This Blog has Moved!

This blog is moving to


Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label Data Loss Prevention. Show all posts
Showing posts with label Data Loss Prevention. Show all posts

Monitoring for Leaked Company Documents through Google Alerts

This article is part of a series on using Google Alerts to protect you, your family, and your company through early notification of data breaches and leaks.

Previous Articles:

Misuse of Your Personal Information and Google Alerts
Monitoring for New Zero Day Exploits through Google Alerts


If you're following good security practices, all of your internal company documents are properly labeled with important labels such as "Company Proprietary", "Company Sensitive" or "Do Not Distribute".

In fact your company has probably established a standardized header for use on all sensitive documents.

So, when's the last time you performed a Google search for this header?
When's the last time you searched to see what documents are being exposed to the web hosted on your domain?

The results might surprise you.

The Google Hacking Database has some excellent information on how to use Google to find sensitive files.  It's very easy to use some of the search queries there, add your company name or standard header, and see what happens.

In fact, even if you find no results, it would be a great idea to setup Google Alerts to monitor for documents posted (accidentally or otherwise) which appear to be internal company documents.

Here's an example, which should produce results for (hopefully!) intentionally posted documents:

site:blogspot.com filetype:doc OR filetype:xls OR filetype:pdf
The above query will return common office documents which are hosted on blogspot.com, or any subdomains.  Replace blogspot.com with your main domain, and see what results you find.

Beware: Many hackers already know these tricks, and will use them to perform reconnaissance on your company before initiating an attack.  Even the most mundane documents, such as a list of email addresses and phone numbers, could be used to assist in launching a spear phishing (targeted phishing) attack against your company.

Insider Threats and Data Loss Prevention

One of the biggest challenges many organizations face is how to deal with the insider threat.

A common means of attempting to control insider threats is through Data Loss Prevention software.

Unfortunately, there is no one clearly superior method for implementing Data Loss Prevention.

I'm happy to offer to my readers a free research report on different Data Loss Prevention techniques from the Aberdeen Group.

The ideal approach to security and compliance is like the ideal referee: one that makes good calls and enforces the rules regarding safety and fair play, but generally doesn't get in the way of the people playing the game. In its fifth annual study on best practices in data loss prevention (DLP), Aberdeen analyzed and compared the results from more than 600 organizations which have adopted one of four distinct approaches to the operational use of DLP technologies. The best approach, in terms of balancing enterprise risk and reward, is like the children's fairy tale of Goldilocks and the Three Bears: the bed we choose to lie in should be neither too soft (Do Nothing, Monitor / Notify), nor too hard (Stop / Go), but just right (Adapt / Protect).

Access Your Complimentary Copy Today. This $399 Value Offer Expires 01/09/2012