A Fortify 24x7 brand. Grown up security platforms, sold the way software used to be sold.Client sign inMail an engineer
Cyb3rs3cur1ty
Module 05 // Data protection

Nobody protects a file when nobody knows where it lives.

Every company keeps sensitive material in places that were never the plan. A spreadsheet full of card numbers left over from an event in 2019. Passport scans in a shared folder. Client records copied to a desktop for one urgent job and never removed afterwards. Actifile goes looking, puts a number on the risk, then controls what may happen next.

ActifileDiscoveryEncryption
2 lines / discovery first, enforcement second / counted per device
Lines here2
EngineActifile
Counted byDevice
OrderFind it, then govern it

Discovery is the unglamorous part everything else needs

A policy about handling sensitive data is worth very little while nobody can say which machines are holding any. The scan looks across endpoints and file shares for recognisable shapes: card numbers, national identifiers, medical records, bank details, contracts, and whichever pattern matters in your particular trade. What comes back is usually a surprise, and the surprise is normally sitting on somebody's laptop.

Then it becomes arithmetic. Each device gets a figure based on what it holds and how exposed that is, which turns an unbounded worry into a queue of machines ordered by how much trouble each represents. Cleanup with an order to it actually gets done. Cleanup as a general aspiration does not.

An unbounded worry becomes a queue, and a queue gets worked.

Enforcement, once you know what you are enforcing on

The second line acts on whatever the first line turned up. Files matching the patterns you care about can be encrypted where they sit, so a copied folder is useless to whoever copied it. Channel rules govern the routes data leaves by: removable drives, personal cloud storage, and whatever else you decide should not be a normal exit for client records.

This is not a promise to make exfiltration impossible. Somebody determined, with legitimate access and a phone camera, is not a problem software solves. It is a promise to remove the casual paths, and the casual paths are where the overwhelming majority of accidental loss happens.

Lines on this module

Specifications and rates

Every rate below arrives live from billing. Anything you pick up drops into the inventory panel and sits there quietly.

Fortify-DLP-ClassifySpec

Sensitive Data Discovery

Actifile scanning, classifying and scoring exposure

Finds the sensitive material sitting across enrolled devices and shares, sorts it by type, and produces a risk figure per machine so that remediation has an order to it.

  • Scans endpoints and file shares for regulated and proprietary patterns.
  • Sorts whatever it finds by category and tallies the volume of each.
  • Scores exposure per device, turning a pile of findings into an ordered queue.
EngineActifile
SweepsEndpoints and connected file shares
Hunts forCard, identity, health, financial and custom patterns
You getAn inventory of sensitive files and a risk figure per device
Counted byDevice, each month
Loadingper device
billed each month, in advance
QTY
Fortify-DLP-EnforceSpec

Encryption and Channel Control

Actifile encryption, plus control over the exit routes

The enforcement half. Sensitive files are encrypted where they sit, and the routes data can leave by are governed instead of being left open because nobody ever closed them.

  • Transparent encryption of matching files, so a stolen copy will not open.
  • Rules covering removable media, personal cloud storage and similar routes.
  • An audit trail of what moved, who moved it, and where it went.
EngineActifile
NeedsThe discovery line on the same device
LockingApplied in place to files matching your rules
Exit routesRemovable media, cloud storage and similar exit routes
Paper trailAn audit trail of movement events
Counted byDevice, each month
Loadingper device
billed each month, in advance
QTY
Honest scope

What sits in the box, and what does not

Data protection attracts more marketing nonsense than anything else we sell, so the boundary here is worth reading twice.

IN THE BOX

  • A scan of enrolled devices and shares for the sensitive patterns that matter in your particular trade.
  • A risk figure per machine so cleanup can be ordered rather than guessed at.
  • Encryption of matching files in place, which makes a copied folder useless on its own.
  • Channel rules covering removable drives, personal cloud storage and similar routes.
  • A record of movement so a question about what left can be answered with evidence.

NOT IN THE BOX

  • A guarantee against a determined insider. Legitimate access plus a phone camera is not a software problem, and pretending otherwise would be dishonest.
  • Legal advice about your obligations. We can show you where regulated data sits. What you must then do about it is a question for counsel.
  • Systems we cannot reach. Data inside a hosted application we have no connection to falls outside the scan.
  • Deleting things on your behalf. Findings arrive with recommendations. Removing records is your decision and frequently a legal one.
  • Backup. Encrypting a file is not the same as keeping a second copy of it. That is the backup module.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - Cyb3rs3cur1ty is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.