A Fortify 24x7 brand. Security set properly for firms that sell things and keep books.Your accountAsk us something
SecureBizIT
Forme 07 / Where the data sits

You cannot protect the customer list if nobody knows where the copies are.

Small firms accumulate data the way a workshop accumulates offcuts. A spreadsheet of card details from a system retired in 2019. Scans of identity documents inside a mailbox export. The whole customer list on a laptop belonging to somebody who left. This forme locates the lot first. Only then does it rule on what may go where.

ActifileDiscovery firstThen the exits
2 sorts / find it first / then govern it
Sorts in this forme2
Set onActifile
Counted inDevices
Worked byFortify 24x7 engineers

Finding comes before governing

Every data policy ever drafted assumes somebody knows where the data lives. Almost nobody does. Actifile reads across machines and shares and returns an inventory: which sensitive material, how much of it, and the device carrying the heaviest load. That last figure is the useful one, because it turns an overwhelming problem into a running order.

The findings are uncomfortable in a fairly predictable way. It is rarely the server. It is a laptop in the back office, a shared folder named Old Stuff, and four copies of one export made for a migration nobody finished.

It is rarely the server. It is the shared folder called Old Stuff.

Then the exits

Encryption is applied to the files themselves, so a copy that walks out on a memory stick is still covered rather than becoming a plain document the moment it leaves. The routes data genuinely leaves by, which are removable drives, uploads and mail attachments, get watched as real exits instead of assumed to be shut.

What you want out of this is a number that goes down. Exposure per device is tracked over time, so a clean up shows up as a trend rather than as a claim somebody makes in a meeting.

Sorts on this forme

Specifications and rates

Figures underneath come straight from billing when this page opens. Whatever you set falls into the composing stick and sits there until you are done reading.

Fortify-DLP-ClassifySpecification

Sensitive Data Discovery

Actifile, reading what is genuinely on the disks and shares

No rule governs a folder nobody has found. This goes hunting: card numbers in a retired spreadsheet, identity documents inside a mailbox export, the customer list on a machine belonging to somebody who left two summers ago.

  • Reads across machines and shares hunting regulated and commercially awkward material.
  • Gives each machine a figure, and the figures decide what gets cleaned first.
  • Turns up copies nobody remembers making, and there are always copies.
Set onActifile
PrintsAn inventory of sensitive files, every machine carrying a figure
Standing typeScanning that keeps going, rather than one report a year
Locked byA scope you set over the machines and shares you name
Proofed byA trend line showing the exposure figure coming down
Pullingper device
charged up front, month by month
QTY
Fortify-DLP-EnforceSpecification

Encryption and Channel Control

Actifile, encrypting the files and minding the exits

With the sensitive files known, this settles what may happen to them. Encryption follows the file itself, and the routes data really leaves by get watched instead of assumed shut.

  • Encryption applied to files, so a copy stays covered after it walks.
  • Removable drives, uploads and attachments treated as the exits they are.
  • An alert when the pattern shifts, such as a bulk copy at an odd hour.
Set onActifile
PrintsEncrypted files, and an alert when one leaves oddly
Standing typeEncryption that travels with a file off the machine
Locked byRules you agree, applied to the channels you name
Proofed byReporting on what moved, where to, and under which account
Pullingper device
charged up front, month by month
QTY
Honest scope

Where this forme stops

Knowing where your data sits is powerful and it is not everything. Marked up here is where these two lines stop.

  • stetIt is not a compliance certificate. Knowing where regulated data sits helps enormously with an audit and is not the same as passing one. Nobody here will hand you a certificate we have no standing to issue.
  • delAn authorized person can still take a file. Whoever may open a document may equally keep hold of one. This makes that visible and puts encryption around it. It does not make it impossible.
  • trDiscovery covers what is in scope. Machines and shares on the list get read. A personal device, or a cloud account nobody mentioned, sits outside until it is added.
  • wfCleaning up is your decision. We can show you four copies of the same customer export. Deleting three is a commercial decision, and it is not ours to take for you.
  • spClassification is very good without being perfect. Automated matching finds far more than a manual review ever would, and it will occasionally flag something dull. Expect to tune it during the first month.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - SecureBiz IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.