Accounts
An individual account for each person instead of one shared, rights by role, and regular pruning of the authorised list.
Measures are chosen to match the required level of protection. We do not add excess: unnecessary restrictions get in people way and add nothing.
An individual account for each person instead of one shared, rights by role, and regular pruning of the authorised list.
We record who accessed the data and when, and keep those records. Without them investigating an incident is impossible in principle.
The servers and databases where the information physically sits: a separate segment and restricted connections.
Encryption whenever traffic leaves the controlled zone, including branches and people working from home.
Restricting removable media, printing and attachments where the nature of the work justifies it.
Backup with regular restore testing and protection of the copies themselves against encryption.
We proceed in stages and start with what gives the greatest effect and interferes least with the work.
We classify the system and obtain a list of mandatory measures. After that we follow it strictly.
We eliminate shared passwords, switch on logging and sort out rights. It takes days and the payoff is noticeable.
Network zoning, boundary protection, encrypted links, control of removable media.
We try to reach data where we should not be able to and see whether it lands in the logs.
Accounts of former employees live on for years. Someone left six months ago and their login still works and still reaches the client database. Revoking rights on departure should be part of the HR procedure, not the goodwill of an administrator.
With understanding where information about people is held. Usually that is not only the accounting system: spreadsheets turn up on the shared drive, exports in mail, copies on laptops. Until a list exists there is nothing to protect - it is unclear what.
No. Encryption is justified where the medium can physically leave the office: laptops, removable disks, backups, communication links. Encrypting a desktop in a locked office makes little sense.
Quickly establish the scale, close the channel and work out how it happened. You must act to a procedure written beforehand: improvising during an incident is expensive. We prepare such a procedure separately.
Write where information about your employees and clients is held. We will look at what is closed and what is open to everyone.
Request received
It is already with a manager. You will get an answer within the working day, and urgent requests go to the duty engineer immediately.
There is no such city in the list. Check the spelling.