Practicing (Annoying) Better Security

At Redgate Software, we’ve been looking to “level up” our internal security game. While we have had very good security during the 16 years I’ve been there, there have been a few security issues with our products. The speed at which we address things, as well as the communications with customers, has impressed me.

We’ve had almost no problems with our internal systems, unlike a few other places I’ve worked. We haven’t had the phishing/virus/breach/ransomware issues that I’ve seen at other employers or heard about from friends. I do think our IT staff is diligent and careful, as well as forward-thinking. It also helps that we’ve had a relatively small employee staff that worked in physical offices for most of our existence.

Recently, we’ve been on a security push to tighten up the way we deal with systems. As we grow our staff, and as we add more offices, there is a recognition that our attack surface area is growing. We also find more and more people using non-Redgate-owned devices. This year we’ve had a series of policies rolled out that we are supposed to adhere to in order to ensure strong security, as well as compliance with data privacy rules such as the GDPR.

One of these is a bring-your-own-device (BYOD) policy. For years I’ve used my personal mobile phone for Redgate, with a few settings enabled to allow a remote wipe if I lose it. However, I’ve also had a personal desktop that I use for daily work in my home office. I’ve never enabled a lock on this as my wife occasionally uses it to get a picture or other document. Or send me something I forgot to sync in the cloud.

Part of our new policy is that I need to enable a lock on my desktop, as there is privileged Redgate information on there. Not much Redgate data, but the machine does connect to our business OneDrive and SharePoint systems. This lock should be a 2-minute timeout, which means that I come back to my desktop after coffee, laundry, or something else to find it locked. After years of always locking my desktop in corporate offices, I somehow find this more annoying. Especially as I’ve gotten used to rarely typing my 15-character password. I mess this up regularly and have to (more slowly) re-type my password a few times.

I know this is better security, and I am always conscious of locking my laptop in our various offices when I go in. However, I find it annoying at home. Especially when I pop in away from work to look up something on the Internet. I keep telling myself this is good security, and good for both Redgate and our customers. I’m still annoyed by the change, but I know it’s for the best. Like many who work in organizations, I’ve been lazy about some security aspects for years, and the change is a disruption. I’m sure some of you feel the same way about the rules and protocols that your employers have implemented.

You’re not alone in desiring a more convenient workplace, but security is a series of overlapping measures that work together to protect data. Practicing and adhering to good security is a lot like a daily backup. Most of the time it’s something never need, but when there’s an issue you’ll be glad you followed the process that day.

Steve Jones

Listen to the podcast at Libsyn, Spotify, or iTunes.

Unknown's avatar

About way0utwest

Editor, SQLServerCentral
This entry was posted in Editorial and tagged . Bookmark the permalink.

7 Responses to Practicing (Annoying) Better Security

  1. And here I thought I was the odd one for having a 14 character password.

    “2 minutes auto lockout” does that take into account cases where you could simply be reading and not move teh mouse or touch the keyboard for 2 minutes? If no then yeah I’d be annoyed by that too and like you I ALWAYS lock my workstation even just to step to the next office because I’m just that way.

    My security rules:
    1) Never leave my system unlocked
    2) Never select REMEBER for password
    3) Never share my [work] password w/anyone even my wife 🙂

    Like

  2. way0utwest's avatar way0utwest says:

    I haven’t had issues when I’m working. Likely I think I must be moving the mouse, even when reading. I think it also gives a few seconds when it blanks where you can move the mouse or hit a key to keep it going before lock.

    I have previously always locked when I’m not at home, but at home, no. My wife has copies of my password files, because, well, I’m getting old. There might be a reason she has to get to something.

    Like

  3. Brian K's avatar Brian K says:

    There’s a MS Store app called Move Mouse that is super handy for that sort of thing. I use it mostly if I’m running long scripts on a shared screen with people watching… keeps it from locking during bathroom breaks.

    Like

Comments are closed.