Latest news
67% of respondents say that senior management in their organizations either don’t know where all company data resides or are not sure, according to Varonis.In addition, 74% of organizations reported that they do not have a process for tracking which files have been placed on third party cloud digital collaboration and storage services.
With Bring Your Own Device (BYOD) - particularly mobile and tablet devices - and file synch services booming, companies are open to a wave of potential devastation. Files kept on third party cloud services can be lost, misplaced, accessed by unauthorized people or leave the company with the employee, causing data privacy and compliance issues.
larmingly, of those that are allowing cloud-based file synchronization services, only 9% of respondents’ companies have a process for authorizing and reviewing access to cloud repositories in place, with another 23% still developing their access policies.
The remaining 68% either have no plans in place that they are aware of, or live without formal processes for granting and reviewing access. Without control over access, or knowledge of where potentially sensitive organizational data resides, data is virtually ‘up for grabs’.
Given the risk and operational implications of moving data into a cloud environment, it is hardly surprising that 78% of those surveyed would prefer to use their existing permissions and storage if they were able to provide collaboration and file synchronization services similar to those available in the cloud.
Equally, the majority of respondents (57%) reported that BYOD would be more attractive for their organization if they could provide secure access to their internal file shares for collaboration.
“The results clearly show a lack of control by those organizations that have adopted cloud file sync services”, said David Gibson, VP of Strategy at Varonis. “The most disturbing findings were the number of companies that report they have no way to track what data is being stored in the cloud, no process to manage access to that data (or plans to do so), and that management doesn’t know where enterprise data is stored. This should act as a wakeup call for organizations to develop a conscious strategy to ensure secure collaboration as quickly as possible.”
David Gibson’s tips for secure collaboration are:
- Create an inventory of your most used collaboration platforms to get an overview where data lives, who has access to it, and who is using it.
- Identify data owners for each data set and have owners perform a preliminary entitlement review to see if data is stored in the right place and if the right people have access to it.
- Remediate any exposures, such as data that is accessible to too many people or regulated/sensitive content that is stored in the wrong place.
- Monitor access to all data – this will help easily identity data owners and identify unused data and abuse.
- Put a process into place that provides secure collaboration for remote employees - including synchronization, mobile device support and extranet functionality – that works within the existing enterprise servers and infrastructure.


Spotlight

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

To hack back or not to hack back?
Posted on 12 June 2013. | If you think of cyberspace as a new resource for you and your organization, it makes sense to protect your part of it as best you can. But is it a good idea?

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.







