From the Wall Street Journal, but there were lots of other reports. The Chamber had at least six weeks worth of email data containing sensitive information stolen in a breach that was widely reported
This expert from the Brookings Institute is the extreme case. When he travels in China, he disables Bluetooth and Wi-Fi, never lets his phone out of his sight and, in meetings, not only turns off his phone but also removes the battery, for fear his microphone could be turned on remotely.
There are a whole series of cloud-based document sending services such as Google Docs, Dropbox, Box.net, and others that can store documents in the cloud.
These services all share one common weakness: you can’t manage them well from an enterprise perspective. Also, browser-based FT is limited to 2 GB or less, and many of these services have other hidden limitationsEven when IT is aware of their use, the services generally lack transaction logging, which makes document control problematic and impedes litigation preparedness.
Law enforcement shut down one of these services, MegaUpload, and in the ensuing months other peer file sharing services have curtailed their activities.
This is a sample screen from Docusign
There are more than a dozen DLP vendors, and these products offer a wide range of protective features, and some even integrate with endpoint security products, proxy/caching servers, and network intrusion protection appliances. However, while DLP products are great at identifying security breaches after the fact but don't do much to help keep your confidential information contained within your enterprise. They are mostly used for compliance and other regulatory reasons.
This is Global Velocity’s DLP product and you can tune it to block Facebook messages for example, but allow users to add items to their Wall as an example.
These are various gateway appliances that operate inside your firewall, and automatically work in the background to encrypt and decrypt message traffic in conjunction with your mail servers. These are somewhat cumbersome but offer the following features
This is Mimecast’s Outlook plug in, and as you can see, there isn’t much to set up with it.
Not as easy to use as native email appsMany still employ symmetric keys Some can only read and not compose encrypted messagesThese all have a Web service that is hosted by the vendor on the public Internet and users connect via a browser to read and send messages. recipients don't have to download any special software when they get an encrypted message from you.
Transcript of "How to secure your emails for sensitive docs"
Why You Shouldn’t Email Your Sensitive Documents David Strom firstname.lastname@example.org TechNet Mid America July 2012
Obstacles to Email Encryption Adoption Today• Unencrypted emails are too easy to send• IT admins think encryption is too expensive or cumbersome or complex• Compliance regsshould drive more email encryption usage (but don’t…)• The mobile encryption experience hasn’t been so wonderful 4
Investors’ Email Compromises Have Consequences! 5
Secure email alternatives• Cloud-based storage• Secure document delivery services• Data loss prevention products• Full encryption choices
Secure document issues• Do you need secure intra- or inter-enterprise collaboration?• Can you recall sent messages?• What happens when someone leaves your company?• How does the service affect users’ existing email experience?• Can you authenticate recipients and thwart malware such as key-loggers?
Data loss prevention• Global Velocitys GV-2010 security appliance• BlueCoat Networks DLP appliance• SendmailsSentrion email server• McAfee Host DLP• Symantec/Vontu DLP v10• Safend Protector• Trend Micro DLP
DLP Drawbacks• You are tracking rather than encrypting messages• Once a message leaves your premises, you can’t do anything about it• Can be expensive
Full encryption choices• Voltage SecureMail• PGP Universal Server• Sophos Email Appliance• Cisco IronPort• Proofpoint Protection Server• Mimecasts Unified Email Messaging• Echoworx Encrypted Mail
Common product features• Crypto key management• Auto encrypt sensitive info as part of their policies• Lots more rules processing• Outlook plug-ins
Encryption Landscape Vendor Approach Key/Certificate Mobile capability ManagementCisco IronPort Symmetric key per CRES (cloud) Web-based message Or on premise Proofpoint Symmetric key per PP Key service or on premise Web-based; read message onlySymantec/PGP PKI PGP Directory or on premise Web-based; read only Entrust PKI Entrust PKI or on premise Web-based Zix PKI Zix Directory Web-based Voltage Identity-based Cloud-based Native app encryption Echoworx PKI Echoworx PKI Native app