Jump to content

Recommended Posts

Posted

As we develop our solutions further for Education we're keen to understand what your biggest concerns are and what would ally those concerns.

 

For example is you greatest concern cyber attack and what kind of solution would work for you? I.e greater security in terms of firewalls and antivirus or would you like to move to a secure entirely cloud platform?

 

Are you looking for an all in one solution or are you keen to manage it yourself?

 

Do you think your IT supplier takes GDPR seriously enough?

  • 4 months later...
Posted

My biggest concern is a data breach, e.g. malware infects one of our staff accounts, which then takes a copy of that staff members mailbox and also a copy of the fileshares she has access to.

I know there is sensitive data on file shares that most of our staff members have access to - e.g. results of special needs investigations, childrens behavioral reports etc.

 

It isn't ideal but a lot of our staff are older and are stuck in the way of working with fileshares and e-mails - they will e-mail documents to themselves to work on, then e-mail them back - and our wellbeing department has a folder in a network share, that they all work from e.g. a spreadsheet with behavior logs in it, a staff member will log a concern in the spreadsheet, and a member of wellbeing will call home and note the result in this spreadsheet.

 

This isn't ideal because if one of these staff accounts gets compromised, all of this data could be rinsed by malware, and then we could be threatened to pay BTC or all of this very sensitive data gets leaked.

 

This is my biggest fear, and some of this new malware is so sophisticated it could slip right by Sophos antivirus, and perhaps even AppLocker.

Our network got hit a few years ago with Emotet, it sailed right past Sophos; this was before I had set up AppLocker however. Anyway it was impossible to remove, luckily we were replacing our entire network infrastructure that summer anyway or we'd have been in serious trouble. This Emotet just sent out spam, if it had rinsed our data it doesn't bear thinking about.

 

Anyway mitigating against this is very difficult, I am trying to train staff in Google Docs but that has its own issue, it only takes a successful phish and you have exactly the same problem. Does anyone here use 2FA for all staff?

 

So for me my worries are: Sensitive data is kept in e-mail inboxes/sent items inappropriately, and b) Shared staff drives, that pretty much all staff have access to, has sensitive medical data in it, I have password protected a lot of these documents but new ones are saved with no password and it could be a while before I get to it.

We have bought into some MyConcern thing with our LEA, hoping to learn about that and see if that might offer us a solution.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...