The Unique Cyber Risk Facing UK Cleaning Companies
On the surface, a cleaning company's digital footprint seems minimal. A website, an enquiry form, maybe an online booking system. But the data that flows through those simple systems is disproportionately sensitive in one critical way: your clients give you access to their properties.
A client who books a regular domestic clean with you has shared their home address, their preferred entry arrangements — potentially including alarm codes, key safe combinations, or key custody details — their schedule (when they'll be away from home), and payment information. For a commercial cleaning client, that extends to building access codes, security pass procedures, and the cleaning schedules of office premises that may contain valuable equipment or confidential records.
This combination of access data and schedule information makes a compromised cleaning company booking system a different kind of threat than a typical data breach. The risk isn't just financial — it's physical. An attacker who knows your clients' home access arrangements, alarm codes, and when they're away from the property has the intelligence needed for a burglary.
This guide covers the specific risks facing UK cleaning businesses online and what to do about them.
What Data Does a Cleaning Company Collect?
**Client contact details** — Names, phone numbers, email addresses, and home or office addresses for all active and former clients.
**Property access information** — Key arrangements (key held by agency, key safe code, alarm code, gate code, building access procedure). This data is acutely sensitive: it's effectively a how-to guide for entering a property.
**Cleaning schedules** — When each client's clean takes place and how frequently. Combined with access information, this tells an attacker exactly when a property will be occupied by a cleaner rather than the owner.
**Client absence information** — Some cleaning clients provide information about holidays or extended absences to arrange different service levels. This tells an attacker when a property will be completely empty.
**Payment data** — Direct debit mandates, standing order references, card details for one-off payments, and invoicing information.
**Staff records** — DBS check references, ID verification, payroll data, and working schedules for cleaning staff.
**Keyholding records** — If your company holds physical keys on behalf of clients, your records of which keys belong to which clients are a physical security asset that must be treated digitally.
How Attackers Target Cleaning Company Websites
Database Extraction via SQL Injection
Your client database — containing addresses, access codes, and schedules — is the target. A SQL injection vulnerability in your booking form, contact form, or client login portal can give an attacker direct read access to your database tables.
This doesn't require sophisticated hacking. Many cleaning company websites run on WordPress with off-the-shelf booking plugins that have known, publicly documented vulnerabilities. An attacker doesn't need to discover a new vulnerability — they need to know your plugin version and run a published exploit.
Client Portal Access
Some cleaning companies offer a client login portal for booking management, invoice access, and schedule viewing. If these portals have weak authentication — no account lockout after failed attempts, no MFA, sequential user IDs that allow account enumeration — an attacker can work through accounts systematically.
Once inside a client account, they have access to exactly the information that's dangerous: the client's address, their cleaning schedule, and potentially their access arrangements.
Admin Account Compromise
Your back-end admin system contains your entire client list, all access notes, and all schedules. An admin account is compromised through:
- **Weak or reused passwords** — if your admin password is the same one you use for another service that's been breached, an attacker can find it in leaked credential databases - **No multi-factor authentication** — a password alone isn't sufficient protection for an account with access to hundreds of clients' physical access details - **Phishing** — cleaning business owners and managers receive email at the same address that's publicly listed on their website; targeted phishing campaigns are straightforward
Insider Threats via Web Systems
Former staff who retain access to your client management system represent a risk. A cleaning operative who leaves on bad terms and still has their login credentials can access client information — including addresses and access details — unless accounts are promptly deactivated.
If your staff access client records through a web portal, those sessions must be properly terminated on employment end and access logs should be reviewed for anomalous activity.
UK GDPR and Cleaning Companies
Cleaning companies are data controllers under UK GDPR. The specific GDPR risks in this industry:
**Access code information is sensitive personal data in context** — While alarm codes aren't explicitly listed as a special category under UK GDPR, the combination of access codes with addresses and schedules creates a data set that could directly enable harm to individuals. The ICO expects you to apply appropriate security proportionate to the risk that data could cause if misused.
**Client absence data is highly sensitive** — Information about when clients will be away from their property is data whose misuse could directly enable burglary. You have a strong obligation to keep it secure and to minimise how long you retain it.
**Right to erasure** — Clients who end their service with you can request deletion of their data. You need to be able to actually do this, including deleting access codes and schedules from all systems — not just your main database, but any backups, spreadsheets, or email threads where this data lives.
**Staff DBS data** — DBS check certificates and references must be handled with care. They reveal criminal record information and must be retained only as long as necessary.
**72-hour breach notification** — If your client database is compromised, the ICO must be notified within 72 hours. Given that the stolen data includes physical access information, you may also have an obligation to notify clients immediately so they can change their alarm codes and key arrangements.
Practical Security for Cleaning Companies
**Separate access information from general client records where possible** — Don't store alarm codes and key arrangements in the same database table as contact information. Compartmentalisation limits the blast radius of any breach.
**Enforce strong passwords and MFA on admin accounts** — Anyone who can log in to your client management system should use a strong unique password and multi-factor authentication. This is the single most impactful security measure you can take.
**Audit staff access regularly** — Review who has access to your client management system and remove access promptly when staff leave.
**Use HTTPS everywhere** — Every page on your website, especially any that handle login or booking, must use HTTPS. Never transmit access codes or client data over unencrypted connections.
**Keep your website software updated** — WordPress, booking plugins, and CRM systems release security updates regularly. Outdated versions are a primary attack vector.
**Don't store more than you need** — If a client changes their alarm code, delete the old one. If a client ends their service, implement a defined retention period rather than keeping their access data indefinitely.
**Encrypt access code data at rest** — If your system stores access codes and alarm codes, they should be encrypted in your database so that a database export doesn't immediately give an attacker usable access credentials.
Penetration Testing for Cleaning Companies
A web application penetration test for a UK cleaning company covers your booking and enquiry forms, your client portal (if you have one), your admin panel, and any integrations with scheduling or invoicing software.
Key findings to expect:
- SQL injection in booking forms exposing client database - IDOR in client portal URLs exposing other clients' schedules - Weak authentication on admin panel - Missing security headers - Outdated plugin vulnerabilities
Yrzo AI's continuous automated penetration testing catches these vulnerabilities as they emerge, running against your live website and alerting you before they can be exploited. At a price point designed for small businesses, it's accessible to independent cleaning companies and national franchises alike.
**[Protect your clients' access data → Start your free trial at yrzoai.dev](https://yrzoai.dev)**
Your clients trust you with the keys to their homes. That trust extends to how you protect their data online.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →