THE CONSEQUENCES OF NOT ENCRYPTING CONTENT

CONTENT CAN BE EXPOSED

There are many situations in which unencrypted email can be obtained by unauthorized parties:

Email can be intercepted

While most email is not of sufficient interest to third parties to warrant their attention in trying to intercept it, there are cases in which this interception has occurred. The recent revelations about activities at the (USA) National Security Agency with regard to intercepting email and other content is but one example of many that have occurred in less official ways.

Lost or misplaced mobile devices

Data interception can occur when unencrypted smartphones, tablets, laptops, USB sticks, mobile hard drives, etc. are lost or stolen. This is a fairly common occurrence and can result in the loss of intellectual property or confidential corporate information.

Mistakes by users

Another consequence from failing to encrypt content can result from simple user mistakes. For example, the type-ahead feature in most email clients means that eventually an employee will inadvertently send an email to the wrong party.

Malicious activity by users

Although less common as a source of data leakage than mistakes, disgruntled employees or contractors can misappropriate content for their own or others’ use, such as sending files through the corporate email system to their personal accounts. If systems are not in place to at least detect – if not outright block – this activity, organizations can lose thousands of documents before they know any of this kind of activity has occurred.

DATA BREACH LAWS CAN BE VIOLATED

If email and other content are not encrypted, the most serious impact will be that sensitive or confidential data can be breached. In the USA, at present, 46 of the 50 US states and many countries have laws against data breaches that specify steps that must be taken if sensitive content is exposed in an unauthorized manner. The result of a data breach – such as unauthorized interception of unencrypted email that contains sensitive data – is that a law is violated, which triggers a variety of often expensive consequences, such as remediation efforts, lawsuits, negative publicity, etc.

A potentially damaging impact of an email or other data breach is damage to an organization’s reputation. The negative publicity arising from a breach, coupled with backlash from regulators, stockholders, investors, customers and prospects can seriously damage an organization’s standing in its industry, potentially putting it out of business in the most extreme of cases. Add to this the fact that customers are less likely to do business with an organization they cannot trust, resulting in potentially severe impacts to corporate revenue in the short term and possibly more significant impacts over the long term. The direct remediation costs for data breaches can be quite expensive as a result of notifying customers, responding to inquiries, updating systems, creating new policies, purchasing credit reporting services for customers, and the like.

NEXT STEPS: QUANTIFY THE CONSEQUENCES

 

It is essential that decision makers understand the significant consequences hat can result by failing to encrypt data. For example, if an unencrypted email with internal data like trade secrets, sensitive product plans or customer information is intercepted by an unauthorized party; this can trigger data breach notification requirements, heavy fines, or harm to corporate reputation. As one element of this exercise, it is useful for decision makers to quantify the cost of a data breach as a starting point.

DEVELOP AN ENCRYPTION PLAN

The first step in the process of implementing encryption for the first time or improving a deficient encryption process is to identify the content that is most in need of encryption: namely, emails and attachments that would be most damaging to the organization if compromised. This might be content like privileged communications between senior business managers; sensitive documents like financial projections or draft policy statements; content that contains obviously confidential information like bids, tenders, acquisition information, employee medical records or customer financial information content; content that could embarrass business partners if intercepted; confidential product plans; etc.

A key element of the process is to conduct a sort of “inventory” on confidential content sources or communication types that should be encrypted when leaving the corporate firewall. This might include developing a list of keywords that should be detected when content is sent outside the firewall, or it might be a list of individuals or roles – such as chief legal counsel – whose emails are more thoroughly screened because they are more likely to contain sensitive or confidential information.

Next is to identify the “second tier” of information that is not necessarily highly confidential, but that decision makers would like to keep confidential, such as embargoed press releases sent to industry or financial analysts, or draft datasheets sent to printers. Addressing these content types normally represents that vast majority of the problem in most organizations and is the easiest to address. This can be followed by the
less obvious use cases that might require more effort and integration.

Osterman Research found in a study published in August 2012 that 75% of organizations want a real time approach to checking for content that should be encrypted. Another 16% want to manage such potential violations in a post-send mode, while the remaining 9% are not yet sure of how to deal with the issue. In terms of specifically how to deal with policy violations in the context of sensitive content that is sent without encryption, the same study found that 53% of organizations prefer to notify offenders with a pop-up notification, while 40% want the offending content sent to a supervisor for review.

DEVELOP A SOLID BUSINESS CASE AND ROI

Organizations most often think of encryption as a defence against something bad happening in an organization – i.e., the loss of sensitive or confidential information. While that is certainly true, not as many focus on the proactive, offensive use case for encryption. For example, business cases and ROI considerations for encryption should not be based solely on regulatory compliance or data breach prevention concerns. Instead, encryption can be useful as a means of avoiding fines or loss of business and can enable competitive differentiation and create new business opportunities that might not be available otherwise.

The use of encryption might mean that customer statements can be provided electronically. This not only reduces the cost to the sender, but provides an improved customer experience. In the case of email, encryption can enable secure communications and transactions over low-cost, well understood and easy-to-use communication channels that are less expensive to manage than postal mail or physical delivery services.

CREATE POLICIES FOCUSED ON ENCRYPTION

Next is to create detailed policies based on legal and regulatory requirements to protect content through encryption. This step should include a focus on the key business risks that need to be mitigated, consequences for violating corporate data protection policies, and should also provide a detailed and thorough perspective on an organization’s BYOD policy. Inclusion of BYOD is a critical step in developing encryption policies, since 97% of organizations permit corporate email to be accessed on personally owned devices.

TRAIN EMPLOYEES

An important component of any organization’s encryption plan should be employee education about the policies and the dangers of not using appropriate encryption. For example, encryption solutions should be used to provide feedback and indirectly train employees about handling sensitive information, such as through notifications when confidential information is included in an unencrypted email or file transfer.

Plus, if employees are normally dealing with content that should be encrypted when sent externally, it is our view that automated, policy-based systems should be deployed to handle these tasks automatically. A pop-up message to the offender shouldn’t be required – let automated systems handle the encryption activities automatically, or route the message through a secure channel.

IMPLEMENT POLICY CONTROLS AT THE GATEWAY OR IN THE CLOUD

As noted above, encryption should be policy based and automatically encrypt content – or at least inform users of the potential need to encrypt – based on the detection of various keywords, the domain of the recipient, character strings or identifiers associated with sensitive and confidential information (e.g., date of birth, credit card numbers, healthcare-related terms) in an email, file transfer, etc. However, some encryption solutions lack efficient automation schemes and do not offer simple policy definition schemes. Add to this the fact that IT generally wants policy definition for encryption to be part of a larger policy management system instead of a separate tool that requires its own interface and learning curve.

EVALUATE DEPLOYMENT OPTIONS

As a key last step, decision makers should evaluate all of the available deployment options for encryption solutions. These include:

• On-premises software deployed on IT-managed servers

• Physical and virtual appliances

• Cloud-based services

• Combinations of two or more of these in a hybrid configuration

Many organizations, particularly enterprises, will want to consider a hybrid approach to encryption, perhaps deploying an on-premises solution for staff in the primary location and a cloud-based service for remote users in remote offices that do not have dedicated IT staff.

See further articles on encryption.

 


Top 11 tips to avoid spreadsheet errors
Why is Data Encryption not more common?