Security Best Practices
Protecting sensitive payroll data requires a layered security approach. This guide provides recommended security practices for ProPay WEB administrators, payroll processors, and users to safeguard employee information, financial data, and system access.
Why Security Matters
ProPay WEB handles highly sensitive information including:
- Social Security numbers
- Bank account information for direct deposits
- Wage and salary data
- Personal employee information
- Tax withholding details
A security breach can result in identity theft, financial fraud, regulatory penalties, and loss of client trust. Following these best practices helps protect your business and your clients.
Server and Network Security
Keep Systems Updated
Operating System Updates
- Enable automatic Windows updates or check weekly
- Install security patches promptly
- Restart the server when updates require it
- Schedule updates during off-hours to minimize disruption
Software Updates
- Keep ProPay updated to the latest version
- Update IIS and related components
- Apply browser updates on all computers accessing ProPay WEB
Firewall Configuration
Router Firewall
- Keep router firmware updated
- Change default administrator password
- Disable remote administration unless required
- Only forward necessary ports (80 for HTTP, 443 for HTTPS)
- Enable logging and review logs periodically
Windows Firewall
- Keep Windows Firewall enabled
- Only allow necessary applications (IIS, ProPay)
- Create specific rules rather than disabling the firewall
- Review firewall rules quarterly
> Important: Never disable the firewall to troubleshoot connectivity issues. Instead, create specific exceptions for required services.
Use SSL/HTTPS
Enable HTTPS
- Install an SSL certificate on your server
- Redirect all HTTP traffic to HTTPS
- Use TLS 1.2 or higher (disable older protocols)
- Renew certificates before expiration
SSL Best Practices
- Use certificates from trusted Certificate Authorities
- Choose 2048-bit or higher encryption
- Enable HSTS (HTTP Strict Transport Security)
- Test SSL configuration with online tools like SSL Labs
See SSL Certificate Setup for detailed installation instructions.
User Account Security
Password Policies
Enforce Strong Passwords
- Minimum 8 characters (12+ recommended)
- Mix of uppercase, lowercase, numbers, and symbols
- No dictionary words or personal information
- Different passwords for different accounts
Password Management
- Change passwords every 90 days
- Never share passwords between users
- Use a password manager for secure storage
- Immediately change compromised passwords
See Password Policies for complete password guidelines.
User Access Control
Principle of Least Privilege
- Give users only the access they need
- Use access levels appropriate to job duties
- Restrict administrative accounts to essential personnel
- Review and update access rights quarterly
Access Level Guidelines
| User Type | Recommended Access | Why |
|---|---|---|
| Business owner | Level 9 (Unrestricted) | Full oversight of their company |
| Payroll clerk | Level 4 or 5 | Data entry without admin functions |
| HR manager | Level 3 | Employee management without payroll |
| Report viewer | Level 1 | View-only access |
| Department manager | Department-restricted | Access to their department only |
Departmental Restrictions
- Use departmental access to limit data visibility
- Separate sensitive positions (executives) from general staff
- Ensure at least one user has full access for payroll submission
Account Lifecycle Management
New Users
- Verify identity before creating accounts
- Assign temporary password that expires on first login
- Document account creation
- Train users on security policies
Departing Users
- Remove access immediately upon termination
- Reset passwords if accounts cannot be deleted
- Review any shared credentials
- Audit recent activity for anomalies
Regular Reviews
- Audit user accounts quarterly
- Remove inactive accounts
- Verify access levels remain appropriate
- Document review findings
Data Protection
Backup Strategies
Regular Backups
- Back up ProPay data daily
- Include the entire PAYSOFT folder
- Store backups in multiple locations (local and cloud)
- Encrypt backup files
Backup Testing
- Test restore procedures monthly
- Verify backup integrity
- Document recovery steps
- Keep backup documentation current
Offsite Storage
- Store backup copies away from your office
- Use encrypted cloud storage services
- Protect against theft, fire, and natural disasters
- Consider a standby server at a separate location
Physical Security
Server Room
- Limit physical access to authorized personnel
- Lock server room or computer area
- Use security cameras if appropriate
- Maintain access logs
Workstations
- Position monitors away from public view
- Use privacy screens where needed
- Lock computers when unattended
- Secure mobile devices and laptops
Safe Computing Practices
For Administrators
Protect Administrator Credentials
- Use unique, strong passwords for admin accounts
- Never save admin passwords in browsers
- Log out of admin sessions when finished
- Use separate accounts for admin and daily work
Monitor System Activity
- Review login reports regularly
- Investigate failed login attempts
- Watch for unusual access patterns
- Address suspicious activity immediately
Secure Remote Access
- Use VPN for remote administration
- Enable two-factor authentication where possible
- Limit remote access hours if feasible
- Log all remote sessions
For All Users
Login Security
- Never share your username or password
- Log out when finished (especially on shared computers)
- Lock your computer when stepping away
- Report suspicious activity to your administrator
Safe Browsing
- Verify you're on the correct ProPay WEB URL
- Look for the padlock icon and HTTPS
- Don't access ProPay WEB from public Wi-Fi without VPN
- Clear browser cache on shared computers
Email Security
- Never send passwords via email
- Be cautious of phishing emails
- Verify requests for credential changes
- Report suspicious emails immediately
Preventing Social Engineering
Verify Identity
- Confirm caller identity before providing information
- Call back on a known number if suspicious
- Don't provide credentials to anyone claiming to be support
- Report social engineering attempts
What Paysoft Will Never Ask
- Your password
- Credit card information via email
- Remote access to your computer without prior arrangement
- Social Security numbers via phone or email
Incident Response
If You Suspect a Breach
- Contain - Change passwords and disable compromised accounts
- Assess - Determine what data may have been accessed
- Notify - Contact affected parties and Paysoft support
- Document - Record all details of the incident
- Remediate - Fix vulnerabilities that allowed the breach
- Review - Update security practices to prevent recurrence
Password Compromise
If a password may be compromised:
- Change the password immediately
- Review recent activity for that account
- Check for unauthorized changes
- Notify affected users
- Document the incident
Suspicious Activity
Report immediately if you notice:
- Unfamiliar login activity
- Changes you didn't make
- Missing or altered data
- Unexpected password reset requests
- Strange system behavior
Compliance Considerations
Data Privacy
Employee Data
- Collect only necessary information
- Limit access to sensitive data
- Dispose of unneeded records securely
- Comply with data retention requirements
Client Data
- Maintain client confidentiality
- Use departmental access to separate client data
- Follow industry data handling standards
- Document data protection procedures
Audit Preparedness
Maintain Records
- Login activity logs
- User access changes
- Password reset history
- Security incident reports
Regular Reviews
- Document security procedures
- Update procedures when systems change
- Train staff on security requirements
- Test incident response plans
Security Checklist
Use this checklist for regular security reviews:
Monthly
- [ ] Review login activity reports
- [ ] Check for failed login patterns
- [ ] Verify backup completion
- [ ] Test backup restoration
Quarterly
- [ ] Audit user accounts and access levels
- [ ] Remove inactive users
- [ ] Review firewall rules
- [ ] Check SSL certificate expiration
- [ ] Update passwords for shared accounts
Annually
- [ ] Review overall security policies
- [ ] Update incident response procedures
- [ ] Conduct security awareness training
- [ ] Test disaster recovery plan
- [ ] Evaluate new security tools and practices
Getting Help
Security Questions Contact Paysoft support for:
- Security configuration assistance
- Best practice recommendations
- Incident response guidance
- Security feature questions
Suspected Security Issues Report immediately to:
- Your IT administrator
- Your payroll processor
- Paysoft technical support
Related Topics
- Employer User Management
- Password Policies
- SSL Certificate Setup
- Router and Firewall Configuration
- Employee Portal
- Employer Portal
- ProPay WEB Overview