt;li&gt;Your data is shared with advertisers&lt;/li&gt;



&lt;li&gt;Opt-out options vary by jurisdiction&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Microsoft Teams&lt;/h3&gt;



&lt;p&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Microsoft-reliant organizations&lt;/p&gt;



&lt;p&gt;Microsoft Teams is the obvious choice for businesses that rely on Microsoft services. Its deep integration with the Microsoft ecosystem enables many quality-of-life conveniences, such as real-time document collaboration within the app and an automatic Outlook sync. It scales well too, Teams can handle everything from small-group chats to company-wide town halls.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;However, Microsoft’s privacy practices have long faced criticism. Concerns range from auto-enabling &lt;a href=&quot;https://changepilot.cloud/blog/microsoft-teams-update-causes-privacy-concerns-in-australian-education-sector&quot;&gt;features that collect user data&lt;/a&gt; to bossware features such as &lt;a href=&quot;https://www.itpro.com/security/privacy/microsoft-teams-is-getting-a-new-location-tracking-feature-that-lets-bosses-snoop-on-staff-research-shows-it-could-cause-workforce-pushback&quot;&gt;location tracking&lt;/a&gt; and the &lt;a href=&quot;https://www.microsoft.com/en-gb/privacy/data-collection-teams&quot;&gt;volume of data&lt;/a&gt; they collect.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;Strengths:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Part of Microsoft 365&lt;/li&gt;



&lt;li&gt;Scales from small teams to large organizations&lt;/li&gt;



&lt;li&gt;Seamless integration with Microsoft software&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;strong&gt;Keep in mind:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Auto-enabled features may collect user data&lt;/li&gt;



&lt;li&gt;Includes location tracking capabilities&lt;/li&gt;



&lt;li&gt;Significant data collection across Microsoft products&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Connecteam&lt;/h3&gt;



&lt;p&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Deskless teams&lt;/p&gt;



&lt;p&gt;Connecteam is designed for teams that don’t work in corporate environments, such as retail and healthcare. The app-based design combines chat, announcements, and employee directory in one place, making it seamless for cross-team communication. It includes operation-centric features such as scheduling, time tracking, and task management to make it easy to manage a distributed, deskless team.&lt;/p&gt;



&lt;p&gt;Some features of Connecteam can raise privacy concerns for your team. The app collects extensive data, including location data, that is shared with employers and may also be used for targeted ads. However, Connecteam assures that it &lt;a href=&quot;https://au.connecteam.com/trust-center/&quot;&gt;handles data in compliance with regulations&lt;/a&gt; such as GDPR and HIPAA. It is also ISO 27001 and SOC 2 certified.&lt;br&gt;&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;Strengths:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Mobile-first design for field teams&lt;/li&gt;



&lt;li&gt;Includes scheduling and time tracking&lt;/li&gt;



&lt;li&gt;Bridges communication between corporate and frontline workers&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;strong&gt;Keep in mind:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Collects extensive data, including location data&lt;/li&gt;



&lt;li&gt;Data shared with employers and potentially advertisers&lt;/li&gt;



&lt;li&gt;May raise privacy concerns for your team&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Haiilo&lt;/h3&gt;



&lt;p&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Employee engagement&lt;/p&gt;



&lt;p&gt;Haiilo is an internal communication tool focused on employee engagement. It functions like a private social network for your organization. It is built to foster company culture and streamline communication, and allows your employees to share content on their personal social networks. As an internal communications tool, it is more specialized than the other options on the list.&lt;/p&gt;



&lt;p&gt;Haiilo is geared towards large enterprises with large workforces. It may be more than you need for smaller organizations. The platform collects data on behalf of employers, who control how it is used. This means you are responsible for how employee data is handled, and employees may not have opt-out rights.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;Strengths:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Designed specifically for employee engagement&lt;/li&gt;



&lt;li&gt;Centralized hub for company updates&lt;/li&gt;



&lt;li&gt;Encourages employee advocacy&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;strong&gt;Keep in mind:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Better suited for large enterprises&lt;/li&gt;



&lt;li&gt;You control employee data&lt;/li&gt;



&lt;li&gt;Employees may have limited opt-out rights depending on your setup&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Proton Workspace&lt;/h3&gt;



&lt;p&gt;&lt;strong&gt;Proton Workspace&lt;/strong&gt; &lt;strong&gt;Best for:&lt;/strong&gt; Organizations that need a secure, compliant alternative to Google Workspace or Microsoft 365&lt;/p&gt;



&lt;p&gt;Proton Workspace is a fully encrypted productivity suite that replaces the tools your team already uses — email, calendar, file storage, documents, spreadsheets, and video meetings — without the data exposure that comes with mainstream platforms. End-to-end encryption is built into every product, meaning your data is protected in transit, at rest, and from the platform itself.&lt;/p&gt;



&lt;p&gt;For compliance-driven organizations, Proton Workspace offers a defensible answer to auditors: zero-knowledge architecture means no one — including Proton — can access your data. Swiss jurisdiction puts it beyond the reach of FISA court orders and the CLOUD Act. Workspace Premium includes Lumo, a privacy-first AI assistant that doesn&amp;#8217;t use your data for model training.&lt;/p&gt;



&lt;p&gt;Migration from Google Workspace, Outlook, or other providers is handled through Easy Switch, with no engineering resources required.&lt;/p&gt;



&lt;p&gt;&lt;strong&gt;Strengths:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;End-to-end encrypted across every product&lt;/li&gt;



&lt;li&gt;Zero-knowledge architecture — your data is inaccessible even to Proton&lt;/li&gt;



&lt;li&gt;Swiss jurisdiction, outside US legal reach&lt;/li&gt;



&lt;li&gt;ISO 27001 and SOC 2 certified; GDPR and HIPAA compliant&lt;/li&gt;



&lt;li&gt;Open-source code, independently audited&lt;/li&gt;



&lt;li&gt;Lumo AI assistant included in Premium (data never used for training)&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;&lt;strong&gt;Keep in mind:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Fewer third-party integrations than Google Workspace or Microsoft 365&lt;/li&gt;



&lt;li&gt;Lumo is available on Workspace Premium only&lt;/li&gt;



&lt;li&gt;Teams migrating complex workflows may need adjustment time&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Keep your business communications private&lt;/h2&gt;



&lt;p&gt;The right internal communication tool depends on how your team works, but privacy shouldn&amp;#8217;t be a tradeoff. Look for &lt;a href=&quot;https://proton.me/business&quot;&gt;team collaboration tools&lt;/a&gt; that offer end-to-end encryption by default. &lt;/p&gt;



&lt;hr class=&quot;wp-block-separator has-alpha-channel-opacity&quot;/&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Frequently asked questions&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;How do I choose the best internal communication tool for my business?&amp;nbsp;&lt;/h3&gt;



&lt;p&gt;Consider your business&amp;#8217;s needs, such as your team&amp;#8217;s distribution and the type of communication they rely on most. &lt;/p&gt;



&lt;p&gt;Next, evaluate how the choices integrate with your existing software, or if they’re part of a suite that is easy to migrate to.&lt;/p&gt;



&lt;p&gt;Lastly, consider the platform’s security. Business communications are highly sensitive, and you should choose a tool with robust privacy protections.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Is internal communication software secure?&amp;nbsp;&lt;/h3&gt;



&lt;p&gt;Not all of them are. Many platforms collect user data and use basic encryption that keeps the providers in control of your data. &lt;/p&gt;



&lt;p&gt;Third-party integration (such as with AI assistants and note-takers) also creates additional security concerns as each app operates under its own privacy policy. &lt;/p&gt;



&lt;p&gt;Security should be a priority when choosing business communication software. Choose tools like Proton Meet and Proton Mail that protect your data with end-to-end encryption by default, ensuring your communications and data are accessible only to intended recipients.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Can internal communication tools replace email?&lt;/h3&gt;



&lt;p&gt;Not entirely. Email itself is an internal communication tool. Other tools, such as instant messaging and video conferencing software, complement email communication, enabling quick collaboration and coordination among teams. However, email is still essential for external correspondence and formal communications.&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>Introducing Proton Drive CLI: Use Drive from your terminal</title><link>https://proton.me/blog/proton-drive-cli</link><guid isPermaLink="true">https://proton.me/blog/proton-drive-cli</guid><description>Proton Drive CLI is now available for Windows, macOS, and Linux. Upload, download, share, and automate your Drive workflows from the terminal.</description><pubDate>Tue, 09 Jun 2026 11:53:13 GMT</pubDate><content:encoded>
&lt;p&gt;Last week, we finished launching the &lt;a href=&quot;https://proton.me/blog/drive-sdk-may-2026&quot;&gt;Proton Drive SDK&lt;/a&gt;, a shared engine designed to harmonize Proton Drive across all platforms and to bring you the features you need faster. Today, we&amp;#8217;re taking the next step: &lt;strong&gt;Proton Drive CLI is here, available for Windows, macOS, and Linux&lt;/strong&gt;.&lt;/p&gt;



&lt;p&gt;The CLI brings the power of our &lt;a href=&quot;https://proton.me/drive/&quot;&gt;cloud storage&lt;/a&gt; and &lt;a href=&quot;https://proton.me/drive/security&quot;&gt;end-to-end encryption&lt;/a&gt; to scripts, backups, and deployment pipelines without the hassle of writing code. It&amp;#8217;s built on the same Proton Drive SDK that powers our official Proton Drive client applications, and is fully interoperable with them.&lt;/p&gt;



&lt;p&gt;For our developer community: While &lt;strong&gt;we are developing our fully-featured Linux app&lt;/strong&gt;, the CLI already allows you to script a lot of Proton Drive&amp;#8217;s key features from your favorite scripting environments (or even schedule jobs with cron). The CLI is intended to complement the Proton Drive application. It&amp;#8217;s not a full replacement — for example, only the applications include a full synchronization engine that runs in the background — but rather a way to achieve many goals from a lightweight scripting environment.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is the CLI?&lt;/h2&gt;



&lt;p&gt;A &lt;strong&gt;command-line interface (CLI)&lt;/strong&gt; is a program you run from a shell, such as Terminal, PowerShell, or SSH. You pass a command and arguments, it does the job, and exits. Like other Unix command-line tools, you can pipe and script the Proton Drive CLI together with other tools into larger workflows.&lt;/p&gt;



&lt;p&gt;The Proton Drive CLI is a single binary you can drop into that world. It supports common Drive operations such as listing folders, uploading and downloading files, trash, sharing, or invitations. Results are displayed in plain, readable text by default — and if you&amp;#8217;re building automation on top, you can switch to a machine-friendly format using the &lt;code&gt;--json&lt;/code&gt; (or &lt;code&gt;-j&lt;/code&gt;) parameter.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How does Proton Drive CLI help?&lt;/h2&gt;



&lt;p&gt;Until now, using Proton Drive as part of an automated workflow — alongside tools like deployment scripts, backup jobs, cron, or internal runbooks — meant either doing it manually (like opening the app or dragging files) or reverse-engineering Drive&amp;#8217;s internals to write custom scripts that were brittle and hard to maintain. The CLI changes that by allowing you to run Proton Drive operations directly from the terminal. It can, for example, upload files after a build finishes, back up a folder on a schedule, invite a reviewer, or check what&amp;#8217;s been shared.&lt;/p&gt;



&lt;p&gt;This is especially useful when you need a specific action to happen at a specific time, rather than keeping folders continuously in sync, such as publishing files after a release, taking a snapshot of a shared folder before an audit, or revoking access when someone &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboards&lt;/a&gt;. The CLI runs the operation, tells you if it worked, and exits.&lt;/p&gt;



&lt;p&gt;It&amp;#8217;s a natural fit for anyone who already works in the terminal and for teams who want their Drive workflows written down as repeatable commands rather than a series of clicks to remember.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Get started with Proton Drive CLI&lt;/h2&gt;



&lt;p&gt;At launch, the CLI covers the essentials: sign in and out, browse and manage files and folders (including trash), and handle sharing and invitations.&lt;/p&gt;



&lt;p&gt;A few typical flows:&lt;/p&gt;



&lt;pre class=&quot;wp-block-preformatted&quot;&gt;proton-drive auth login&lt;br&gt;&lt;br&gt;# Upload files from local directory to folder in My files&lt;br&gt;proton-drive filesystem upload ./reports/* /my-files/Reports --conflict-strategy skip&lt;br&gt;&lt;br&gt;# See who has access, then invite a colleague&lt;br&gt;proton-drive sharing status /my-files/Reports&lt;br&gt;proton-drive sharing invite --user example@pm.me --role editor --message &quot;Please review reports&quot; /my-files/Reports&lt;br&gt;&lt;br&gt;# Download to a local backup directory&lt;br&gt;proton-drive filesystem download /my-files/Reports ./backups&lt;/pre&gt;



&lt;p&gt;For the full command set and flags, run &lt;code&gt;proton-drive help&lt;/code&gt; or &lt;code&gt;proton-drive &amp;lt;command&amp;gt; --help&lt;/code&gt;. For example, &lt;code&gt;proton-drive filesystem upload --help&lt;/code&gt;.&lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;https://proton.me/support/drive-cli&quot;&gt;Find out more about using the Proton Drive CLI&lt;/a&gt;.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What comes next&lt;/h2&gt;



&lt;p&gt;Upcoming additions to the Proton Drive CLI include support for:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/drive/photo-storage&quot;&gt;Photos and albums&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;Files and folders shared using a secure, public link&lt;/li&gt;



&lt;li&gt;Multi-account support for larger teams and managed service providers&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;Our long-term goal is to bring everything you can do in the Proton Drive app to the command line.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Download Proton Drive CLI&lt;/h2&gt;



&lt;p&gt;The fastest way to get started is to download the pre-built binaries for your platform:&lt;/p&gt;



&lt;div class=&quot;text-center&quot;&gt;&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small bg-purple-500 text-white hover:text-white focus:text-white&quot; href=&quot;https://proton.me/drive/download#desktop&quot;&gt;Download Proton Drive CLI&lt;/a&gt;&lt;/div&gt;



&lt;p&gt;On macOS and Linux, you&amp;#8217;ll need to make the file executable after downloading (&lt;code&gt;chmod +x proton-drive&lt;/code&gt;). Once that&amp;#8217;s done, run &lt;code&gt;proton-drive version&lt;/code&gt; to confirm the build.&lt;/p&gt;



&lt;p&gt;Sign-in happens through your browser — no password on the command line. Your sessions are stored securely by your operating system (Windows Credential Manager, macOS Keychain, or libsecret on Linux).&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Build from source&lt;/h3&gt;



&lt;p&gt;Prefer to build from source? The CLI is implemented in TypeScript, packaged with &lt;a href=&quot;https://bun.sh/&quot;&gt;Bun&lt;/a&gt;, and available for download in the &lt;a href=&quot;https://github.com/ProtonDriveApps/sdk&quot;&gt;Drive SDK repository&lt;/a&gt;. After cloning it, you can install the dependencies and build the CLI from the main directory:&lt;/p&gt;



&lt;pre class=&quot;wp-block-preformatted&quot;&gt;cd js/cli&lt;br&gt;bun install&lt;br&gt;bun run build&lt;br&gt;./release/proton-drive auth login&lt;br&gt;./release/proton-drive filesystem list /my-files&lt;/pre&gt;



&lt;p&gt;See the CLI README in the repository for more details.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Fair use and rate limits&lt;/h2&gt;



&lt;p&gt;Proton Drive CLI follows the same fair use policies as all Proton Drive clients. To stay within limits, only upload or download what has actually changed — don&amp;#8217;t reupload the same files repeatedly or rewrite entire folders when only a few files are new. Accounts that generate unusually high traffic are temporarily throttled to protect the service for everyone.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Now in your terminal, with the same level of privacy&lt;/h2&gt;



&lt;p&gt;Proton Drive CLI is available today, and more features will soon follow. Everything you do through the terminal is protected by the same &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end encryption&lt;/a&gt; as the rest of Proton Drive. Download it, try it, and let us know what you build. And if you&amp;#8217;re on Linux: a full-featured desktop client with sync is on its way.&lt;/p&gt;
</content:encoded><category>Product updates</category><category>Proton Drive</category><author>Michal Hořejšek</author></item><item><title>What to look for in an AI assistant</title><link>https://proton.me/business/blog/ai-assistants-for-businesses</link><guid isPermaLink="true">https://proton.me/business/blog/ai-assistants-for-businesses</guid><description>Here&apos;s what SMB founders and IT leaders should look for before connecting an AI assistant to their business data.</description><pubDate>Mon, 08 Jun 2026 18:37:16 GMT</pubDate><content:encoded>
&lt;p&gt;AI assistants have promised what most businesses lack: Efficiency without any additional cost. &lt;/p&gt;



&lt;p&gt;They can summarize your emails, respond on your behalf, decide which messages need decisions, automate calendar events, extract information from your documents, and even organize them.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;For a founder or executive at a small or medium-sized business, where needs outpace resources, it can feel like a wish granted just in time. All it asks of you is absolutely everything — access to your inbox, calendar, files, and even confidential business information.&lt;/p&gt;



&lt;p&gt;As much as 69% of firms are already using AI assistants like ChatGPT, Claude, and Grammarly — but 30% are unsure or &lt;a href=&quot;https://proton.me/business/blog/smb-cybersecurity-report&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;don&amp;#8217;t trust AI companies&lt;/a&gt; to safeguard their proprietary business data. &lt;/p&gt;



&lt;p&gt;The trade off isn’t obvious at first. But what SMBs get in efficiency, they pay for in security.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The price of efficiency &lt;/h2&gt;



&lt;p&gt;When you connect your Gmail, Google Drive, or calendar to a tool such as Perplexity’s Comet, you&amp;#8217;re granting it OAuth permissions — often beyond ‘view’ access. Depending on the scopes requested, the tool may be able to download contacts, control your entire calendar, and even write emails on your behalf.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;These permissions are technically disclosed during the authorization flow, but most users don’t fully evaluate what they mean in practice. Once granted, the tool can access and process sensitive company data at scale.&lt;/p&gt;



&lt;p&gt;The same pattern applies to other AI assistance workflows. Indexing internal knowledge bases, summarizing proprietary documents, or contextualizing company data, they all expand your exposure.&lt;/p&gt;



&lt;p&gt;When you don’t know what access you’ve granted, you can’t accurately assess the risk you’ve introduced.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How much AI assistants and browsers can see&lt;/h2&gt;



&lt;p&gt;You know AI browsers like Perplexity’s Comet or &lt;a href=&quot;https://thehackernews.com/2025/10/new-chatgpt-atlas-browser-exploit-lets.html&quot;&gt;ChatGPT’s Atlas&lt;/a&gt; can read the page you’re on, summarize it, and rewrite text. But did you know it can act on your behalf? &lt;/p&gt;



&lt;p&gt;Because the efficiency depends on deep integration, the assistant needs visibility into your browsing activity and may request access to connected accounts. In some cases, it can trigger actions rather than simply generate text.&lt;/p&gt;



&lt;p&gt;This is the architecture of AI agents more broadly. They&amp;#8217;re designed to act across connected systems. A &lt;a href=&quot;https://proton.me/blog/ai-agent&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;single compromised or manipulated agent&lt;/a&gt; can move through your email, calendar, files, and credentials in sequence.&lt;/p&gt;



&lt;p&gt;That&amp;#8217;s a consequence of how these tools are built. It creates a surface that researchers are already finding ways to exploit.&lt;/p&gt;



&lt;p&gt;Security researchers have already demonstrated how hidden instructions embedded in web content can manipulate these systems in unintended ways. &lt;/p&gt;



&lt;p&gt;One recent exploit, &amp;#8220;&lt;a href=&quot;https://layerxsecurity.com/blog/cometjacking-how-one-click-can-turn-perplexitys-comet-ai-browser-against-you/&quot;&gt;CometJacking&lt;/a&gt;,&amp;#8221; demonstrated how instructions embedded in URLs could manipulate the AI into accessing personal or company data or executing harmful actions without the user&amp;#8217;s knowledge. &lt;/p&gt;



&lt;p&gt;Vendors respond quickly with patches and safeguards. In this case, Perplexity responded with a four-layer safeguarding approach. But the pattern highlights something more fundamental: These tools are designed to interpret and act. &lt;/p&gt;



&lt;p&gt;Even Perplexity states in their &lt;a href=&quot;https://www.perplexity.ai/hub/legal/privacy-policy&quot;&gt;Privacy Policy&lt;/a&gt;: “No security measures are impenetrable, and we cannot guarantee ‘perfect security’”. The question isn&amp;#8217;t whether a tool is secure now. It&amp;#8217;s whether you’re comfortable with how much access it requires. &lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Where the burden of privacy lies&lt;/h2&gt;



&lt;p&gt;AI vendors emphasize privacy controls and opt-outs. Perplexity&amp;#8217;s Comet Assistant, for instance, assures users that &amp;#8220;Comet Assistant puts you in control&amp;#8221;.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;But those controls assume something incorrectly: that users understand how their data is processed, actively configure the relevant settings, and monitor how policies evolve over time.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;In practice, most don&amp;#8217;t. According to Proton&amp;#8217;s &lt;a href=&quot;https://proton.me/business/blog/smb-cybersecurity-report&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;2026 SMB Cybersecurity Report&lt;/a&gt;, 43% of SMBs say they can&amp;#8217;t independently verify provider privacy, and 35% don&amp;#8217;t understand how providers handle their data at all.&lt;/p&gt;



&lt;p&gt;Some information may be excluded from model training. Other data may be retained to improve personalization. Policies can differ across features and change as products develop. Turning off certain functions may limit the very capabilities that make the tool attractive in the first place.&lt;/p&gt;



&lt;p&gt;In that environment, privacy is no longer a static product promise. It becomes an ongoing operational responsibility.&amp;nbsp;&lt;/p&gt;



&lt;p&gt;The burden shifts to you, the user. You must decide what data can be shared, to monitor policy updates, to configure settings appropriately, and to reassess risk as the product evolves.&lt;/p&gt;



&lt;p&gt;This page collects practical guides and explainers on &lt;a href=&quot;https://proton.me/lumo/ai&quot; type=&quot;link&quot; id=&quot;https://proton.me/lumo/ai&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;AI privacy and security&lt;/a&gt;, so you know exactly what you&amp;#8217;re working with.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Features of a private AI assistant or AI-powered browser&lt;/h2&gt;



&lt;p&gt;Your team should be able to use an AI assistant without concern that every interaction is being stored, profiled, or used to train the next version of the model.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;No data logging. By default. &lt;/strong&gt;Your team should be able to use an AI assistant or agent without concern that every interaction is being stored, profiled, or monetized. If a tool builds &amp;#8220;memories&amp;#8221; or &amp;#8220;preferences,&amp;#8221; you should ask: Who controls this data? Is it truly off by default, or is it buried in settings? And if I turn it off, what product capabilities do I lose?&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;No model training on your business information. &lt;/strong&gt;Business documents, partners’ information, reports, or plans should never be used for AI model training. This is not only a fairness concern but also a security matter, as the data can resurface in incidents you cannot control.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Real transparency. &lt;/strong&gt;Transparency builds trust, but only if it’s real. This means that you should be able to understand, at every step, how your data is handled and what principles guide the product. If you need to spend two hours parsing Terms &amp;amp; Conditions that contradict your actual experience with the tool, that&amp;#8217;s not transparency. It’s just a tagline.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Zero-access encryption. &lt;/strong&gt;With zero-access encryption, your data is protected by keys that only you control—not even the provider can read it. This removes the need to trust policies or promises because the architecture makes misuse technically impossible.&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;Most AI tools extract value from the businesses that use them. Your conversations, documents, and files feed model training, audience profiling, and in some cases government data requests — typically without meaningful disclosure or consent. Not Lumo.&lt;/p&gt;



&lt;p&gt;Lumo is the AI assistant built for businesses that refuse afford to hand over their data for convenience. Zero-access encryption, no data logging, no model training on your business information. &lt;/p&gt;



&lt;p&gt;&lt;a href=&quot;https://lumo.proton.me/u/7/&quot; type=&quot;link&quot; id=&quot;https://lumo.proton.me/u/7/&quot;&gt;Try Lumo for free&lt;/a&gt;&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>Why business data security is a growth issue, not just a tech problem</title><link>https://proton.me/business/blog/business-data-security</link><guid isPermaLink="true">https://proton.me/business/blog/business-data-security</guid><description>Business data security can affect how you find customers, win deals, and scale without stopping to untangle early mistakes. Learn how.</description><pubDate>Mon, 08 Jun 2026 12:27:32 GMT</pubDate><content:encoded>
&lt;p&gt;No business owner wants their company to become the cautionary tale LinkedIn influencers post about. &lt;/p&gt;



&lt;p&gt;But anyone with entrepreneurship experience will know that every part of your business demands attention in the first 100 days. Everything from product development, marketing, fundraising, to hiring is a fire to put out.&lt;/p&gt;



&lt;p&gt;That&amp;#8217;s why business data security becomes an afterthought, only getting attention when something goes so wrong you can&amp;#8217;t ignore it. &lt;/p&gt;



&lt;p&gt;That could be a breach that exposes sensitive client data, a ransomware attack that stops every area of operations, or a compliance failure that only comes to light during a pre-investment security audit.&lt;/p&gt;



&lt;p&gt;Those events aren&amp;#8217;t tech problems. They&amp;#8217;re growth problems that affect whether customers trust you, whether deals close, and whether you can scale without rebuilding everything from scratch. And it all comes down to business data security.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is business data security?&lt;/h2&gt;



&lt;p&gt;Business data security is how your company controls what data it holds, where it lives, who can access it, and what happens if something goes wrong. &lt;/p&gt;



&lt;p&gt;In practice, that means choosing the right tools to store and share your business data, deciding policies to govern who has access to what, and setting defaults for how every team handles sensitive data. &lt;/p&gt;



&lt;p&gt;Keep reading to learn why building security into the foundations of your business helps it grow faster. &lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Should business data security be a part of your growth infrastructure? Key factors to consider&lt;/h2&gt;



&lt;p&gt;The way you handle data early determines your ability to grow later. &lt;/p&gt;



&lt;p&gt;It affects three concrete things — whether customers trust you, whether you can win and close enterprise deals, and whether you can scale without stopping to untangle early mistakes.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Trust &lt;/h3&gt;



&lt;p&gt;Security is now &lt;a href=&quot;https://proton.me/business/blog/smb-cybersecurity-report&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;a selling point&lt;/a&gt;. Whether you’re selling to enterprises or consumers, trust is what wins and keeps customers. &lt;/p&gt;



&lt;p&gt;Businesses want clear answers about how you handle data before they sign anything. That transparency builds confidence and assures potential clients their data will remain safe in your hands.&lt;/p&gt;



&lt;p&gt;Consumers want to know their personal data isn&amp;#8217;t being mishandled. A public breach tells them otherwise.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Compliance &lt;/h3&gt;



&lt;p&gt;SOC 2, GDPR, and HIPAA are often prerequisites for enterprise and government contracts. Those certifications determine who you can sell to and how quickly deals close. &lt;/p&gt;



&lt;p&gt;When your security posture is documented and auditable, you spend less time answering due diligence questionnaires and more time closing.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Momentum &lt;/h3&gt;



&lt;p&gt;Early security shortcuts are just points of friction that you&amp;#8217;ve deferred. When enterprise or government contracts ask about data access levels during due diligence, those shortcuts surface as a tangled web of unclear permissions that slow everything down at exactly the wrong moment.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The risk of patchwork security&lt;/h2&gt;



&lt;p&gt;&lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Four in five&lt;/a&gt; small businesses have suffered a recent data breach, and a single incident can cost over $1 million. &lt;/p&gt;



&lt;p&gt;These cybersecurity threats are common and expensive. Yet, many startups rely on default security settings from a patchwork of solutions. &lt;/p&gt;



&lt;p&gt;A default browser password vault in place of a dedicated password manager, a free-tier cloud storage account cobbled together with a second when the first runs out of space, and a consumer messaging app the team already has on their phones. Each tool is technically in place, but none are configured to meet your business&amp;#8217;s actual security needs.&lt;/p&gt;



&lt;p&gt;That fragmentation has real consequences. You might see it in the onboarding/offboarding process, when access has to be granted or revoked manually across every tool, leaving dozens of former employee with &lt;a href=&quot;https://proton.me/business/blog/spreadsheet-security-business-survey&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;an active login to your cloud storage&lt;/a&gt;.&lt;/p&gt;



&lt;p&gt;Patchwork security also means no one has a complete picture of who has access to what. Gaps don&amp;#8217;t announce themselves. They hide in the spaces between tools until something goes wrong.&lt;/p&gt;



&lt;p&gt;Establishing secure defaults reveal security gaps. When there&amp;#8217;s a standard for how data is stored, shared, and accessed, anything outside that standard stands out, like unusual access requests or unexpected 2FA requests. Without defaults, nothing looks unusual, so security gaps hide in plain sight.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Where do you start with business data security?&lt;/h2&gt;



&lt;p&gt;It’s impossible to solve every security problem on day one. Instead, build a strong foundation that covers how data moves, where it lives, and who can access it.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Secure your business email&lt;/h3&gt;



&lt;p&gt;Businesses live on email, so make sure you choose an &lt;a href=&quot;https://proton.me/business/mail&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;encrypted email&lt;/a&gt; solution. &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;End-to-end encryption&lt;/a&gt; protects your emails from unauthorized access, rendering their content unreadable to snoops. This is important protection, as unsecured email leaves sensitive communication exposed.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Store data in encrypted cloud storage&lt;/h3&gt;



&lt;p&gt;Your intellectual property, customer data, and financial documents all need secure storage. Choose encrypted &lt;a href=&quot;https://proton.me/business/drive&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;cloud storage&lt;/a&gt; with built-in granular access controls to ensure only the right people can access sensitive data.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Control identity and access&lt;/h3&gt;



&lt;p&gt;Ensure that every team member has individual credentials, not shared accounts, and that they use a &lt;a href=&quot;https://proton.me/business/pass&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;password manager&lt;/a&gt;. This way, you can control access levels to match their roles, so you don&amp;#8217;t have to default to admin permissions for everyone. Equally important, ensure access is completely revoked when an employee leaves.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Make business data security your growth advantage&lt;/h2&gt;



&lt;p&gt;&lt;a href=&quot;https://proton.me/business&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Proton for Business&lt;/a&gt; is the simple way to build a strong security foundation for your business. &lt;/p&gt;



&lt;p&gt;With encrypted &lt;a href=&quot;https://proton.me/business/mail&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;email&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/drive&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;cloud storage&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/vpn&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;VPN&lt;/a&gt;, and a &lt;a href=&quot;https://proton.me/business/pass&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;password manager&lt;/a&gt; in one secure, compliance-ready suite. It&amp;#8217;s how over 50,000 businesses have built their security baseline without adding complexity. Get started for free. &lt;/p&gt;



&lt;p&gt;&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item></channel></rss>