1 / 4100%
Due to recent events, it is important that we address the problems associated with
intellectual property theft. It was discovered that competitors obtained copies of confidential
architectural drawings from Padgett Beale. After investigation by the Corporate Security office,
it was discovered that the drawings were obtained by way of an Advanced Persistent Threat
mechanism from an existing Padgett Beale hotel in the same geo-political jurisdiction. An
advanced persistent threat mechanism is where a cybercriminal gains access to a file,
network, or an email and then inserts malware into a network. This malware continuously
looks for vulnerabilities and exfiltrates information from the network, even if encrypted
(Anatomy of an APT (Advanced Persistent Threat) Attack, n.d.). Another competitor came forward,
to say that they also received URLs for web pages containing links to the resort plans by an
unknown party. Intellectual property theft can cause a company to lose competitive edge, a
slowdown in business growth, and reputational damage (Gartner, 2021) . Tools such as data
classification and marking, separation of duties, and least privilege should be used to
discourage or make it difficult for employees, managers, and executives to inadvertently
misuse and/or steal the company's intellectual property.
One way to protect intellectual property theft is by using data classification. Data
classification organizes data into categories based on their content and the file type. This
allows the company to identify important or sensitive files and secure critical data.
Identifying the files allows you to limit access to personally identifiable information (PII),
control location and access to intellectual property, and reduces attacks to the surface area
of the sensitive data. The data would be classified into low sensitivity, medium sensitivity,
and high sensitivity data. The low category would include public information that doesn’t
require any access restrictions. The medium level is intended for internal use, but if the
information was breached, there wouldn’t be a catastrophic result. The high sensitivity data
category would require strict access and controls. These implementations would reduce the
chance of leakage of important information (Petters, 2021).
The next tool that would assist in discouraging intellectual property theft is the
implementation of separation of duties. Separation of duties is the belief that no one person
should hold all of the responsibilities for a key function. For example, you wouldn’t give
one person the keys, lock, and code for a nuclear weapon. The responsibility would be
spread out. This prevents someone from doing catastrophic damage to a company, by
having too much power. In this situation this would be beneficial, to ensure that one
individual does not have access to conflicting roles, that could allow them to commit
intellectual property theft (Sorenson, 2021) .
The third tool that will be discussed is least privilege. Least privilege is the practice
of restricting access rights for employees to only what is required for them to perform their
job. Least privilege ensures that only the minimal level of user rights is applied for systems,
processes, devices, and application. This will ensure that employees only have access to
what they should, and in the event that they are hacked or information is stolen, the
information that is stolen won’t be catastrophic to the company since they had minimal
access (Miller, 2021).
With these processes and procedures, intellectual property theft should be
discouraged and prevented. There are some best practices that the company can practice on
the daily to protect the future growth of the company. There best practices are to ensure that
proper training is given to employees. This will assist with preventing employees from
making unintentional mistakes. Data encryption is another best practice. This will ensure,
that if the information is accessed, it will be harder to steal the information. It is important
to back up important files. This will ensure that in the time of data loss, you are able to
gain access to the data another way. Ensure this data is protected as well. Running regular
test and audits such as penetration testing is a great best practice. This will detect any
vulnerabilities in your system, therefore providing preventative measure before an actual
attack. Physical security is just as important as data security. Ensure you are protecting all
sensitive physical information, so that it is not put into the wrong hands (Henry, 2017) .
In conclusion, intellectual property theft can cause a company severe damage. It can
lead to financial loss, competitive edge loss, and reputational damage. Padgett Beale has
recently discovered that they were victims of intellectual property theft by way of an
Advanced Persistent Threat mechanism and the forwarding of information by an unknown
party. Tools that would discourage and prevent this behavior are data classification and
marking, separation of duties, and least privilege. There are also a few best practices that
the company can practice daily to assist in the prevention of intellectual property damage.
Security is extremely important at Padgett Beale and these tools and best practices will
greatly assist with reducing and discourage intellectual property theft.
Works Cited
Anatomy of an APT (Advanced Persistent Threat) Attack. (n.d.). FireEye. Retrieved April 27,
2022, from https://www.fireeye.com/current-threats/anatomy-of-a-cyber-attack.html
Gartner. (2021, May 18). 7 Best Practices to Prevent Intellectual Property Theft. Ekran.
Retrieved April 27, 2022, from https://www.ekransystem.com/en/blog/best-practices-to-
prevent-intellectual-property-
theft#:%7E:text=The%20impact%20of%20intellectual%20property,at%20a%20country
%2Dwide%20level.
Henry, M. (2017, October 12). 7 BUSINESS BEST PRACTICES FOR PROTECTING
INTELLECTUAL PROPERTY. Henry Patent Law Firm. Retrieved April 27, 2022, from
https://henry.law/blog/7-business-best-practices-for-protecting-intellectual-property/
Miller, M. (2021, February 19). What Is Least Privilege & Why Do You Need It? BeyondTrust.
Retrieved April 27, 2022, from https://www.beyondtrust.com/blog/entry/what-is-least-
privilege
Petters, J. (2021, March 25). What is Data Classification? Guidelines and Process. Varonis.
Retrieved April 27, 2022, from https://www.varonis.com/blog/data-classification
Sorenson, N. (2021, July 1). Segregation of Duties in Your Organization. Pathlock. Retrieved
April 27, 2022, from https://pathlock.com/learn/segregation-of-duties-in-your-
organization/
Students also viewed