Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

IT Support for Recruitment Agencies in the UK

In short

Recruitment agencies hold huge volumes of candidate personal data and move money through placements and invoices, which makes them a natural target. This guide covers protecting candidate data under UK GDPR, securing your CRM/ATS, keeping mobile consultants safe, and stopping the invoice fraud that hits placements.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

Why recruitment agencies are a target

Recruitment agencies sit on exactly what criminals want. A single consultant’s inbox can hold CVs, right-to-work documents, references, contractor bank details and signed client contracts. Multiply that across your team and your CRM, and you are one of the largest holders of personal data of any small business your size. On top of that, money moves through your business constantly: placement fees, contractor payroll, client invoices. Data plus money movement is the combination attackers look for.

The good news is that you do not need to become a technical expert to manage this well. You need a handful of sensible controls, applied consistently, and someone keeping an eye on them. This guide walks through the parts that matter most for an agency.

Candidate personal data is your biggest responsibility

Under UK GDPR, every candidate record you hold is personal data, and some of it is sensitive: health information disclosed for a role, criminal record checks, right-to-work documents showing nationality. You are the data controller, which means the law holds you responsible for keeping it safe and using it fairly.

A few practical foundations go a long way:

  • Know what you hold and where. CVs in a shared inbox, a spreadsheet on someone’s laptop, and old records in a former consultant’s mailbox are all liabilities. If you cannot list where candidate data lives, you cannot protect it.
  • Only keep what you still need. Set a retention period and stick to it. Holding thousands of CVs from five years ago is risk with no reward.
  • Be ready for candidate requests. People have the right to ask what you hold about them. Knowing how to respond calmly is part of running a professional agency.
  • Register with the ICO. Most agencies must pay the annual data protection fee. It is inexpensive and easily overlooked.

If UK GDPR still feels vague, our GDPR basics for UK small business guide breaks it down without the jargon.

Securing your CRM or ATS

Your CRM or applicant tracking system is the heart of the agency, and it is also the single system that would hurt most if it were breached or lost. Whether you use a cloud recruitment platform or something more bespoke, the same principles apply.

Turn on multi-factor authentication for every user. A password alone is not enough to protect a database of thousands of people. MFA means that even if a password is stolen or guessed, the attacker still cannot get in. If you are not sure what that involves, see multi-factor authentication explained.

Control who can see and export what. Not every consultant needs the ability to bulk-export the entire candidate database. Limiting export rights reduces both the damage from a compromised account and the risk of data walking out of the door when someone leaves.

Remove access the day someone leaves. Recruitment has natural churn. A leaver whose accounts are still active weeks later is a genuine exposure. This should be a routine step, not something you remember later.

Check your data location and backups. Know where your provider stores data and how it is backed up. Reputable cloud tools handle a lot of this, but you should still understand what happens if the service goes down or a record is deleted by mistake.

Mobile and remote working, done safely

Consultants live on their phones and laptops: interviewing at client sites, sourcing on the train, taking calls from home. That flexibility is a strength, but it means candidate data travels everywhere too.

The aim is simple: make the security travel with the device.

  • Encrypt every device. If a laptop or phone is lost, encryption means the data on it stays unreadable. On modern devices this is often just a setting to switch on and confirm.
  • Use a password manager. Consultants juggle logins for job boards, LinkedIn, the CRM, email and more. A password manager gives each one a strong, unique password without anyone having to remember them. Our guide to the best password manager for a small business covers the options, and tools such as Proton Pass make this straightforward for a distributed team.
  • Use a VPN on public Wi-Fi. Sending candidate data over café or hotel Wi-Fi without protection is a needless risk. A business VPN such as Proton VPN encrypts the connection so it cannot be snooped on.
  • Be able to wipe a lost device. Phones and laptops go missing. The ability to remotely lock or wipe a device turns a crisis into an inconvenience.

A single tricked payment can cost thousands, so verifying any change of bank details by phone is one of the highest-value habits you can build.

Email fraud: the placement and invoice trap

This is where agencies lose real money. Criminals understand your workflow. They know that placements end in invoices, and that contractors get paid. So they wait for the moment money changes hands and step in.

Two scams dominate:

  1. The changed bank details. An email arrives, apparently from a contractor, a client or even your own finance person, saying the bank details have changed for an upcoming payment. It looks legitimate. If you pay without checking, the money is gone.
  2. The fake invoice. A convincing invoice lands, matching a real placement, but the account it points to belongs to the fraudster.

This is a form of business email compromise, and it is one of the most costly frauds hitting UK small businesses. Our explainer on business email compromise shows how these attacks are built.

Defending against it is more about habit than technology:

  • Verify any change of bank details by phone, using a number you already hold, never the number in the email.
  • Slow down payment approvals. Urgency is the fraudster’s main weapon. A short pause to check is not bureaucracy, it is protection.
  • Train the team to spot the signs. Most of these emails carry tells. Learn them with our guide on how to spot a phishing email.
  • Tighten your Microsoft 365 settings so more of the obvious fakes never reach an inbox. Our Microsoft 365 security settings piece is a good starting point.

Backups and business continuity

Imagine your CRM is unavailable for two days, or a ransomware attack locks your files. How does the agency keep placing candidates? Backups are the answer to the question you hope you never have to ask.

Good practice is straightforward: keep more than one copy of your important data, keep at least one copy somewhere separate from your main systems, and test that you can actually restore it. A backup you have never tested is a hope, not a plan.

Where DACROS fits in

Most agencies do not want an in-house IT department; they want the technology to work, the data to be safe, and someone to call when it is not. That is what managed IT support provides. If the term is new to you, our overview of what managed IT support is explains the model.

At DACROS we help Leeds and Yorkshire recruitment agencies get the fundamentals right: securing your CRM and email, setting up mobile working properly, achieving Cyber Essentials, and keeping everything backed up and monitored. You can see the full picture on our services page, and our pricing is built for small businesses rather than large corporates.

If you would like a plain-English review of where your agency stands, get in touch. No jargon, no pressure, just a clear picture of your risks and what to do about them.

Frequently asked questions

Do recruitment agencies need to be registered with the ICO?

Almost certainly, yes. If you process candidate and client personal data (which every agency does), you are a data controller and normally need to pay the ICO data protection fee. It is an annual fee, usually a modest amount for a small business, and being unregistered is a common and easily avoidable compliance gap.

How long can we keep candidate CVs and data?

UK GDPR does not set a fixed number, but you must only keep personal data for as long as you have a genuine reason to. Many agencies set a retention period (for example, revisiting candidate records every couple of years) and delete or re-consent after that. Write your policy down, apply it consistently, and be ready to explain it.

What is the biggest cyber risk for a recruitment agency?

Email-based fraud is usually top of the list. Criminals target the moment money changes hands, sending fake invoices or changed bank details for a placement or a contractor's payment. A single tricked payment can cost thousands, so verifying any change of bank details by phone is one of the highest-value habits you can build.

Can consultants safely work from their phones and cafes?

Yes, with the right setup. Use company-managed accounts with multi-factor authentication, a password manager, encryption on every device, and the ability to remotely wipe a lost phone or laptop. Avoid sending candidate data over public Wi-Fi without a VPN. Mobile working is fine when the security travels with the device.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.