Home›Insights›Articles›How to protect an energy company's critical files in the cloud
Blog · Automation · Energy & utilities
How to protect an energy company's critical files in the cloud
Thousands of users, millions of files and customer data the law requires you to protect. What we learned moving the critical information of a leading natural gas distributor in Colombia to the cloud.
Why an energy company's information is an asset to protect
In Colombia, Statutory Law 1581 of 2012 governs the processing of personal data. One of its principles is security: information must be handled with the technical, human and administrative measures needed to prevent tampering, loss, or unauthorized or fraudulent access, consultation or use. The Superintendency of Industry and Commerce (SIC) enforces compliance.
For a distributor with millions of customers, that has very concrete implications. On top of the legal requirements come the risks any organization faces when thousands of people work with files every day:
- Scattered information. When files are everywhere, it's hard to know what exists, who has it and how well protected it is.
- Email as a transfer channel. Attachments travel unencrypted, can't be revoked and hit size limits that push people toward unsanctioned services.
- Untraceable devices. A lost or compromised PC can hold critical information without anyone knowing.
- Siloed tools. Different solutions in each department multiply costs and complicate audits.
Transfer, collaboration and secure email on one platform
GoAnywhere MFT is Fortra's managed file transfer platform. Beyond automating and encrypting file exchange between systems, people and partners, it includes collaboration modules that handle users' day-to-day needs. This project combined three pieces:
- GoAnywhere MFT in the cloud, on containers. GoAnywhere can be deployed on many platforms, including Docker and the major cloud providers. A container-based deployment made for a fast rollout and an environment that's easier to scale and maintain.
- GoDrive. Enterprise file sync and sharing (EFSS) for employees and partners, with AES-256 encryption of files synced to devices, folder-level permissions, versioning, file recovery and a mobile app.
- Secure Mail. Encrypted files and messages sent straight from email, including an Outlook add-in, with unique HTTPS links, expiration dates, download limits and the ability to revoke access.
The solution was integrated with the company's Active Directory and its mail service (SMTP), and complemented with traceability for employee PCs.
Protecting information isn't about putting more locks on every file. It's about giving people a secure, simple way to work with them.
Five lessons for moving critical information to the cloud
1. Centralize before you encrypt
Encrypting scattered files just moves the problem around. The first step is deciding where critical information should live and offering a single, secure place to work with it. From there, encryption and traceability can be applied consistently.
2. Integrate with the identity you already have
If users have to remember one more password, adoption suffers. Active Directory integration lets permissions follow the company's real structure and makes onboarding and offboarding take effect immediately.
3. Replace the attachment, not the email
Email will remain most people's favorite channel. Rather than fight that habit, offer an alternative from the same mail client: encrypted packages with no practical size limit and control over who downloads and until when.
4. Don't forget the employee's device
Critical information doesn't only live on servers. Securing employee PCs and having traceability over them closes one of the most common gaps in any organization.
5. Deploy on containers to gain speed
A container-based cloud platform shortens implementation time, simplifies upgrades and lets you grow without redesigning infrastructure. For many companies it also makes the solution affordable across the whole organization, not just one department.
The result: centralized, encrypted and traceable information
Today the company has more than 1,000 employee PCs secured, more than 5 million files encrypted serving more than 5,000 users and traceability across 100% of its devices. The cloud implementation was fast, critical information is centralized and the platform runs integrated with Active Directory and corporate email.
For a company that provides an essential service to millions of households and businesses, that means something very concrete: knowing where its information is, who is accessing it, and being able to prove it when asked.
Where to start
If sensitive files at your organization still travel as attachments, live on PC hard drives or get shared through services IT doesn't control, a good first step is an inventory of how critical information moves today. At Redsis we combine more than 25 years of mission-critical platform experience with Fortra automation and integration solutions such as GoAnywhere MFT and JAMS.
Read the full story
See how a leading natural gas distributor in Colombia protected its critical data in the cloud with GoAnywhere MFT.