A small NAS will be fine but make sure you use passwords, RAID one or five, encryption and backup if it's for business especially if it's holding customer details. GDPR says if you don't you could cop it. These are all usually free and implementing them just takes a little time.
It will also be...