Security Best Practices

Protecting sensitive payroll data requires a layered security approach. This guide provides recommended security practices for ProPay WEB administrators, payroll processors, and users to safeguard employee information, financial data, and system access.

Why Security Matters

ProPay WEB handles highly sensitive information including:

  • Social Security numbers
  • Bank account information for direct deposits
  • Wage and salary data
  • Personal employee information
  • Tax withholding details

A security breach can result in identity theft, financial fraud, regulatory penalties, and loss of client trust. Following these best practices helps protect your business and your clients.

Server and Network Security

Keep Systems Updated

Operating System Updates

  • Enable automatic Windows updates or check weekly
  • Install security patches promptly
  • Restart the server when updates require it
  • Schedule updates during off-hours to minimize disruption

Software Updates

  • Keep ProPay updated to the latest version
  • Update IIS and related components
  • Apply browser updates on all computers accessing ProPay WEB

Firewall Configuration

Router Firewall

  • Keep router firmware updated
  • Change default administrator password
  • Disable remote administration unless required
  • Only forward necessary ports (80 for HTTP, 443 for HTTPS)
  • Enable logging and review logs periodically

Windows Firewall

  • Keep Windows Firewall enabled
  • Only allow necessary applications (IIS, ProPay)
  • Create specific rules rather than disabling the firewall
  • Review firewall rules quarterly

> Important: Never disable the firewall to troubleshoot connectivity issues. Instead, create specific exceptions for required services.

Use SSL/HTTPS

Enable HTTPS

  • Install an SSL certificate on your server
  • Redirect all HTTP traffic to HTTPS
  • Use TLS 1.2 or higher (disable older protocols)
  • Renew certificates before expiration

SSL Best Practices

  • Use certificates from trusted Certificate Authorities
  • Choose 2048-bit or higher encryption
  • Enable HSTS (HTTP Strict Transport Security)
  • Test SSL configuration with online tools like SSL Labs

See SSL Certificate Setup for detailed installation instructions.

User Account Security

Password Policies

Enforce Strong Passwords

  • Minimum 8 characters (12+ recommended)
  • Mix of uppercase, lowercase, numbers, and symbols
  • No dictionary words or personal information
  • Different passwords for different accounts

Password Management

  • Change passwords every 90 days
  • Never share passwords between users
  • Use a password manager for secure storage
  • Immediately change compromised passwords

See Password Policies for complete password guidelines.

User Access Control

Principle of Least Privilege

  • Give users only the access they need
  • Use access levels appropriate to job duties
  • Restrict administrative accounts to essential personnel
  • Review and update access rights quarterly

Access Level Guidelines

User Type Recommended Access Why
Business owner Level 9 (Unrestricted) Full oversight of their company
Payroll clerk Level 4 or 5 Data entry without admin functions
HR manager Level 3 Employee management without payroll
Report viewer Level 1 View-only access
Department manager Department-restricted Access to their department only

Departmental Restrictions

  • Use departmental access to limit data visibility
  • Separate sensitive positions (executives) from general staff
  • Ensure at least one user has full access for payroll submission

Account Lifecycle Management

New Users

  • Verify identity before creating accounts
  • Assign temporary password that expires on first login
  • Document account creation
  • Train users on security policies

Departing Users

  • Remove access immediately upon termination
  • Reset passwords if accounts cannot be deleted
  • Review any shared credentials
  • Audit recent activity for anomalies

Regular Reviews

  • Audit user accounts quarterly
  • Remove inactive accounts
  • Verify access levels remain appropriate
  • Document review findings

Data Protection

Backup Strategies

Regular Backups

  • Back up ProPay data daily
  • Include the entire PAYSOFT folder
  • Store backups in multiple locations (local and cloud)
  • Encrypt backup files

Backup Testing

  • Test restore procedures monthly
  • Verify backup integrity
  • Document recovery steps
  • Keep backup documentation current

Offsite Storage

  • Store backup copies away from your office
  • Use encrypted cloud storage services
  • Protect against theft, fire, and natural disasters
  • Consider a standby server at a separate location

Physical Security

Server Room

  • Limit physical access to authorized personnel
  • Lock server room or computer area
  • Use security cameras if appropriate
  • Maintain access logs

Workstations

  • Position monitors away from public view
  • Use privacy screens where needed
  • Lock computers when unattended
  • Secure mobile devices and laptops

Safe Computing Practices

For Administrators

Protect Administrator Credentials

  • Use unique, strong passwords for admin accounts
  • Never save admin passwords in browsers
  • Log out of admin sessions when finished
  • Use separate accounts for admin and daily work

Monitor System Activity

  • Review login reports regularly
  • Investigate failed login attempts
  • Watch for unusual access patterns
  • Address suspicious activity immediately

Secure Remote Access

  • Use VPN for remote administration
  • Enable two-factor authentication where possible
  • Limit remote access hours if feasible
  • Log all remote sessions

For All Users

Login Security

  • Never share your username or password
  • Log out when finished (especially on shared computers)
  • Lock your computer when stepping away
  • Report suspicious activity to your administrator

Safe Browsing

  • Verify you're on the correct ProPay WEB URL
  • Look for the padlock icon and HTTPS
  • Don't access ProPay WEB from public Wi-Fi without VPN
  • Clear browser cache on shared computers

Email Security

  • Never send passwords via email
  • Be cautious of phishing emails
  • Verify requests for credential changes
  • Report suspicious emails immediately

Preventing Social Engineering

Verify Identity

  • Confirm caller identity before providing information
  • Call back on a known number if suspicious
  • Don't provide credentials to anyone claiming to be support
  • Report social engineering attempts

What Paysoft Will Never Ask

  • Your password
  • Credit card information via email
  • Remote access to your computer without prior arrangement
  • Social Security numbers via phone or email

Incident Response

If You Suspect a Breach

  1. Contain - Change passwords and disable compromised accounts
  2. Assess - Determine what data may have been accessed
  3. Notify - Contact affected parties and Paysoft support
  4. Document - Record all details of the incident
  5. Remediate - Fix vulnerabilities that allowed the breach
  6. Review - Update security practices to prevent recurrence

Password Compromise

If a password may be compromised:

  1. Change the password immediately
  2. Review recent activity for that account
  3. Check for unauthorized changes
  4. Notify affected users
  5. Document the incident

Suspicious Activity

Report immediately if you notice:

  • Unfamiliar login activity
  • Changes you didn't make
  • Missing or altered data
  • Unexpected password reset requests
  • Strange system behavior

Compliance Considerations

Data Privacy

Employee Data

  • Collect only necessary information
  • Limit access to sensitive data
  • Dispose of unneeded records securely
  • Comply with data retention requirements

Client Data

  • Maintain client confidentiality
  • Use departmental access to separate client data
  • Follow industry data handling standards
  • Document data protection procedures

Audit Preparedness

Maintain Records

  • Login activity logs
  • User access changes
  • Password reset history
  • Security incident reports

Regular Reviews

  • Document security procedures
  • Update procedures when systems change
  • Train staff on security requirements
  • Test incident response plans

Security Checklist

Use this checklist for regular security reviews:

Monthly

  • [ ] Review login activity reports
  • [ ] Check for failed login patterns
  • [ ] Verify backup completion
  • [ ] Test backup restoration

Quarterly

  • [ ] Audit user accounts and access levels
  • [ ] Remove inactive users
  • [ ] Review firewall rules
  • [ ] Check SSL certificate expiration
  • [ ] Update passwords for shared accounts

Annually

  • [ ] Review overall security policies
  • [ ] Update incident response procedures
  • [ ] Conduct security awareness training
  • [ ] Test disaster recovery plan
  • [ ] Evaluate new security tools and practices

Getting Help

Security Questions Contact Paysoft support for:

  • Security configuration assistance
  • Best practice recommendations
  • Incident response guidance
  • Security feature questions

Suspected Security Issues Report immediately to:

  • Your IT administrator
  • Your payroll processor
  • Paysoft technical support

Related Topics

← Back to Index