Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - How can Businesses Evade the Ever Increasing Threat to their Data Security?
Articles

How can Businesses Evade the Ever Increasing Threat to their Data Security?

ISBuzz TeamBy ISBuzz TeamJune 3, 20156 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
businesses evade the ever increasing threat to their data security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Intralinks on the state of corporate information security

The risk to corporate data has never been so great. Businesses are fending off an ever-growing range of security threats, from state-sponsored espionage and targeted attacks to new zero-day vulnerabilities, while also being forced to address their employees’ sharing habits.

Nevertheless, businesses must be able to communicate freely and effectively with both internal and external parties. Yet, this vital communication does increase the risk of sensitive corporate information falling into the wrong hands if not handled in a sufficiently secure manner.

The risk of breaches, interception or accidental leaks means that free file-sharing services and email are no longer considered viable methods of sharing documents. Now that the majority of employees can access corporate data on mobile devices, it has never been so important that enterprise security measures are extended beyond the traditional perimeter of the organisation.

Data leaks are a real and persistent threat to businesses. The risks have been highlighted by recent incidents where the Information Commissioner’s office (ICO) has stepped in to impose fines on organisations for accidental loss of data. Incidents like these are bound to continue, damaging the affected businesses in terms of both finance and reputation. So how can businesses ensure they have the right policies in place when it comes to IT security and file sharing? And how can they ensure they don’t become the next business paying out to the ICO?

Data loss is often the result of IT struggling to keep track of users’ sharing habits outside of the office. Not that long ago, a corporate firewall could ensure that all sensitive data was kept secure within IT’s control. The steadily increasing trend in BYOD policies means that IT now struggles to know who is sharing data and who they are sharing it with.  Popular consumer tools including cloud file sync and share (FSS) services are now being used by employees at work, making life difficult for both IT and compliance departments.

If we imagine the FSS market as a pyramid, with the vertical axis representing business value. At the bottom of the pyramid is a wide breadth of adoption, where some FSS providers can now declare up to 500 million users. While these millions of users are improving their own efficiency and saving themselves time, they are creating difficulties for others within their business.  One reason is that the protocols for accessing information change over time, for instance when employees join, move or leave the company. This flexibility is important but it can become difficult for IT and compliance teams to manage these protocols and implement the correct policies to protect intellectual property (IP) against data loss if employees are using their own cloud FSS services

More niche solutions are located at the pyramid’s peak. Their more focused adoption rates are usually aimed at solving more clearly defined business problems. These solutions provide a higher level of business value to highly-regulated organisations, enabling them to track information more easily, cut down on paper usage and allow access to the most up-to-date information available. They promote increased efficiency in sharing information which could, for example, shave a month off the time it takes to run a pharmaceutical trial, thereby ensuring the product can spend an extra month in market before the patent expiry date falls.

Businesses should ensure that any file-sharing platforms have the strongest possible capabilities to protect any information shared, while ensuring the user experience is seamless. Technologies such as Information Rights Management (IRM) make it easier for a business to manage document access and protect IP outside the corporate boundary. For increased confidence in document security, businesses can add specific permissions, such as applying a time limit after which the user will no longer be able to view the document– even if it’s already been shared or downloaded.

For legal reasons, businesses within highly regulated industries, such as banking or the pharmaceutical sector, need to be completely confident that sensitive documents detailing information about customers, contracts or medical trials remain secure. It’s also worth considering that if certain information needs to be retrieved for a legal issue, it is much easier to find the documents in question if they are not spread across 50 different systems. Compliance issues like this must be taken into account when choosing FSS technology for the enterprise

Ownership can be key for businesses operating across multiple countries where regulations vary. If a government authority requests that an organisation’s cloud provider supplies them with certain data on a customer, this can cause difficulties for all parties involved. A solution such as Customer Managed Keys (CMK) helps to ensure that more power stays with the information owner. With exclusive control over their own encryption keys, the owner can control access to their information regardless of its physical location. If the customer disables the encryption keys, there is no danger of the service providers being able to decrypt the data or grant access to another party.

With data leak threats continuing to impact businesses, IT security is becoming a huge concern: not just for the IT department but also for the board of directors. When reviewing company security policies, both IT and the C-suite should remember that employees need to be able to work efficiently, which means being able to share information with their colleagues both inside and outside the organisation quickly and easily.

Businesses can no longer rely on a few short sentences in the general employee policy handbook to provide guidance on safe information sharing. Organisations need to take control over the huge variety of sharing tools being introduced to the workplace by employees. By giving proper guidance on how to apply the right security controls over the documents being shared and introducing a secure, friction-free sharing process, organisations can ensure that their information remains secure against leaks.

By Richard Anstey, CTO EMEA, Intralinks

Richard AnsteyBio : Mr. Anstey joined Intralinks after serving as Chief Architect at OpenText, where he was responsible for the technology evolution of the company’s full information management portfolio including innovation and technical due diligence on acquisitions. During his time at OpenText, Mr. Anstey led the global product management team as it passed the USD 1 billion revenue threshold and has over 15 years of Information Management experience.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}