Data Encryption – Reasons to be Cheerful (Parts 3)

43% of cyber attacks target small businesses.

“GDPR? That was years ago…” – Data Encryption is just as important now as it was then…

If you’ve run a business in recent years, big or small, you will have seen a gradual increase in making sure that sensitive data is not compromised or used for malicious purposes. We’ve all seen stories of large companies’ networks being hacked by outside ‘bad actors’ and lists of names, addresses and credit card or bank details being syphoned off to the dark corners of the Internet for sale.

GDPR Enforcement and Media Attention

In the days after GDPR came into force, stories of large fines from the Information Commissioners Office (ICO) even made it into the newspapers. However, after 24th May 2017 a lot of businesses have become complacent about data breaches and the consequences they have.

SMEs’ Blind Spot on Data Security

Small and Medium Businesses in particular have a blind spot on this sort of thing. This is understandable to a degree, as they are always busy keeping the business running, rather than having to comply with every bit of legislation.

Ongoing Importance of GDPR Compliance

GDPR is still with us and will ever be. Just because you wrote a GDPR policy in 2017 doesn’t mean that you are covered. You still need to ensure the IT systems you and your staff access are secure, and the types of data stored are understood.

Target IT’s Commitment to Data Security

We at Target IT have always believed that making sure data is secured and not easily harvestable by unauthorised parties is essential to all businesses. Otherwise, we’d be in the business of selling stable doors to customers whose horses have already bolted…

Data Security comes in several parts

Of the 3, Protection of Data is the one that is lacking in a lot of Businesses. Backup itself is something of an intangible for some; whether it’s managed in-house, outsourced or not done all – some businesses just don’t know if their data is backed up; or in the worst case assume it is done by Microsoft (it’s not).

VIEW ALL OUR SERVICES

01

Protection of Devices

  • Anti-Virus
  • Anti-Spam
  • Anti-Ransomware

02

Protection of the Network

  • Firewalls
  • User Authentication
  • Access Rights

03

Protection of the Data

  • Backup
  • Data Encryption
  • Cyber Security

If you don’t know how your data is backed up – or even if it is – then talk to us and we can help.

The other part of Data protection is encryption. This ensures that if data on a disk (local hard drive, USB stick, etc.) is encrypted, then only the person’s machine that has the decryption keys can access it. With a post-pandemic work force of more Laptops than Desktops and working from home or other remote locations, that becomes ever more important. Whatever size of organisation you are, the bottom line is your data should be encrypted.

Let’s examine that on an unencrypted machine.

Say, for example, a user has left their Laptop on the Train and someone has stolen it. The person who stole it doesn’t have the Windows user password, but has enough knowledge to remove the Hard Drive and put it into an external caddy to examine the data.

Seamless IT Solutions for Uninterrupted Business Growth

The unencrypted disk contains data from all sorts of applications

01

You use Outlook on your machine – the .OST or .PST file on your machine contains all the emails
you have, and if copied, can be used on another machine with simple software to extract the data from
it.

02

You use OneDrive personal Storage or sync to SharePoint. A local copy of any documents you
store or use is kept on your local machine. Again, unencrypted data can be copied.

03

Google Chrome, Microsoft Edge (or other Web browser) history and passwords can be extracted
from the local machine.

Now let’s look at a scenario

Let’s look at the same scenario with a machine that has been encrypted with ESET Endpoint Encryption. This encrypts the entire hard drive, and the encryption keys are stored in a Management console that is managed by Target IT for the customer:

Thwarting Data Thieves

The thief takes the disk from the stolen laptop and puts it into an external caddy to examine the data…but no! they see a blank disk, asking them if they wish to format it. Because they don’t have the decryption keys they cannot decrypt the disk to harvest the data.

Reporting a Secure System

Your data is protected, and when the ICO ask if there has been a data breach due to loss of hardware you can report that it hasn’t, and using ESET Management tools can produce a report showing when the machine was encrypted and that it is protected. It can even be remotely wiped if the machine happened to be unlocked at the time and the thief gained access to Windows at that point.

Customer Confidence

and Compliance

Finally, encrypting data is a big tick when talking to your own customers; as it gives them peace of mind. When gaining Cyber Essentials Certification it is also something that gets you ahead of the game.

Talk to us at Target IT about how we can help secure your data and keep your business data compliant. 

Learn more from our latest blog posts & Case Studies