Most companies can tell you where their data is kept. Far fewer can tell you who can reach it, where copies have ended up, or what would happen if a laptop holding it went missing. Those are the questions that matter when a client, an auditor or a regulator asks.
What we look at
- Who has access to what, and whether that still matches what people actually do
- Where company data is allowed to go — personal drives, USB devices, personal email, unmanaged cloud accounts
- Encryption on laptops and portable devices, so a lost machine is an inconvenience rather than a disclosure
- Sharing settings in Microsoft 365, which are frequently more open than anybody intended
- A record of access, so you can answer the question rather than estimate
Access is the part that drifts
Permissions are usually correct on the day they are set. Then somebody changes department and keeps their old access, a contractor is added for one project, a shared folder is opened up to solve an urgent problem and never closed again. Nobody does anything wrong, and after three years the picture bears no resemblance to what anyone would have designed.
Reviewing access periodically is unglamorous work, and it is the single most effective thing most businesses can do about internal data risk.
Compliance, honestly
We handle the technical side: controls, encryption, restricting access, and producing the evidence that those things exist. That is usually what an auditor or a client security questionnaire is actually asking for.
What we do not do is tell you what the law requires of your business. That is a question for your legal advisers, and you should be wary of an IT company that answers it for you.
Related
This works with user account and password security, endpoint protection, and the backup work covered under IT security. Data you cannot restore is a data protection problem as much as a technical one.
Part of our IT security service. Most clients take this as part of a wider agreement rather than on its own. See the full service.
Nicosia +357 22 356 840 · Limassol +357 25 030 261 · Larnaca +357 24 030 269 · info@itlogicpro.net
