How a company deals with its own information is something we have all had to consider carefully – who has what type of access, what kind of security to put in place. These are all valid areas to explore thoroughly. Recently, while working on the IT infrastructure of a new client, it became apparent that a whole area of neglect had developed without the company in question even being aware of its existence. Many companies’ only real resource is the data they amass over time, and so they have to balance their need for security with the need to keep costs as low as possible. We’ve all seen hosting packages offered at those low low prices, so it’s not unusual to find a company’s various server applications spread over the face of the globe.
Compliancy concerns
The problem in this case was due to developments over the past few years – larger multi-nationals have all had to make sure they complied, but many smaller organisations seem not even to have considered their responsibilities in this area. From my experience, smaller companies often suffer from the amount of information out there, with no executive summaries for the decision makers, many an opportunity can be lost. While a law or change in business practices can also go unobserved.
The client in question handles large amount of data, but it wasn’t the amount of data, it was the type that raised a flag, and this still would have been fine except for the small matter of the location of the server hosting the data.
Many of you may not have considered the EU Directive on Data Privacy which came into force in 1998 – it applies to all data pertaining to EU citizens. If your company stores data on an EU citizen, no matter how insignificant in your opinion, it is necessary to make sure you are in compliance with it. This is especially important when we remember all those wonderfully cost-effective data hosting solutions across the Atlantic.
Self-regulation rules stateside
The United States relies on self-regulation and private organisations such as the Better Business Bureau for privacy protection which is ineffective at best. Europe has a very comprehensive set of protections for the privacy of its citizens, with that 1998 directive on Data Privacy it became illegal to export data to countries that do not have “adequate” privacy protection, this includes (you got it) the States.
In this particular case, the client handles a substantial amount of data concerning EU citizens, the database containing this data had been moved a few years ago to a hosted solution based on a server in a rack space somewhere in Texas. This was definitely a problem as the only way the current situation could be brought into compliance would have been to seek permission and wavier of rights from each and every EU citizen in that database, expensive and not a great way to enhance trust in your company. The alternative option was to move it to a similar hosting solution within the EU, or in-house. Due to the complexity and costs, real and implicit, of the former the decision was taken in this case to migrate the database services in house as a finer level of control and security were required after evaluating both the technological requirements and legal responsibilities.
Broader knowledge
It’s important to find a good source of advice on more then just the technical element when looking at your corporate IT infrastructure. Prevention after all according to your dentist is better then cure, every company out there should have an IT plan and set of policies which cover more then just the specifications and details of its servers. Any legal obligations and employee usage implications should be explored as ignorance is not an accepted defence. This used to be solely the preserve of larger companies but is swiftly becoming necessary for the smaller firm out there to sit up and take note, it’s absolutely necessary that an up to date document is kept of all aspects pertaining to your organisations IT, not doing so can lead to costly recovery and legal problems not just from non-compliance with a specific area of law as above, but also to complications when dealing with employee misconduct, or disaster recovery. It also makes it far less time consuming and therefore costly for you to out source to contractors, as up to date documentation of this type allows us to harvest all the necessary information we need to help us complete a job on time and in budget.
* Our guest columnist is a freelance network and security consultant. He works for several clients in the SME space and we do not disclose his identity for reasons of professional confidentiality.








Ltd