CLOUDTWEAKS CONTRIBUTOR PROGRAM

Join the CloudTweaks thought leadership contributor program which includes a customized profile, branded identity page, newsletter marketing, social amplification and more...

The program is currently available to consultants, influencers or executive level contributors.

Daren Glenister

Safeguarding Data When Employees Leave The Company

Safeguarding Data

Employee turnover is unavoidable. According to CompData Consulting, the average employee turnover rate in 2015 in the US was 16.7 percent, and this number was significantly higher in such industries as hospitality (37.6%) and banking and finance (18.6%). While employee turnover and terminations come with a variety of corporate, financial, and logistical hurdles, they also create a wide range of data protection and data management problems.

A survey published by Biscom in 2015 found that 87 percent of employees take the data they created over the course of their employment when they leave, and 28 percent take data that others had created. That includes confidential financial data, customer information, intellectual property, price lists, marketing plans, sales data, company directories, competitive intelligence, product design specifications – all of which belong to the business. Employee theft is damaging for a company in multiple ways, such as violating national and international regulations, harming their competitive position, or affecting the bottom line. And it could force the company to take legal action against former employees.

While employees take data with them for many reasons, the motivations tend to fall into three main buckets:

Safeguarding Company Data

  • Accidental. The cloudification of business and the rise of bring your own device (BYOD) policies means that departing employees could be taking substantial amounts of corporate data and not even realize it. Because a growing portion of employees do some (or all) their work from home, they often maintain a rich source of corporate data on their personal computers or in public cloud services.
  • Entitlement. Many employees knowingly take information with them because they feel they’re entitled to it, or that it won’t affect the company. If an employee who worked on a flagship account created valuable intellectual property, they may feel justified in taking that information with them. This problem is further compounded by the lack of security or monitoring technology to protect against data exfiltration.
  • Malicious. Employees angry with company management because they were laid off or fired could be motivated for revenge by destroying valuable data. Alternatively, a departing employee looking for a quick way to get ahead in a new position at a competing company might be inclined to take a few trade secrets with them. While this group may represent only a small portion of data loss in a company, the damage could be significant.

A perfect example of malicious data theft is the recent story of an IT employee who was fired by Indianapolis-based American College of Education. Before the employee left the College, he intentionally changed the login credentials to an important Google document that stored emails and course materials for 2,000 students. Once

the College and its students realized they no longer had access to the Google document, the fired IT worker was more than happy to provide the password – once his former employers paid him $200,000. The two parties are now fighting it out in court.

Best practices for retaining data

Data protection should be an ongoing effort, not just a priority when employees leave. To reduce the risk of employees taking information with them when they leave, organizations will need a combination of frequently updated policies and procedures, as well as technology solutions. Most importantly, it needs to be enforced. Here are a few best practices for ensuring that data doesn’t leave the office with your departing employees.

  • Ensure ongoing visibility of sensitive corporate data. It’s crucial for organizations to keep tabs on sensitive corporate data across all areas of the network, including cloud applications or other repositories where data might be stored. Deploying a content archive to capture and index data is an important first step. It will also enable monitoring and auditing to give insight into how employees are accessing data.
  • Limit employee access to data and develop policies on proper use of platforms. It’s essential for companies to have acceptable use policies regarding proper use of corporate email, company-owned and personal devices, cloud applications and other platforms where corporate data may be stored. Additionally, companies can set parameters for who has access to what data on a need-to-know basis, ensuring IT has greater control over sensitive information.
  • Encrypt data at all stages and require authentication. Whether it’s in-transit, at-rest or in-use, sensitive and confidential data should always be encrypted, regardless of its location. Authentication can further protect data by preventing access to unauthorized parties. This alone can prevent much of the data loss that occurs when an employee leaves a company.
  • Find the right technologies. Content archiving makes corporate data tamper-proof, and makes it easier for data managers to retain, search for and appropriately manage data assets. Enterprise Content Management (ECM) systems are another way to prevent data theft from departing employees because they provide businesses the ability to control access to and understand where corporate data resides. Another option is virtual desktops, ensuring that no data is stored locally.
  • Look for signs of unusual employee behavior. When employees are planning to steal corporate data, they often exhibit a few warning signs. For example, managers may notice a spike in the volume of information copied to the cloud, USB drives, personal devices, etc. The employee may have recently deleted a significant number of documents from their computers or other data repositories. Access to CRM systems at odd hours of the night may also indicate a potential data theft in progress.

Employee turnover is a fact of life, but data loss due to departing employees should not be. Most businesses are not adequately prepared to deal with repercussions of employee data theft, or have the capabilities to mitigate these risks before they occur. Blending strong corporate policies focused on the proper handling of sensitive information with the right technology tools that best meet the organization’s needs can minimize, if not eliminate, the threat of employee data theft.

By Daren Glenister

Daren Glenister

Daren is the Field Chief Technology Officer for Intralinks. Daren serves as a customer advocate, working with enterprise organizations to evangelize data collaboration solutions and translate customer business challenges into product requirements.

Glenister brings more than 20 years of industry experience and leadership in security, compliance, secure collaboration and enterprise software, having worked with many Fortune 1000 companies to turn business challenges into real-world solutions.

View Website
The Lighter Side Of The Cloud - Thin Client
Online Courses For Free
The Lighter Side Of The Cloud - Deconstruction
The Lighter Side Of The Cloud - Snowball Effect
The Lighter Side Of The Cloud - Speeding Tickets
Chris

How to Avoid Becoming Another Cloud Security Statistic

Cloud Security Statistic Last year, Gartner predicted that, by 2020, 95 percent of all cloud security failures will be caused ...
The Connected Car: The Unknown Hero of Automotive Innovation

The Connected Car: The Unknown Hero of Automotive Innovation

Connected Car Innovation Spanning the last decade, the automotive industry has seen an explosion of technological innovation which has, and ...
Infatuation leads to love - How container orchestration and federation enables multi-cloud competition

Infatuation leads to love – How container orchestration and federation enables multi-cloud competition

Container Orchestration The use of containers by developers -- and now increasingly IT operators -- has grown from infatuation to ...
Part 2: Strategies for Securing Mobile Devices in a Cloud-based World

Part 2: Strategies for Securing Mobile Devices in a Cloud-based World

Part 2: Strategies for Securing Mobile Devices With workplace mobility now a way of life and companies investing in cloud-based ...
Digital Innovation Starts with a Digital Core

Digital Innovation Starts with a Digital Core

Digital Innovation A lot of times when the prevalent industry trends are discussed among industry folks, there are usually two ...
Why ‘Data Hoarding’ Increases Cybersecurity Risk

Why ‘Data Hoarding’ Increases Cybersecurity Risk

Data Hoarding The proliferation of data and constant growth of content saved on premise, in cloud storage, or a non-integrated ...
Infosec thought leaders

Cryptocurrencies and Ransomware: How VDI Can Help Defend Against the Next Ransomware Attack

Cryptocurrencies and Ransomware The WannaCry ransomware made headlines back in May when it crippled hospitals across the UK and put ...
Data Vulnerability Tools

Data Vulnerability Tools

Provided is a list of popular data vulnerability tools to help your company keep an eye out for any security related exploits that you should be made aware of ...
Technology Certification Courses

Top Five Technology Certification Courses To Choose From In 2018

Technology Certification Courses Gartner predicts that the global public cloud services market is projected to grow by 55 percent in the next three years and is expected to reach $383.3 billion by the end of 2020. Today, cloud computing helps enterprises ...
How Security Certification Helps Cloud Service Providers Stay Transparent and Credible

How Security Certification Helps Cloud Service Providers Stay Transparent and Credible

Security Certification Helps Cloud Service Providers If you are a cloud service provider (CSP), you know your customers have a choice as to who to work with, but do you know what will help tip the scales in your favor? ...
Cloud And Cybersecurity: 5 Things CISOs Need To Consider

Cloud And Cybersecurity: 5 Things CISOs Need To Consider

The Cloud and Cybersecurity Tomorrow’s digital enterprise is at war today. War not only with external cybersecurity hackers and viruses, but also within the organization itself – a conclusion based on my discussions with information security managers and cloud architects ...
Load Testing Tools

Load Testing Tools

Provided is a short list of load testing tools which will test server and application resistance and certainly valuable in order to help test and tweak your company's infrastructure ...