CommodoreS Posted May 15, 2018 Posted May 15, 2018 I just wondered if anyone has come across this company at all Secure School Email | X509 Encryption for Education It sounds good, but there does not seem to be much technical information there.
Meldrew Posted May 16, 2018 Posted May 16, 2018 For a company that supposedly is all about security, it doesn't give any information about its GDPR compliance. There's several other things that ring alarm bells. Personally I wouldn't touch them with a barge pole. Meldrew 1
djrscally Posted May 16, 2018 Posted May 16, 2018 I don't know that they sound sketchy; they just look like a re-seller who'll just add on a fee for the X509 certs you can buy from any CA or something. I really don't think S/MIME is a good solution for schools anyway. The whole methodology means hardly anybody uses it, so you're paying for something that will basically never see any use, and it wont let you send encrypted emails to others anyway unless they've bought their own certificates. 1
secureschoolemail Posted May 18, 2018 Posted May 18, 2018 secureschoolemail has been running for nearly 4 years. It's not just something that was created to take advantage of the GDPR regulations. Article 34 states that a breach notification to individuals is mandatory where it is likely to “result in a risk for the rights and freedoms of individuals”. However, if you can show that you have protected personal data adequately the impact of a breach can be minimised and the potential obligations reduced: “…the controller has implemented appropriate technical and organizational protection measures, and that those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorized to access it, such as encryption.”
djrscally Posted May 18, 2018 Posted May 18, 2018 secureschoolemail has been running for nearly 4 years. It's not just something that was created to take advantage of the GDPR regulations. Article 34 states that a breach notification to individuals is mandatory where it is likely to “result in a risk for the rights and freedoms of individuals”. However, if you can show that you have protected personal data adequately the impact of a breach can be minimised and the potential obligations reduced: “…the controller has implemented appropriate technical and organizational protection measures, and that those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorized to access it, such as encryption.” So how's it work? Are you just selling x509's for S/MIME?
secureschoolemail Posted May 18, 2018 Posted May 18, 2018 No. It's SaaS based service. All users get self signed S/MIME certs when they start using the product. If they want to start using certified S/MIME certificates for digital signatures they can do that, but nobody has done that to date
secureschoolemail Posted May 18, 2018 Posted May 18, 2018 I register the domain on the gateway. You modify the connectors and the MX records to point to smg.secureschoolemail.co.uk and that's it. To send a secure email put [secure] into the subject line. Works with O365, GSuite, Exchange etc.
Edutech98 Posted May 18, 2018 Posted May 18, 2018 (edited) Your "contact us" page seems to be done over http. So people will be sending emails with their name, email address, phone number etc over an insecure connection. TBH it screams alarm bells to me when a company offering security products can't get their own basic security right. Edited May 18, 2018 by Edutech98
secureschoolemail Posted May 18, 2018 Posted May 18, 2018 You are absolutely correct. Just sent email to hosting company to ask them to update it to https. Thanks for pointing that out to me
Edutech98 Posted May 18, 2018 Posted May 18, 2018 You also don't have a privacy policy on your website which is basic data protection101 when collecting personal data. And on your GDPR page you spelt the ICO's website wrong ( (http://www.ico.ork.uk). No offence but the company doesn't seem particular aware of basic security or data protection best practises.
secureschoolemail Posted May 18, 2018 Posted May 18, 2018 Many thanks for all your help. All your suggested changes will be up and running by COB Monday. Do you have an interest in email encryption generally or is it just for the education sector
mthomas08 Posted May 22, 2018 Posted May 22, 2018 (edited) For a company that supposedly is all about security, it doesn't give any information about its GDPR compliance. There's several other things that ring alarm bells. Personally I wouldn't touch them with a barge pole. Meldrew Don't necessarily need a product like this. If IT have taken steps to secure their systems or collected GDPR policies from external email providers, add some staff training on being cautious/secure. It's all fine. Our auditor asked some basic questions regarding email and our system updates. He seemed happy. We even do the occasional email to all staff as reminders or with the internal weekly news bulletin. Edited May 22, 2018 by mthomas08
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now