We use cookies and data to
- Deliver and maintain Google services
- Track outages and protect against spam, fraud and abuse
- Measure audience engagement and site statistics to understand how our services are used and enhance the quality of those services
If you choose to ‘Accept all’, we will also use cookies and data to
- Develop and improve new services
- Deliver and measure the effectiveness of ads
- Show personalised content, depending on your settings
- Show personalised ads, depending on your settings
If you choose to ‘Reject all’, we will not use cookies for these additional purposes.
Non-personalised content and ads are influenced by things like the content that you’re currently viewing and your location (ad serving is based on general location). Personalised content and ads can also include things like video recommendations, a customised YouTube homepage and tailored ads based on past activity,…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
