Even if security within the Enterprise is Perfect – 3rd Party is not
- 41% to 63% of breaches involved third parties
- 71% of companies failed to adequately manage risk of third parties
- 92% of companies planned to expand their use of vendors
- 90% of anti-corruption actions by DOJ involved 3rd parties
Global Data Protection Regulation proposes solving privacy problems with 8 Data Principles
What if customer information leaks and there’s no way to track the location of the lost data?
Security is One Big business Problem:
General Data Protection requires security CIA triad
Aim for the CIA triad: customer information confidentiality, integrity, availability, preventing wrongful disclosure, manipulation, denial of service
Strong security lowers cyber insurance cost.
Improved cybersecurity earn higher service price and faster service adoption.
Strong cybersecurity gains the approval of major assessors and regulators like FTC, FCC, FDIC, PCI, AICPA, DOJ, ISO and EU
Data-centric security tools reduce security problems
Risk: Stolen (lost) laptop
Actual Risk: Premature breach notification
“Absence of evidence” = no evidence to defend a data breach
Default access to information is set to private, enforcing privacy by design
Log and audit functions exist to prove compliance and even to enforce remediation to violations of access
Response: Early detection of irregular distribution of files leads to better incident identification and response
Data Centric Security Supports Fair and Lawful Processing
GDPR requires that people give their consent to how their data is used
Over time, if the customer or employee disagrees with how the data is being used or with the accuracy of the data, then what?
How do we modify protection on a document once it has left our perimeter?
Data Centric Security Supports Fair and Lawful Processing
Protection persistence travels beyond the perimeter and is tied to the customer’s data.
Based on our understanding, the permissions we grant will change
Companies must honor all reasonable requests to stop processing or ENABLING USE of citizen private information
Audits and Activity Logging create a capacity to perform web-based audits and easily examine a trail of all activities performed on all files for all use.
Proving Fair and Lawful Processing
Information-Centric Audits and Activity Logging offers the ability to:
Perform web-based audit trail of all activities performed on all files for all use
Operate with real-time auditing
Notify file owners for unauthorized file activities; Send a daily digest to file owners summarizing all the day’s file activities; Restrict access to audit logs based on administrative access (e.g. allowed to view only the audit logs of their group/OU); Filter activity logs based on specific criteria; export audit logs as stand-alone files
Offer users the ability to monitor the usage of files protected by him/her
Log unauthorized attempts to access and use a file; log file activities while offline; log forensic audit details (machine name, IP address, file path etc.); export audit logs to other reporting and log correlation tools (e.g., BI, SIEM etc.); log access to audit logs for administrators and power
Right to Erasure (“Right to Be Forgotten”)
Individuals have the right to require a company to delete their personal data if the continued processing of data is not justified (especially where the data is inaccurate or incomplete).
Once the business has built operational dependencies on shared information, getting that data back involves a number of business impacts.
Enterprise Data Rights Management (EDRM) and Electronic File Synch and Storage (EFSS) make it possible to remove visibility to that information no matter where it is in the world.
One-Stop-Shop – Centralized Consistent Privacy
European Data Protection Board (EDPB) is far less likely to find fault with an organization taking active protection measures involving data-centric privacy. With data centric security there’s evidence of consistent rules applied at the moment information is taken into business custody and throughout the data lifecycle.
Avoids over dependence on file encryption
- If your answer to protecting data is encryption, consider that encryption on its own can be hacked and the greatest barrier to its success is that people simply don’t use it.
- File encryption alone isn’t persistent, doesn’t protect a file while it is open, does not support revoking access after distribution, and doesn’t provide tracking of what is happening with the file.
- A data centric product and program approach
- Know your data flow
- Identify EU citizen personal data
- Flag systems needing opt-in, EU data access, correction and deletion requests, and age-gating requirements
Shore up your ISMS
- Things to get right:
- encryption or pseudonymization of personal data
- processes and capabilities to handle personal data access, correction, deletion and
- portability requests
- a Data Protection Impact Assessment process
- a data breach response plan
- Some Technologies are more important - DRM plus EFSS
Digital or Information Rights Management (DRM):
A set of technologies that provides control over how a given piece of protected content can be used including what the recipient can do with the file, for how long and from which device/IP location. Rights Management also provides rich tracking wherever the file goes and provides modification of usage controls or revocation of usage.
Enterprise file sync-and-share (EFSS):
Enterprise file sync-and-share is a service that allows users to save files in cloud or on-premises storage and then access them on other desktop and mobile computing devices. This is a baseline product expectation to any modern enterprise, and soon, we’ll find that all persons are using file storage as opposed to local storage. We’ll see less thumb drives and more digital storage.
DLP plus Data Classification
is a comprehensive approach (covering people, processes, and systems) of implementing policies and controls designed specifically to discover, monitor, and protect confidential data wherever it is stored, used, or in transit over the network and at the perimeter. However, while sensitive information can be detected, DLP does nothing to secure information that must be exchanged to complete business processes.
Data classification program:
is a program that categorizes data to convey required safeguards for information confidentiality, integrity, and availability; establishes controls required based on value and level of sensitivity. The challenge is that just because a document is classified, that does nothing to protect the information in transit, at work, or at rest.(Source: Derived from SANS Institute InfoSec Reading Room).
- How do we start a conversation about Global Data Protection? Ask!
- Where is the sensitive data and who owns it?
- How do you know who is accessing it?
- Where is it flowing and how is it shared- including 3rd parties and vendor access?
- What is the quantifiable value and risk?
- How would you like to automate the access control process? What do you most want to accomplish through automation?
Regulatory use cases
- Data-Centric Cybersecurity Risk Management
- Aids Market Entry = solid cybersecurity and a functioning risk management program.
- Answers Customers demand cyber insurance
- Assesses Security Controls is the most critical step of a risk management program.
- Missing the tools and expertise to manage data-centric security = missing the business boat.
Data-Centric emphasis in meeting GDPR
- Data-centric security products (like SECLORE) can have an impact on enabling, tracking, or verifying control objectives across multiple control framework domains. The majority of articles with applicability from GDPR are identified within the domains of:
- Controller and Processor
- Transfer of personal data to third countries or international organizations
- Independent Supervisory Authorities
- Co-operation and Consistency
- Security Risk Assessment Frameworks include data-centric control requirements
We found 144 Control Assertions or objectives that could be better enabled through the implementation of SECLORE application features.
Protecting the Cloud-Based Business Environments presents major challenges
Understanding a kill chain allows you to slow down your adversaries
- Handle changes to major US & World regulations
- Transfer & manage cyber risk
- Support Cyber Insurance requirements for due diligence, consistent risk assessment and remediation
- Stop cloud and container environment data exfiltration
- Harness the issue of too many environments and too many things for a traditional risk management approach
How to Address Your IT Security
- The only way to know whether a security control works or not, or passes or fails, is to test it.
- For a configuration with known best practices, we can use CIS Security Benchmark to run SCAP resulting in CIS validation. This is not enough.
- Testing security takes more than just a vulnerability scanning tool that only checks a small number of security controls. Additionally, a vulnerability scan often tests a fraction, approximately five percent, of the security controls.
History of Secure Host Configuration Testing
History of Secure Host Configuration
Make Data the New Perimeter
- Seclore Document Rights Management:
Addresses a Huge Security Gap - Where is the Problem?
- Control Is Important
- Persistent, Granular Usage Controls
- Permanence: Protection persists with the file forever
- Remote Control:
File rights can be changed from anywhere in the world - Audit Trail:
All activities are tracked - Automatically Audits Usage of Information
- Automatically captures and consolidates file usage data from distributed environments:
WHO accessed the file,
- WHAT the user did with the file,
- WHEN and from WHERE
- Usage Policy Attributes
- Easily Access Protected Documents
- Browser-based access
- Lite-weight agents
- iPhone, iPad, Android, Windows
- Automated Usage Policies Applied to Files
- Automate File Protection with Pre-Built Connectors
- Utilize Any File-Sharing Method Without Risk
- Protection stays with the file regardless of how it is shared or how it is accessed and utilized
Q & A

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics