Guarding Company Secrets On The Road
Corporations spend millions of dollars annually to promote their products and services at trade shows, conventions, corporate meetings and events, and customer-focused events. But they also lose millions of dollars through the theft of proprietary information and property at these events.
In the American Society for Industrial Security's recent "Trends In Intellectual Property Loss Survey," this was found to be an area of concern to the meeting, trade show and convention industry. "Competitive intelligence professionals consider meetings and conventions one of the lucrative sources of proprietary information," the survey said. "Information flows more freely during trade shows than perhaps at any other time."
Safeware Insurance Agency reported that 208,000 laptop computers valued at $639,742,000 were reported stolen in 1995. The impact of a computer loss is more than monetary. In addition to the original equipment purchase price and the replacement costs, there is the loss of information that is on the computer, which in most cases is not replaceable and of far greater value to competitors if compromised.
Such risks can be addressed by proper planning and on-site management. To limit exposure to inadvertent loss or the deliberate theft of information, the following guidelines are recommended.
Use non-disclosure agreements with all external service providers. Ensure that external services safeguard your proprietary materials (hard copy, soft copy, video, etc.) to your standards at all times. Internally, establish an effective proprietary information protection program throughout the company. Advise attendees in advance and remind them on site of their information security responsibilities. Caution attendees to safeguard proprietary handouts and their notes during meetings, after hours and while traveling.
Limit the amount of sensitive information carried to only that which is absolutely necessary, and hand-carry it.
Conduct technical surveillance counter-measure inspections of meeting rooms and, as appropriate, executives' hotel rooms, prior to any sensitive or critical stages of the meeting.
Monitor meeting room access and secure all points of access, including back-of-the-house entrances. Use name badges or other means to identify authorized participants, including facility staff and external resources. Immediately after use, inspect meeting rooms to retrieve any sensitive materials left behind.
Use high-quality security services and written security duties to secure the meeting rooms and A/V equipment. Avoid using wireless microphones whenever possible.
Secure computer hardware with security cables and safeguard software with passwords, file encryption and anti-virus programs. Ensure that all company information is removed from the hard drives of rented computers.
Provide secured storage with proprietary locks for all sensitive information and have a crosscut shredder on site to destroy proprietary materials.
Avoid working on or talking about sensitive information in public areas (restaurants, rest rooms, airplanes). Refrain from using laptop computers in these areas as well.
Avoid the use of conference centers for proprietary information reproduction and hotel fax facilities for sending and receiving sensitive information. Instead, rent a copy machine and use authorized personnel to reproduce the information, or bring a company fax machine and secure it in a room with exclusive access by authorized personnel. Ensure that fax, telephone, cellular, and/or video communications between off-site meetings and other locations are properly safeguarded, which may require encrypted communications.
By implementing these and other appropriate security measures, those responsible for security can add to the success of an event where proprietary information and/or property needs to be protected.
<I>Richard P. Werth is president of R.P. Werth & Associates Inc., a Franklin, Tenn.-based international firm that specializes in security</I> <I>and contingency planning for meetings and</I> <I>travel.