[Product]How to Protect Confidential Data during Job-Transition Season

e758b902dc828.png


Towards the end of first half of the year, after companies wrap up salary negotiations along with bonus payouts, 

there comes job transition period with new job openings in the market.


During such period, not only employees walk out the door but also company’s confidential data

that they handled leave along with them such as design files, source codes, customer information and many more.


In such cases,

if we have limitations in keeping key talents, at least we must protect our company assets, 

both tangible and intangible. Let’s take a look how we can prevent our corporate assets.

 



01. Reasons Why We Need to Pay Close Attention during Job-Transition Season


As mentioned above, job transitions are mostly witnessed towards the end of first half

after salary negotiations and bonus payouts.


It is also when critical security gaps occur due to unexpected off-boarding of key talents

within organizations.


The problem is that these moments can quickly become the significant security gaps.


According to Proofpoint's 2024 Data Loss Landscape Report*, 87% of data exfiltration

from cloud environments was caused by departing employees.


In other words, companies often possess misconceptions that the person most likely to

walk away with the greatest volume of critical data is by an outside hacker; when such

data loss are mostly caused by our colleagues right next to us. And the moment they're

most active is often witnessed during jot transition period

 


02. What are the common cases of data exfiltration


Looking at the real-world cases, the methods are surprisingly simple.

Among the cases disclosed by National Intelligence Service, there was an incident*

when an employee copied ship-component design technology worth billions of won sponsored by national R&D funding 

into an external hard drive upon resignation,

and then set up a separate entity to transfer the core technology overseas.

 

When critical data resides on a personal PC, a single external device can enable " bulk data exfiltration"

resulting in an enormous risk for organizations.


Moreover, when employees upload work files to a personal email or personal cloud storage, 

such files remain accessible from anywhere even after resignation with just a few clicks. 

As the Proofpoint figures* show, file exfiltration in cloud environments happens so easily and

so often that getting ahead of this risk has become urgent.


These two leak methods share one thing in common:

they happen when critical data is scattered across personal PCs under no control.

 


03. What Companies are missing during off-boarding


Many companies have security checks during offboarding process, such as interviews,

confidentiality agreements, equipment returns, and so on. These are absolutely necessary steps.


However, this approach alone has its limitation; the key reason is timing. 

Starting a security review at the point of an employee's departure is like investigating the aftermath after sensitive data has already been dispersed across personal PCs and external media. Even with a signed security pledge,


if the company has no visibility into which files exist, where they reside,

and in how many versions, there's no way to control them.


What's more, security solutions like DRM and DLP control the point at which documents leave the organization,

but where that document is normally stored, and in what version, often falls entirely outside the scope of their 

management.


Ultimantely, the key isn't the last day of an employee’s departure, it's everyday security management.

 



04. The Solution: Document Centralization


The answer is to gather assets on a central server rather than on individual PCs from the very start,

in other words, document centralization.


It's a system that forces every document generated within a company to be stored and managed on a central 

server instead of on user PCs, bringing security policy, access permissions, usage history,

and document lifecycle all under one unified framework.


Unlike a simple file server or cloud storage, the key is that it controls local storage at the PC level and

treats the central server as the single source of truth.


Cyberdigm's Destiny ECM is one of the leading solutions. Since its foundation in 1998, 

the solution has been deployed to more than 1,400+ companies over 28 years, serving over 1.1 million users

with a consistent R&D investment of 25%+ of revenue, and it holds ISO 27001 certification, 

the international standard for information security management.



How exactly does document centralization protect critical data?


First of all, the most powerful control in document centralization is PC storage control.

Instead of storing at PC or local drives, 


it directs users to store all documents on the central server so that no critical data can remain at any employees

personal device. This means that the pathway can not exist through which data could leak via either external hard 

drives or USB devices.


Document centralization also provides granular access permissions by department, user, position, or device, enabling 

individualized control within the same folder. Therefore, once resignation is confirmed, all access privileges associated 

with that account can be revoked all at once, whereas all relevant data remains on the central server.


Finally, any external transfer of data is impossible without administrator approval, and MFA combined with bulk-

download detection flags abnormal activity instantly. If a departing employee attempts to download an unusual large 

volume of data, an alert fires at the very moment.


On top of all this, features like a user-friendly UI identical to Windows, URL sharing, real-time co-editing, and version 

management enhance both security and collaborative measures.


We can’t stop employess from leaving organizations. 

However, whether your company’s technology and trade secrets leave with them depends on which systems are already 

in place. With 28 years of accumulated document centralization expertise, Cyberdigm is here to help you make that 

starting point, protecting your company's assets even when key talent departs.

 


Reference:

  1. "2024 Data Loss Landscape Report," Proofpoint, CIO Korea
  2. Technology Leakage Case, National Intelligence Service Industrial Security Materials (https://nis.go.kr/AF/1_5_1_2.do)