What we protect
We sort information by value. Otherwise everything has to be guarded equally, and that does not work.
The order is: find the data, restrict access, close the routes out, watch for breaches. Skipping the first step devalues the rest.
We sort information by value. Otherwise everything has to be guarded equally, and that does not work.
Laptop disks and removable drives. A lost encrypted laptop is an annoying episode; an unencrypted one is an incident requiring notification.
Permission by list, connection logging, and a total ban where sensitive information is handled.
Restricting the sending of attachments outside and the printing of documents marked confidential.
Transmission monitoring systems with rules written to your own classification.
The order of actions and reporting on what triggered and how it ended.
The order never changes: we start with prohibitions on paper and in access rights, and connect specialised products afterwards.
We compile a list of what is genuinely valuable. Usually it is a few per cent of the total volume of company data.
Encrypting laptops, restricting media in critical departments, cleaning up rights.
We install the system without blocking and spend a month gathering a real picture of what happens.
We switch prevention on only once the flow of false positives has been brought down to a reasonable level.
An unencrypted laptop left in a taxi is the most common data-loss scenario. Yet disk encryption is built into modern operating systems and is switched on centrally without a single purchase. There is simply no cheaper measure in information security.
Put the question differently: what happens if this ends up with a competitor or in the open. Usually a list of a few items emerges - the client base, contract terms, developments, personnel records. Everything else does not need top-grade protection.
No. A large share of the channels is closed by built-in tools: removable media policies, mail server rules, restricted rights. A dedicated product is needed when the data is highly valuable and evidence for an investigation is required.
Separate them. Work mail and systems should be opened only from managed devices or through a separate secure connection that saves no files. A blanket ban on personal devices is usually not observed.
Write what information is critical for you. We will propose measures from simple to complex with cost estimates.
Request received
It is already with a manager. You will get an answer within the working day, and urgent requests go to the duty engineer immediately.
There is no such city in the list. Check the spelling.