A new app can save time by connecting to Microsoft 365, accounting software, customer records or cloud storage. That connection may also give the app access to business data and the ability to act on your behalf.
The risk is not a reason to avoid every integration. It is a reason to check what the app can reach, who is responsible for it and how you will remove it if something goes wrong.
Why integrations need a closer look
Most small businesses use outside software for payments, support, reporting and file sharing. Building every function in-house is rarely practical.
Problems arise when an app receives more access than it needs, keeps data in an unexpected location or becomes essential to a daily process without a recovery plan.
A weak or compromised integration could expose information, interrupt work or allow unauthorised changes. An outage at the provider could also stop an important business process even when no attack has occurred.
What to check before connecting an app
Confirm the business need
Write down what the app is meant to do and who owns the decision. If an existing approved tool already does the job, another connection may add risk without adding much value.
Review the access request
Read the permission screen before approving it. Does the app need to read every mailbox, edit all files or access every customer record?
Ask for the narrowest access that will let it do the job. Be especially careful with access requested for the whole organisation or with administrator approval.
Find out what data the provider receives
Ask what information the app collects, where it is stored, how long it is kept and whether other providers handle it. Check how the provider deletes your data when you close the account.
If the app will handle personal, financial or health information, get suitable privacy or legal advice before connecting it.
Check the provider's security evidence
Look for current, independent evidence that matches the service you plan to use. This may include a recognised security certification, an independent controls report or recent testing results.
Do not rely on a badge alone. Check its scope, date and whether it covers the actual product and data centre involved.
Check access and administrator controls
The app should support individual user accounts, multi-factor authentication and clear access levels. Avoid shared administrator logins. Ask how staff access is removed, how important settings are protected and whether the business can see who made a change.
Plan for incidents, outages and exit
Find out how the provider reports an incident and what support is available during an outage. Decide what staff will do if an important app is unavailable and keep a way to retrieve essential information where practical.
Check who owns the data, what the provider is responsible for and how you can export and delete information when the service ends. Larger or higher-risk arrangements may need contract, privacy or legal review.
Keep a list of connected apps and the person responsible for each one. Review access when staff leave or an app changes purpose, and remove connections that are no longer used. Closing a user account may not remove an organisation-wide connection, so check the main administration area as well.
Make app approval a business process
Staff should know who can approve a new connection and what information is required. A short, consistent check is better than discovering an unknown app after it has had access for months.
Before approving another app, ask JCPIT about an integration review. We will confirm the systems and access in scope before reviewing existing connections or helping you set an approval process.