Archive for the ‘Security’ Category

Why encrypted email is essential

Monday, September 18th, 2017

Email just isn’t safe and, when your business depends on it, you need to consider other ways of communicating.

Emails can end up in the wrong hands – by human error or more sinister means. We’ve all sent emails by mistake (‘Sorry, that wasn’t meant for you’) and we also know of companies who have had their systems hacked. Both of these scenarios are commonplace. They also smack of incompetence and unprofessionalism – both bad news for any professional firm.

So what’s the alternative? We believe it’s all about building layers of security, making it harder to access or make mistakes. docSAFE allows you to send an encrypted message to a secure portal. The recipient is notified and then visits the portal to collect it. The email, its contents and any attachments STAY IN THE SECURE PORTAL. You can also see who reads it (or not).

It’s really inexpensive, simple and it works – please ask us for more details or a free trial.

Why all kinds of organisations should be using docSAFE

Tuesday, August 29th, 2017

We traditionally provide docSAFE to the professions who demand top security and client confidentiality (among other things). However we are seeing docSAFE rise in popularity with other sectors, almost by accident but with very good reason.

You may have seen a mailer we sent out recently that illustrated how the NHS had suffered a huge breach of data of its junior doctors in the north-east. We researched this and found that the NHS staff use of WhatsApp is also widespread which is really worrying.

Organisations that hold any personal data, especially publicly accountable organisations, should be using systems to communicate that are extremely secure. docSAFE has been designed to be secure on a number of key levels – secure login (using 2-factor authentication), secure portal in which to exchange messages and documents, online signing, to be GDPR compliant, offer automatic backups to secure EU based servers and much more.

By using a portal instead of email, for example, the message sit in the cloud until the recipient accesses it. By return, the responses sit in the cloud until the sender accesses it. Both are notified and know the information is there – but it’s locked away safely, staying put, not flying through the ether.

We are expecting more uptake of docSAFE by schools, colleges, universities, doctors and hospitals and similar organisations where security simply cannot be the weak link. Talk to us if you think we can help with your secure communications.

The top reason for cloud working – security

Monday, June 26th, 2017

It really doesn’t matter how good your systems are if they are open to all. By having a portal that is as secure as it is possible to be, you are safeguarding your data, your clients’ data and your reputation. No one likes to work with a business that is flaky or relaxed about the security of their business, and this is especially true of the professions.

We build in layers and layers of security which we believe is the safest approach. It would be a very confident organisation that claims they are impenetrable as hackers are increasingly sophisticated. However you should be working with a business that is ahead of the game, adding new elements of security and constantly active in developing its security.

You might be forgiven for thinking that hackers aren’t interested in Joe Bloggs high street firm – but they are, for many reasons. They can add hidden links in the content of your website, diverting visitors away to another place. They can access data, information and your most sensitive files. This, as well as being highly alarming, also means your systems are non-compliant and the new GDPR data protection rules could mean your business faces huge fines if caught in breach.

We could go on and on (and yes we have little bit) but we can’t stress enough how important security is. We can help if you think you could (or should) improve.

Are you still emailing sensitive information?

Monday, June 12th, 2017

For any professional managing information on behalf of clients, email is dead. It is not secure and highly susceptible to human error. How many times have you sent information to or received information from the wrong source? I am regularly wrongly emailed client documents by a highly intelligent, trusted professional simply because I have a very similar name to his client. It is completely understandable but it could have any number of repercussions.

A client portal is a cloud-based safe. The documents go in (added by you or your client), the recipient is notified and they are then retrieved. It is also subject to several layers of top-level security.

For the sake of your practice, your reputation and your clients’ trust, switch from email to a secure client portal before it is too late. We can help, advise and support a quick transition to a much safer and more professional way to communicate.

A quick guide to GDPR and what you should be doing about it

Wednesday, April 12th, 2017

What is the GDPR?

Firstly, the GDPR affects every business that holds personal information on anyone, be they employees, customers or suppliers. It is a rare business that does not hold a list of personal data of some kind, on or offline.

The General Data Protection Regulation (GDPR) is a legal directive from the European Union for the protection of such personal data. It seeks to address the inconsistent data protection laws currently existing throughout the EU’s member states. Despite Brexit, the UK is still bound by this new law, not only because the UK has chosen to (because it makes sense) but trading with countries who operate under GDPR will be compromised if we don’t uphold the same standards.

What’s the big deal?

Failure to comply with GDPR could mean you risk being fined up to 4% of your company’s global annual turnover. Not only could your business suffer financially but you could also damage your reputation and credibility – who wants to do business with an organisation that doesn’t prioritise its clients’ security?

So begins the 12 month countdown…

What should you be doing?

You must:

  • Keep a record of data operations and activities and consider if you have the required data processing agreements in place
  • Carry out privacy impact assessments (PIAs) on products and systems
  • If applicable to your organisation, designate a data protection officer
  • Review processes for the collection of personal data – do you ask permission? Many CRM systems encourage a dual confirmation (hence why you are asked to click a link via an email after registering with an organisation)
  • Be aware of your duty to notify the relevant supervisory authority of a data breach
  • Implement ‘privacy by design’ and ‘privacy by default’ in the design of new products and assess whether existing products meet GDPR standards

What else could help?

  • Educate your staff – and explain the implications
  • Set up internal systems for reporting a data breach
  • Make sure you extend your GDPR preparation to include any third parties who may have access to your data
  • Ensure you extend the policies to cover everything your store both offline and online
  • A really powerful solution that we recommend is to use a secure client portal and NEVER use email to distribute information of any kind. A secure portal like docSAFE means data doesn’t leave the portal but can be accessed by authorised people only

And if you don’t?

There is a two-tier fine system that will kick in from May 2018. Tier 1 means that if a serious data breach occurs, putting data at risk, you will be fined up to £17.25m or 4% of the previous year’s annual global turnover – whichever is the greatest. Tier 2 can lead to fines of up to £8.6m or 2%, whichever is greater.

How can we help?

Talk to us. We are experienced in identifying the areas of your business that are vulnerable and need addressing for GDPR purposes. Not only that but we know how to implement layers of security for your business that go beyond government legislation. We care about protecting your reputation and credibility, especially for those in the professional sector whose business relies on discretion, the handling of sensitive documents and client protection.

Take the next step, call us today
0121 794 0685