Today’s fast-paced business world sees companies shifting strategies quickly – expanding into new markets, merging with other companies, spinning off subdivisions and adjusting headcounts as needed. In turn, employees pivot from one employer to another, mindful of their own career paths and opportunities to advance.
But be aware: Those departing employees represent potential security landmines. They may have left your company’s data vulnerable to access from unwanted parties through the many SaaS applications the employees used in their work. The potential for harm is large and not easily managed. Here’s why:
The limitations of traditional methods
You might assume that once the employee leaves, all you need to do is delete them from an identity provider (IDP) such as Okta. While that’s a good starting point, it still leaves exposed all the assets the employee may have shared up until that point. Anything shared externally and publicly – as well as to personal accounts – remains available to outsiders.
There’s also the problem of what happens before the profiles are deleted through the IDP. Some employees may plan on scurrying away with corporate information that they think might be of value to their future employer.
The huge amount of unmanageable data many employees leave behind
More often than not, employees who are leaving don’t take any actions to plug up the access points they’ve created during their time with your company. This leaves your data exposed as it has been shared with:
All that data remains shared even when the user has been deleted through the IDP. Unbeknownst to you, the employees could have used their private accounts to access your data and continue to access or exfiltrate it long after they are gone. If strongly motivated, they can also pass that access to other interested parties.
Addressing the threats systematically and holistically
In short, your company is left with a huge amount of unmanageable data access that poses a significant risk and potential for a breach. Security vendors and SaaS applications don’t provide an easy way to remove external and public sharing with bulk actions guided by business context (departing employees, terminated vendors, etc.) Security teams are then left with an unwieldy amount of manual work to carefully review each action before they decide who should be denied access for each SaaS app.
What’s more, there are no effective ways to monitor data access in the apps and remediate as needed. Those soon-to-be-ex-employees who are stealing all your trade secrets or customer databases can go about their merry way without anyone getting an alert that something is amiss.
That’s why you need a centralized method of SaaS data-access management, as offered by DoControl. Data-usage patterns with employees can compare how someone has historically interacted with various SaaS apps in the past against current practices. Consequently, employees trying to download all your Salesforce data onto a thumb drive are stopped before they exceed their normal usage. You get full asset management to perform security investigations into employees that are leaving to be alerted to any suspicious activity and take countermeasures as needed.
Once an employee has left, you can go well beyond just shutting off that person’s access. You can remove all access to assets that have been shared by that employee -- using context-based action options -- through our pre-configured workflows.
Employee turnover is likely to be an ongoing issue for most companies, and it’s one of many issues that we designed DoControl to tackle. To learn more about how we can help your organization stay secure from SaaS data losses, get in touch with us.
This stat comes from the industry report we published earlier this year: The Immense Risk of Unmanaged SaaS Data Access. It’s a great read. We recommend you check it out.
DoControl is named as a Representative Vendor in 2022 Gartner® Market Guide for Insider Risk Management Solutions. Gartner recently published the market guide which assists in understanding and implementing a comprehensive insider risk management program. Gartner describes how “the increase in a hybrid or remote workforce, compounded with additional vendor integration, has prioritized insider risk management as a focus area for security and risk management leaders.”
In today’s hybrid work environment, SaaS security has never been more important. Understanding your existing risks is a critical step to choosing the right security tool, but few SaaS apps provide the visibility necessary to perform a proper assessment.