10 rules
- Two-factor protection on every mailbox and cloud drive.
- A password manager instead of sticky notes and one password for everything.
- Every employee has their own login — no shared accounts.
- Role-based access rights.
- Laptop disk encryption (BitLocker) — a stolen laptop does not leak documents.
- Automatic Windows and software updates, antivirus.
- A daily backup plus one copy unreachable from the office network.
- Guest Wi-Fi for seafarers, separate from the work network.
- Beware of “shipowner” emails with new bank details or “log in to open the document” links — common phishing.
- When someone leaves, close their access the same day and change shared passwords.
Law and technology
Georgia has a personal data protection law. Legal requirements are a question for a lawyer; the technical side — passwords, access, encryption, backups — is my job. I am a lawyer by first degree, so I speak the same language as your legal adviser.
What I do
I check the office against these rules, set up what is missing and leave a short memo for staff.
FAQ
Questions and answers
How long does the check take?
For a small office usually one visit; I quote after seeing the office, before any work.
Does a 3-computer office need all this?
Yes: the risk is the same, and the setup is simpler and quicker.
More for crewing agencies
IT for crewing agenciesCrewing emails in spam: SPF, DKIM and DMARC in plain wordsScams in your agency’s name: how to protect itA setup for online tests and seafarer video interviewsA digital archive of seafarers' documentsCrewing office IT checklist: 20 points in 10 minutesSeafarer vacancies: website, Telegram and Facebook in a minuteAll articles