Jump to content

How to protect Data from being stolen?

The_DR

Hey Guys, 

 

I have a question. I have an employee that has to work with some Data. It's actually a Database with about 10GB of Data. The employee has to work with the real data, it can't be replaced by dummy data. What can I do to prevent the employee to steal the data? For example to download it to an USB Drive. Or to upload it into the Internet. What's possible?

Link to comment
Share on other sites

Link to post
Share on other sites

Not enough information, what kind of database and how are they working with it? You do need to give employees a certain minimum amount of trust in order for them to do their job.

Link to comment
Share on other sites

Link to post
Share on other sites

Well there's 2 solutions: technical and human

Technical solution is to never have the data leave your server, employee should be given a remote access with secure vpn tunnel

That's how corps do it

Now the human solution is called trust 😉

System : AMD R9 5900X / Gigabyte X570 AORUS PRO/ 2x16GB Corsair Vengeance 3600CL18 ASUS TUF Gaming AMD Radeon RX 7900 XTX OC Edition GPU/ Phanteks P600S case /  Eisbaer 280mm AIO (with 2xArctic P14 fans) / 2TB Crucial T500  NVme + 2TB WD SN850 NVme + 4TB Toshiba X300 HDD drives/ Corsair RM850x PSU/  Alienware AW3420DW 34" 120Hz 3440x1440p monitor / Logitech G915TKL keyboard (wireless) / Logitech G PRO X Superlight mouse / Audeze Maxwell headphones

Link to comment
Share on other sites

Link to post
Share on other sites

Firstly by not letting people that you think will steal your data work on it.

 

It sounds like your company needs to look into some data policies. Something like a "nothing leaves the premises" approach where all work is done on a machine that requires some sort of verified login, stays locally, is monitored all the time, is disconnected from any network etc. There are many approaches.

 

 

Crystal: CPU: i7 7700K | Motherboard: Asus ROG Strix Z270F | RAM: GSkill 16 GB@3200MHz | GPU: Nvidia GTX 1080 Ti FE | Case: Corsair Crystal 570X (black) | PSU: EVGA Supernova G2 1000W | Monitor: Asus VG248QE 24"

Laptop: Dell XPS 13 9370 | CPU: i5 10510U | RAM: 16 GB

Server: CPU: i5 4690k | RAM: 16 GB | Case: Corsair Graphite 760T White | Storage: 19 TB

Link to comment
Share on other sites

Link to post
Share on other sites

Honestly, I don't believe in trust. Because I can't count how many times my company had cases  for Data Recovery when an employee (of another company) was let go or even fired and on his last day he took the database of the clients with him AND wiped all the data he had access to. 

 

Well, I don't care if some one is going to take some records like screenshots. But the whole Database is critical. 

 

Well, I can give the employee access via RDP. So the data never going to leave the network. But how can I prevent RDP from mounting USB Devices remotely? Hm... And firewall Rules on the RDP Machine, that gonna allow the Access via RDP but block other Traffic into the Internet?

Link to comment
Share on other sites

Link to post
Share on other sites

There's plenty of enterprise software for data management. usbguard can easily prevent unexpected usb connections, without actually costing anything (it's a Linux package, but i think that should illustrate my point). And I'd assume if you are running a data center, you should already have at least one guy in charge of security. If the stuff is as critical as you say, than that would be the only logical option.

 

As tikker said, just don't give untrustworthy people access to the data. Databases technicians are usually supposed to be screened more thoroughly than McDonald's workers. Revoke access if there's a reason to believe that the employee is copying stuff.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×