Padgett-Beale has been a long standing institution in the hospitality
industry. With that longevity comes certain corporate secrets,
intellectual property and other competition sensitive information that
ensures that Padgett-Beale stays competitive. As demonstrated by
recent events involving Padgett-Beale intellectual property, there is a
demand for attackers to obtain such data and either resell or pass it
on to the competition. Thankfully the other firm acted ethically and
immediately reported the leaked information to the Corporate
Security Office. Such incidents pose a danger to Padgett-Beale
remaining competitive; if the competition possesses confidential
corporate information, those firms can unfairly adjust their strategies
to run Padgett-Beale out of business. Padgett-Beale needs to be
vigilant to counter these acts of industrial espionage.
Intellectual property theft can take a variety of forms, and come from
a number of different sources. Intellectual property theft can happen
via the competition paying for a product or service and reverse
engineering it, infiltrating trade shows, questioning customers, and
even going through the trash (Molinski & Greenwald, 2015). Some
individuals and organizations will take this type of industrial espionage
even further; Uber has been accused of hacking competitor’s
databases, wiretapping hotels and conference venues, impersonating
employees, and covering it all up by destroying records (CI Radar,
2017). The threat of industrial espionage is both an internal and
external threat; everyone from a disgruntled employee to a foreign
government can have an interest in procuring Padgett-Beale secrets.
The competition can be relentless if they want the data bad enough,
and Padgett-Beale needs to be prepared to deal with the constant
threat.
Padgett-Beale needs to implement tools and policies to help combat
the ever present threat of industrial espionage and IP theft. The first
recommendation is to do a complete information audit to find out
where and how competition sensitive information is stored. This audit
should include the amount of information stored, what types of
information are stored, what systems it is stored on, and how those
systems are protected (Cooper, 2017). The results of this audit will
give Padgett-Beale an idea of it’s current security posture, and what
further changes should be implemented. Following this, Padgett-Beale
should develop a system of classifying and marking data with the
appropriate classification markings. Such markings could include
“Competition Sensitive”, “Padgett-Beale Proprietary”, “PII”, “PCI”,
“FOUO” (For offical use only), and so on. If data is properly marked
there is less of a chance of it being accidentally mishandled. In
addition to headers and footers that can be manually inserted into
documents and other data types, there are also tools that can mark
and set rules on “classified” data. Some software companies that
produce such software include Netwrix, Varonis and Spirion. The
company should then audit the responsibilities of each position in the
company. There needs to a be a sort of checks and balances system
with each position within Padgett-Beale to ensure not one position
has too much power to mishandle data. This is referred to as the
separation of duties; duties are split among multiple positions to
ensure one position cannot abuse their authority. In the context of
Cybersecurity, it ensures no one person controls all of the data. A bad
actor with that kind of access would be incredibly hard to detect, and
thus needs to be accounted for. The next recommendation is to
implement the principle of least privilege. Give employees just enough
access to information to perform their job, and no more than that.
This ensures that access to data is limited to those who are authorized
to work with it, limiting the chances for it to fall into malicious hands.
Padgett-Beale should also review it’s data destruction policy. As
mentioned earlier, bad actors will have no problem rifling through the
trash in order to uncover secrets. All documents containing sensitive
information should be properly disposed of via shredding. Not all
shredders are fit for the job; shredders with a security rating of P4 or
above should be used for proper paper destruction (Advantage
Business Equipment, 2018). For the final recommendation, Padgett-
Beale should implement monitoring and detection software to ensure
that data is not exfiltrated. One such example of this type of software
would be a Data Loss Prevention System or DLP. DLP systems can
monitor and block data from being exfiltrated from an organization.
Depending on the system implemented, the DLP system can also be
used classify and mark data (Fortinet, 2022). DLP software will alert
organizations and block exfiltration actions whenever an event occurs.
While policies can help with the prevention of industrial espionage
incidents, hardware and software solutions are needed in order to
properly enforce protection measures.
Industrial espionage and IP theft are two threats that Padgett-Beale
will constantly face. In light of the most recent incident, steps need to
be taken in order to protect the company. Threats can materialize
both inside and outside the company, and range in both scale and
severity. In order to combat this threat Padgett-Beale, at a minimum
needs to take the following six steps: audit the current data situation,
mark and classify the data, separate duties, implement the principle of
least privilege, ensure proper data destruction techniques are used,
and implement a software solution such as a DLP. While the threat
can never be eliminated, there are many steps Padgett-Beale can take
to reduce the risk of industrial espionage.
Sources:
Advantage Business Equipment. (2018, August 22).
Shredder security
levels explained: Paper shredder information
. Advantage Business
Equipment. Retrieved April 23, 2022, from https://www.abe-
online.com/paper-shredder-levels-of-security
CI Radar. (2017). Competitive intelligence blog. CI Radar. Retrieved
April 23, 2022, from https://ciradar.com/competitive-intelligence-
blog/insights/2017/12/22/the-ethics-of-competitive-intelligence-
where-uber-crossed-the-line
Molinski, W., & Greenwald, A. N. (2015, August 14). The fine line
between spying and strategy: Competitive Intelligence's legal limits
and practical considerations. Trade Secrets Watch. Retrieved April 23,
2022, from https://blogs.orrick.com/trade-secrets-
watch/2015/08/14/the-fine-line-between-spying-and-strategy-
competitive-intelligences-legal-limits-and-practical-considerations/
Cooper, C. (2017, July 13).
Cyberespionage: Your intellectual property
under threat
. CSO Online. Retrieved April 23, 2022, from