Jump to content

Recommended Posts

Posted

Hi all,

 

I wondered if anyone has prepared a report for SLT to review the transfer of sensitive information over email?

 

I am currently investigating tightening our policies and procedures and intend to present to our SLT in the next few months with what our various options are. As far as I see it we have three options:

 

Force Secure Transmission of Email within Office 365

+ No cost

+ Using a system staff are currently familiar with

+ Can be setup to automatically secure connection to a number of known services (Child Protection Agencies etc.)

- Does not guarantee secure access the other side (could pop up on a computer for example)

- No control over data retention

- Long wait for NDR if message has been rejected

 

Secure Email Service (such as Egress)

+ Data always within schools control

+ Retention can be managed

+ More secure the other end as the message will not just open if email is left open

- Cost. Could be minimal, depends how many staff are required to send.

- Training for staff to use the new system (minimal)

- Could be a bottleneck for communication if we are relying

 

Encrypting documents before sending

- Longwinded and cumbersome

- Requires staff to communicate password over telephone

- Email filters could reject the encrypted document

 

 

If anyone has anything they have prepared, conclusions they have made etc. I would really appreciate your thoughts.

Posted

I would throw the following in to the mix:

 

Share Files via OneDrive / SharePoint

 

Pros: Part of Office 365

Free

You keep control of the document

You can see who opened it as when

You can update it without re-sending

You can revoke access at any time

You can control things like download, send on etc via the Security & Compliance Center

Posted

Whichever option you go for, I think you need to be pursuing option 1 as well, regardless. Ensuring as far as possible that all incoming and outgoing emails are encrypted in transit. I haven't worked through configuring MTA-STS here yet, but I expect that will be something that will help you to enforce security of email in transit as more and more organisations adopt it.

 

Also, FireFox Send might help you with option 3.

Posted

@robyholmes - Cheers!

@jthompson

 

-With regards option 1, we currently do have opportunistic TLS1.2 configured but are struggling to grasp how to increase security in a manner that provides timely feedback should a message not be possible using this mechanism. NDR's take a day or two to come back which is way to long to consider acceptable if a message is urgent.

- Firefox Send isn't something I had come across but does this not itself present its own GDPR concerns? Will need to investigate this further.

Posted
Just for clarity, I am Spence_101's colleague and he posted the above on my behalf this morning. Also, another negative I have thought of for option 2 (possibly the biggest) is that egress / secure mail phishing is becoming increasingly common so people will be wary of using the links
Posted

We've configured 365 to encrypt messages by default if certain content is detected.

 

Staff can also type "encrypt this message" in subject lines or message body (or click the button in OWA) to encrypt messages ad-hoc.

 

Like @robyholmes for N+1 documents we push staff towards OneDrive sharing - we configure the defaults so documents are only shared read-only with named individuals and with a 7-day window for access.

 

Previously, every outside agency was using a different "secure email" system and our SENCO (for example) had ~7 different logins depending on who the email was from.

 

With regard to emails popping up on computers, force a screen lock after X amount of time. Staff can also quiet notification (Windows 10) when they're teaching so pop-ups don't appear on mirrored screens. IIRC Windows 10 (1809 and greater at least) does this by default when mirroring the screen (same as when you're playing a game full-screen).

Posted

https://office365.uservoice.com/forums/264636-general/suggestions/35748082-shorten-ndr-for-failed-forced-tls

 

Seems like there's no option. The messages end up in a queue, is there a way to query that?

 

What I did was get a report on all email sent, see which had TLS not enabled, and then hit them until they did/add another connector for them that didn't require TLS. Pretty much everyone does now.

 

Hit Nottingham University, they fixed it. BTInternet fixed themselves. Reprotec died.

 

Portland College have a self signed cert, so that's lame.

 

First question is always: What's your threat model, what are you trying to prevent from happening?

Posted (edited)

@pete - Cheers. We are not big OneDrive users at present (working towards this) so feel this may be a step too far at present. With regards email popping up on computers - I am worried about this externally, not here. We already have the systems in place to prevent this happening but worried if we send a particularly sensitive email outside of the college and their is a breach on the receiving end. Having something like egress would go PART WAY to mitigating this.

@mavhc - so have you forced TLS for all? My concern would be that our MIS sends via our tenency. I would suspect out of the 2000 or so parent emails we regularly email to, at least a handful will be regularly failing and not receiving information. This is on top of other random contacts.

 

Good question on threats! My big concern at present is the specific transfer of extremely sensitive information outside of the school environment. I am thinking communication with welfare services, the police ... anything the ICO would deem as particularly sensitive where we must take the highest security measures possible. This is where security in transit, but also security the other end and ensuring it reaches the intended recipient are of vital importance.

Edited by CyBeRkId2002
Posted
Firefox Send isn't something I had come across but does this not itself present its own GDPR concerns? Will need to investigate this further.

 

I'm not sure whether FireFox Send is a true zero-access encryption system or not, so yes, there may be GDPR implications. They say in their privacy notice that only an encrypted copy of your files gets uploaded and that they can't access its contents, but they do presumably control the keys somehow.

Posted
Good question on threats! My big concern at present is the specific transfer of extremely sensitive information outside of the school environment. I am thinking communication with welfare services, the police ... anything the ICO would deem as particularly sensitive where we must take the highest security measures possible. This is where security in transit, but also security the other end and ensuring it reaches the intended recipient are of vital importance.

 

In those instances, the receiving organisation is going to have to be trusted at some point to uphold their end of the data protection bargain. If you've ensured a secure delivery across the Internet to their organisation by having the most super-responsible email server configurations, there's not much more that you can do to demonstrate responsible handling. Even if you've opted to use a system that offers access for only a set period of time, you can't do anything to control how they handle a copy that they've downloaded and stored on their system, and you can't prevent them from storing it on their mail server indefinitely as they pass it around amongst themselves.

Posted

They should have an s/mime certificate that your email client should use to encrypt the sensitive data, then no one else can read it. This problem was solved 23 years ago.

 

http://www.edugeek.net/forums/cloud-services/204977-list-common-email-domains-dont-support-tls.html

 

http://www.edugeek.net/forums/cloud-services/195016-gmail-getting-new-confidential-mode-lock-down-sensitive-messages-5.html#post1750285

 

http://www.edugeek.net/forums/cloud-services/195016-gmail-getting-new-confidential-mode-lock-down-sensitive-messages-4.html#post1750260 I was already on 99.8% TLS so just forced it to 100%

 

That's just stopping people snooping on the traffic though, not really a common thing.

 

If you add a filter on your email server for text that indicates it's a secure document and blocked it, then only encrypted documents will get through.

 

I have a python script that calls pdfencrypt, and 7zip training for office staff, who then phone through the password, that's the only really secure method, everything else means if you email the wrong person they can still read it. and user error is the real problem

  • Thanks 1
Posted

I like that, how did you configure this ?

 

 

We've configured 365 to encrypt messages by default if certain content is detected.

 

Staff can also type "encrypt this message" in subject lines or message body (or click the button in OWA) to encrypt messages ad-hoc.

 

Like @robyholmes for N+1 documents we push staff towards OneDrive sharing - we configure the defaults so documents are only shared read-only with named individuals and with a 7-day window for access.

 

Previously, every outside agency was using a different "secure email" system and our SENCO (for example) had ~7 different logins depending on who the email was from.

 

With regard to emails popping up on computers, force a screen lock after X amount of time. Staff can also quiet notification (Windows 10) when they're teaching so pop-ups don't appear on mirrored screens. IIRC Windows 10 (1809 and greater at least) does this by default when mirroring the screen (same as when you're playing a game full-screen).

Posted
I like that, how did you configure this ?

 

Encrypting if sensitive data is found?

 

Standard "if X, do Y" Exchange Transport Rule. Test this with a small subset of people as you'll discover people have been [doing daft things for years as standard practice when you make this "live".

 

Apply rule if:

 

Sender is located "inside the organisation"

The message contains any of these sensitive information times (adjust to suit - you can pull in standard sensitive info categories, plus custom sensitive information types such as UPN if you define them in https://protection.office.com/sensitiveTypes)

 

Do the following:

 

Apply Office 365 Message Encryption and rights protection to the message (RMS template "encrypt").

 

Except if:

 

(define exceptions here)

 

We also have another rule that looks for the phrase "encrypt this message" in the message body or subject for outgoing mail and triggers the same encryption if it's found.

  • 2 weeks later...
Posted (edited)

Just set up connector here to force TLS 1.2 for all email communications.

All the major email providors support it (Yahoo, Hotmail, Gmail etc...).

 

For the odd users that we get NDR's for (which are usually custom domains) then I email them from a personal email advising them of the situation and that they should speak with whoever manages their email server to update in order to meet todays recommended standards of TLS 1.2.

 

They might have a little moan and groan however if personal data on their child was to be intercepted and used they would be even angrier!

 

 

I went down the route of trying the Office 365 encryption via OME and the new method however it just doesnt work unless using a web mail client or outlook app on a mobile.

IOS mail can handle it to a degree but Android mail just doesnt work with the way the attachment from these methods is presented to click on and then launch the webpage and follow hence the just forcing TLS 1.2 otherwise it was going down the route of Egress or something like that which is stupid money.

Edited by Tefters
Posted (edited)

As an update if anyone is interested - We are now on day 5 after I implemented forced TLS and what this has highlighted is how other companies do not deal with email security seriously enough.

 

3 companies have flagged up with bouncebacks to us, 2 with self-signed certs and in-house IT departments and 1 with an expired certificate for over a year outsourced to an IT company.

I have since emailed these companies and advised them, they are quite embarassed and are resolving the issues. The outsourced IT support company has no clue claiming TLS was enabled and everything was working fine until I highlighted to them that their wildcard SSL certificate expired over a year ago so TLS had not been functioning even though enabled.

 

https://www.checktls.com/ is a great resource to point out their errors.

Edited by Tefters

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...