Услуга · Information security

Personal data security

Our part of the work is technical: to ensure that only those whose role requires it can approach information about people, that every access leaves a trace in the log, and that carrying the database out unnoticed is impossible.

Access
strictly by role
Logs
who looked and when
Channels
transmission under encryption
Removal
under control

What the work includes

Measures are chosen to match the required level of protection. We do not add excess: unnecessary restrictions get in people way and add nothing.

Discuss the scope

Accounts

An individual account for each person instead of one shared, rights by role, and regular pruning of the authorised list.

Access logging

We record who accessed the data and when, and keep those records. Without them investigating an incident is impossible in principle.

Storage locations

The servers and databases where the information physically sits: a separate segment and restricted connections.

Forwarding

Encryption whenever traffic leaves the controlled zone, including branches and people working from home.

Removal of information

Restricting removable media, printing and attachments where the nature of the work justifies it.

Copies

Backup with regular restore testing and protection of the copies themselves against encryption.

How it goes

We proceed in stages and start with what gives the greatest effect and interferes least with the work.

01

Level

We classify the system and obtain a list of mandatory measures. After that we follow it strictly.

02

The first pass

We eliminate shared passwords, switch on logging and sort out rights. It takes days and the payoff is noticeable.

03

Infrastructure

Network zoning, boundary protection, encrypted links, control of removable media.

04

Testing

We try to reach data where we should not be able to and see whether it lands in the logs.

Accounts of former employees live on for years. Someone left six months ago and their login still works and still reaches the client database. Revoking rights on departure should be part of the HR procedure, not the goodwill of an administrator.

Questions and answers

With understanding where information about people is held. Usually that is not only the accounting system: spreadsheets turn up on the shared drive, exports in mail, copies on laptops. Until a list exists there is nothing to protect - it is unclear what.

No. Encryption is justified where the medium can physically leave the office: laptops, removable disks, backups, communication links. Encrypting a desktop in a locked office makes little sense.

Quickly establish the scale, close the channel and work out how it happened. You must act to a procedure written beforehand: improvising during an incident is expensive. We prepare such a procedure separately.

We will protect personal data

Write where information about your employees and clients is held. We will look at what is closed and what is open to everyone.