Skip to main content

Mailing Systems Technology July/August 2023

Page 18

By Alexandria Gregory

THE QUEST FOR ABSOLUTE DATA SECURITY: 6 KEY CONSIDERATIONS

T

here is an adage that states all press is good press, but when it comes to data security, nothing could be further from the truth. For organizations that outsource their print and mail communications, being in the news is rarely, if ever, a positive — which is why it’s important to establish the proper systems for securing customers’ sensitive data. Statistics around data breaches have grown even more alarming in recent years, particularly for ransomware attacks, where malicious software locks a device’s data and demands a ransom before restoring access. Today, the average ransomware demand clocks in at $247K, with the average ransomware payment closer to $952K. Only four percent of companies who pay the full amount are able to retrieve all of their lost data, and the cost of recovering from such an attack exceeds $1.8 million. These staggering figures, which are expected to continue climbing throughout 2023, demonstrate the increasing severity of such attacks, not to mention the devastating financial consequences of damaged brand reputation. With data breaches, hacking incidents, and multi-million-dollar fines showing up in the news headlines continually, the old days of encryption keys just don’t cut it anymore. Today, the focus must be on leveraging technology in a way that keeps your files, your customers’ data, and you absolutely secure and able to sleep at night. The word “compliance” often arises in conversations about data security, but the idea that regulatory compliance is synonymous with security is an unfortunate misconception. While regulations tend to include common elements, such as risk assessment, access control, and vendor management, many breaches often result from negligence from within the organization rather than an attempt by an outside party to gain access to protected data.

18

JULY-AUGUST 2023 | MailingSystemsTechnology.com

By following these six considerations, it’s possible to fill in the gaps of a compliance-only strategy while also anticipating changes to the cybersecurity landscape. Adopt a prevention mindset. To transform your approach to data security and compliance, it’s critical to take a strategic, long-term view that’s laser-focused on prevention. One place to start is by seeking out a customer communications management (CCM) software solution that travels with the data to safeguard it against breaches at every step. No matter what solution you choose, it needs to be able to keep pace with the rapidly and constantly evolving trends in cybercrime.

1

Reference the CIS Critical Security Controls standards. As you’re assessing risks, take advantage of the established industry standards from the nonprofit Center for Internet Security (CIS). Formerly known as the SANS Critical Security Controls, the CIS Critical Security Controls (also called CIS Controls) are a set of 18 recommended actions designed to protect organizations and data from the most prevalent types of cyberattacks. Ranging from inventory of enterprise assets to access control management, security awareness, skills training, and web browser protections, this set of controls offers helpful guidance for mitigating risk in all areas of the enterprise.

2

Look for a CCM tool that’s built with data security in mind. Many companies that outsource their customer communications cobble together software products from multiple vendors, each serving a single purpose within the workflow. However, this patchwork approach to organizational workflow complicates integration, in addition to increasing the

3


Turn static files into dynamic content formats.

Create a flipbook
Mailing Systems Technology July/August 2023 by MadMen3 - Issuu