Introduction
Intellectual property theft is a growing threat worldwide. “The
Intellectual Property Commission estimates that intellectual property
theft in the form of counterfeit goods, trade secret theft, and pirated
software costs the US economy $225 billion to $600 billion. According
to intellectual property crimes statistics, that’s about 1% to 3% of the
US’s GDP”. (Lazic, 2021). Unfortunately, Padgett-Beale is now
experiencing the devastating effects of intellectual property theft
firsthand. Investigation within the Corporate Security office is ongoing.
The initial analysis indicates that it was most likely an Advanced
Persistent Threat (ATP) that infiltrated the corporate network and
illegally exported the organization’s intellectual property. The purpose
of this research and analysis paper is to briefly define an APT, include
processes and procedures that will help prevent future intellectual
property theft. In addition, a list of recommended best practices will be
provided to ensure future protection of the organization’s intellectual
property.
Analysis
After the full investigation of the recent data breach is complete the
company will have detailed data on the exact mechanism in which an
outside entity was able to access secured corporate data. It is
imperative that we all take the appropriate steps to ensure that the
proper processes and procedures are in place to ensure that the
company's intellectual property is secure in a manner that it is difficult
for employees, managers, and executives to inadvertently misuse
and/or steal the company's intellectual property in the future. There
are three policies that should be enacted and enforced as soon as
possible to make this prevention successful.
1. Data Classification and Marking: Data classification is an
important component of any information security program. “Data
classification provides a solid foundation for your data security
strategy by helping you understand where you store sensitive and
regulated data, both on premises and in the cloud”. (Sotnikov,
2020). The process is involves organizing data into relevant
categories that represent different types of data. Typical
classifications include Private, Confidential, Sensitive, Personal,
and Public. Once the data is classified it is marked or tagged with
this classification. The classification will determine where and
how the data is stored as well as who will have access to the data.
2. Separation of Duties (SoD): The concept of separation of duties
involves requiring more than one person to accomplish a
particular sensitive task. “SoD, as it relates to security, has two
primary objectives. The first is the prevention of conflict of
interest (real or apparent), wrongful acts, fraud, abuse and errors.
The second is the detection of control failures that include
security breaches, information theft and circumvention of
security controls”. (Behr & Coleman, 2017).
3. Least Privilege: Another important component of any information
security program is the principle of least privilege. This policy
entails giving a user the minimum amount of privilege or
permissions needed to perform their job function. Lease privilege
has the ability reduce cyber crime surface. “Most advanced
attacks today rely on the exploitation of privileged credentials. By
limiting super-user and administrator privileges (that provide IT
administrators will unfettered access to target systems), least
privilege enforcement helps to reduce the overall cyber attack
surface”. (Cyberark, n.d.).
Recommended Best Practices
The following recommended best practices to prevent identity theft or
fraud should be enacted and enforced across the organization to
immediately increase the level of corporate digital security.
1. Increase monitoring of activity across user accounts.
2. Archive data securely in a timely manner.
3. Encrypt all sensitive data.
4. Increase training for improved awareness of intellectual property
security.
5. Increasing training to users to ensure they can recognize and
avoid phishing attacks.
Summary
The Corporate Security office for Padgett-Beale must take every step
possible to ensure that the recent intellectual property theft
experienced will never happen again. After the investigation of the
recent theft is concluded there will most likely be additional suggested
policies and best practices, but it is imperative to get started securing
our intellectual property as soon as possible.
References
Lazic, M. (2021 February). 29 Crucial Intellectual Property Statistics.
Legaljobs. Retrieved from legaljobs.com:
https://legaljobs.io/blog/intellectual-property-
statistics/#:~:text=The%20Intellectual%20Property%20Commission%2
0estimates,3%25%20of%20the%20US's%20GDP.
Sotnikov, I. (2020 September). Data Classification: What It Is and How
to Implement It. Netwrix Blog. Retrieved from blog.netwrix.com:
https://blog.netwrix.com/2020/09/02/data-classification/
Behr, A. & Coleman, K. (2017 August). Separation of duties and IT
security. CSO. Retrieved from csoonline.com:
https://www.csoonline.com/article/2123120/separation-of-duties-
and-it-security.html
Cyberark. (n.d.). Principle of Least Privilege. Cyberark Glossary.
Retrieved from cyberark.com: https://www.cyberark.com/what-
is/least-privilege/