Tech net Why you shouldn't send sensitive emails

26
Why You Shouldn’t Email Your Sensitive Documents David Strom [email protected] TechNet Mid America July 2012

description

This is a speech I am giving at a DoD-sponsored conference in July 2012.

Transcript of Tech net Why you shouldn't send sensitive emails

Page 1: Tech net Why you shouldn't send sensitive emails

Why You Shouldn’t Email Your Sensitive Documents

David [email protected]

TechNet Mid America July 2012

Page 2: Tech net Why you shouldn't send sensitive emails

Email docs to yourself

Page 3: Tech net Why you shouldn't send sensitive emails

Email is inherently insecure…

Page 4: Tech net Why you shouldn't send sensitive emails
Page 5: Tech net Why you shouldn't send sensitive emails
Page 6: Tech net Why you shouldn't send sensitive emails

Secure email alternatives

• Full encryption• DLP• Cloud-based storage• Secure document delivery services

Page 7: Tech net Why you shouldn't send sensitive emails

Full encryption choices

• Voltage SecureMail• PGP Universal Server• Sophos Email Appliance• Proofpoint Protection Server• Mimecast's Unified Email Messaging

Page 8: Tech net Why you shouldn't send sensitive emails

Common product features

• Crypto key management• Auto encrypt sensitive info as part of their

policies• Lots more rules processing• Outlook plug-ins

Page 9: Tech net Why you shouldn't send sensitive emails
Page 10: Tech net Why you shouldn't send sensitive emails

Drawbacks

• No visibility into document chain of custody• Encryption is still largely unused and

cumbersome• Key management

issues

Page 11: Tech net Why you shouldn't send sensitive emails
Page 12: Tech net Why you shouldn't send sensitive emails

Web-based encryption

• Voltage SecureMail Cloud• Hushmail for Business• Proofpoint on Demand• PGP's Web Messenger • Mimecast's Closed Circuit Messaging

Page 13: Tech net Why you shouldn't send sensitive emails

Data loss prevention

• Global Velocity's GV-2010 security appliance • BlueCoat Networks DLP appliance• Sendmail's Sentrion email server• McAfee Host DLP• Symantec/Vontu DLP v10• Safend Protector• Trend Micro DLP

Page 14: Tech net Why you shouldn't send sensitive emails
Page 15: Tech net Why you shouldn't send sensitive emails

File sending services

Page 16: Tech net Why you shouldn't send sensitive emails
Page 17: Tech net Why you shouldn't send sensitive emails
Page 18: Tech net Why you shouldn't send sensitive emails

Responses to MegaUpload shutdown

Page 19: Tech net Why you shouldn't send sensitive emails
Page 20: Tech net Why you shouldn't send sensitive emails

YouSendIt Privacy Policy

Certain information may become accessible, such as the text and subject of messages you have sent, the name and content of the User Files you have sent, the date and time messages were sent, and the email addresses of the recipients.

Page 21: Tech net Why you shouldn't send sensitive emails

Secure document services

Page 22: Tech net Why you shouldn't send sensitive emails
Page 23: Tech net Why you shouldn't send sensitive emails

Security issues

Page 24: Tech net Why you shouldn't send sensitive emails

Secure document issues

• Do you need secure intra- or inter-enterprise collaboration?

• Can you recall sent messages? • What happens when someone leaves your

company? • How does the service affect users’ existing

email experience? • Can you authenticate recipients and thwart

malware such as key-loggers?

Page 25: Tech net Why you shouldn't send sensitive emails

The moral of the story: don’t use straight email to send your documents. Anything is else better.

Page 26: Tech net Why you shouldn't send sensitive emails

Questions?

David [email protected]

314 277 7832@dstrom (Twitter)

http://strominator.com