Blog

Manufacturing: 5 Top Factors to Consider When You Select Enterprise DRM
Data breach Insider threat Sensitive Unstructured Data

Protect CAD drawingsThe rising wave of industrial espionage and intellectual property theft has manufacturers on edge. Are you tasked with finding the right Enterprise Digital Rights Management (EDRM) solution for your company?

Check out these five tips from IP protection experts in manufacturing. 

*

Are you looking into EDRM solutions to ramp up your organization’s IP protection?  Congratulations, buckle up and hold on for the ride. 

Because this is mission-critical to your company’s future, it’s only natural that you feel the pressure to dot all the I’s and cross all the T’s. The tips below will help you zoom in on the essentials quickly.

Go Beyond Compliance to Reduce Cyber Risk and Insider Threat
Data breach Data security Insider threat Sensitive Unstructured Data

Go Beyond Compliance to Protect Sensitive DataData breaches make headlines every day and companies across the globe struggle to meet changing privacy regulations, such as the California Consumer Privacy Act (CCPA), the upcoming California Privacy Rights Act (CPRA) and of course, the General Data Protection Regulation (GDPR).

Data security is very high on the list of corporate priorities with most concentrating on protecting databases containing personally identifiable information (PII). Sensitive information subject to privacy or industry regulations is not found or stored solely in structured databases, but in unstructured files like Microsoft Office documents, PDFs, images, and computer-aided design (CAD) drawings.

How Can Your Remote Workforce Collaborate Securely?
Data breach Data security Insider threat Print security Secure collaboration

Never has there been a better litmus test for seeing how agile your business is than responding to a pandemic. A recent survey by leading research firm Gartner confirmed that most businesses will shift some employees to remote work permanently as a result of COVID-19. Even from home, employees need to collaborate securely with colleagues, partners and customers to stay productive and meet deadlines and goals. While video chat and instant messaging lets you communicate, a lot of collaboration is through documents. Ideally you want to easily share documents, make sure everyone is working on the most recent version, and be able to securely manage all your projects. With the major shift to working at home, the time to double down on data security is now.

Collecting Laptops From Terminated Employees? Protect Unstructured Data
Cybersecurity Data breach Data security Insider threat Privacy Secure collaboration

Protect data on laptops from terminated employees I read a Tweet recently from “Accidental CISO” about collecting laptops from terminated employees during the pandemic that I deemed retweetable (if that is a word).  Some comments focused more on the hardware – how to get it back – but this got me thinking more about what is actually on the hardware. What sensitive information, like intellectual property, might reside on them?  It also made me think, in a situation like this, how the potential for insider theft is far greater.

Files containing IP can be either printed on home printers, sent over email to personal accounts, saved on a USB stick, screen captured and so on.  These are not necessarily actions of malice, but obvious desperation to assist with the basic need for employment.

Pandemic Sent Your Workers Home? Reminders for Best Data Security Practices
Cybersecurity Data breach Data security Insider threat Print security Privacy Secure collaboration

Overnight, companies across the globe were forced into a fully remote workforce.  If you are prepared, under the best of circumstances, it can still be a challenge, but if you are not, the challenges are even greater and some things can potentially fall through the cracks.  People working from home can lead to a few unintended bad habits. With business continuity being the priority, data is even more at risk as hackers and thieves see opportunity when your guard is down.

For companies that don’t have tools in place, and for that matter, those that don’t have the right tools in place, here are some things you can do while ensuring the health of your employees, and your business stays on track.

Complying with CCPA – What are some of the landmines?
Data breach Data security Privacy

Complying with CCPA - What are some of the landminesThe potential landmines for compliance with CCPA is pretty high.

One of the first things is that a lot of companies don’t know how to interpret the law. We saw that with GDPR for the year prior to it going into effect. CCPA is a lot like it, but there are likely still questions.

Secondly, is the DSRs (Data Subject Requests) or the right to be forgotten. People are very in tune with their privacy these days and will want to act on it, not only for the reduction of spam, but for the identity theft potential. The requests will likely come too fast and companies with a lot of data containing personally identifiable information (PII) – the very thing those DSs will be after them for – will find themselves in a position where they don’t know where to start.

Tariffs Hitting the Automotive Manufacturing Industry Is Bad Enough, But Intellectual Property Protection is of Huge Concern!
Cybersecurity Data breach Data security Insider threat Privacy Secure collaboration

Protect intellectual property in the automotive industryIntellectual property is a valuable asset in a variety of verticals.  Let’s take manufacturing, for example.  More specifically the automotive industry.  It is particularly vulnerable to theft.  In fact, in our Webinar “Close the Gap on Insider Threat: Granular Access Controls & Behavior Analytics , we cited a Deloitte survey where the respondents put the automotive industry at the highest risk of insider cyber threat. This means they need to put serious consideration into protecting their intellectual property in unstructured files, especially when it is handled by multiple parties.

The auto industry is suffering because of the tariff war between the U.S. and China – they’ve got enough to think about in this respect.  But, this does not mean they can let their guard down with protecting CAD/CAE designs, that are very critical to their success.  It is a very competitive market from both a talent and design perspective. In fact, one of our customers considered themselves the “University of Auto Manufacturing”.  This was because they would put time, effort and money into training individuals on their designs, giving them access to their precious CAD/CAE files only to see it walk off on a USB stick perhaps getting into the hands of a competitor.  They got tired of that, and took control through discovery and classification, and by using granular access rights.

It Takes a Village to Raise a Child, Right? It Takes a Team to Develop a Data Governance Strategy!
Cybersecurity Data breach Data security Insider threat Print security Privacy

Define a Practical Data Governance Plan for Unstructured DataThe phrase “It takes a Village to raise a child” is true.  But it is also true that it takes a team to develop a data governance and policy management strategy!

Teamwork is important when developing a data security strategy. As part of that process, data governance and policy management needs to be part of the equation. It’s becoming more and more clear that organizations struggle with policy management – particularly with unstructured data. The very nature of unstructured data leaves it vulnerable to exposure and loss. Insider threat is of particular concern because while hackers typically attack structured databases, your employees and other valued insiders are accessing those databases on a regular basis. The insiders can download sensitive information into spreadsheets and reports. They are accessing your intellectual property, such as product designs and roadmaps. It’s the insiders that will walk off with those designs and sell them to your competition or bring it to a competitor to jumpstart the next phase of their career. The loss of this information will not only cost you revenue, but can also result in a regulatory fine. Who can afford that?

Geese at the ISMG Cybersecurity Summit in New York? It’s all about teamwork!
Cybersecurity Data breach Data security Insider threat Print security Privacy Secure collaboration

Work as a team for unstructured data securityLast week, Fasoo sponsored and participated in the ISMG Cybersecurity Summit in New York City.   It was a great event, well attended and in the Theater District and the ISMG folks were awesome to work with!

As part of our sponsorship, Fasoo had a 10 minute Tech Spotlight where, rather than providing a “death by powerpoint” tech dump, we thought it would be good to get everyone thinking about working together as a team with respect to their data security initiatives by following the example of geese. Below is the recap for the greater audience.

Getting Granular: Why You Need Granular Access Controls
Cybersecurity Data breach Data security Insider threat Print security Privacy Secure collaboration

Granular access controls are important to protect unstructured dataIn our last post, we said “Without granular access controls, you can’t prevent a user from copying data from a file and pasting it into an email, for example. If you only encrypt a file and do not prevent copy and paste or printing, a user can easily compromise security.” And we meant it.

Now,  you might be asking yourself “What does it mean… granular access controls?” And the answer is simple.

Granular permissions or access controls means you grant specific permissions or enable actions when a user opens a file.  This means you can either allow or prevent a person from doing things in a file when it is open – or “in use” – and since data in use is really difficult to protect, wouldn’t it make sense to add this layer of protection?  By applying granular access controls, you can prevent someone from copying and pasting, taking a screen shot, or printing based on the classification of the file and security policy applied to it.  Users can be either granted or denied specific actions when a document is open.