Over a single night, a former employee holding a senior role copies tens of thousands of files out of the company document repository. No alarm goes off: valid credentials, permissions in order, and the traffic of a user downloading documents the way he always has. A few weeks later he resigns, and he now works for a direct competitor. It is the case that explains better than any other why corporate document protection has become a concrete line in the security plan: the reconstruction came from the centralised logs and the evidence ended up in court, but the trail documented what happened without preventing it.
In the projects we run the episode almost always takes the same shape: a resignation, a notice period, an account still active and a shared archive nobody ever segmented. Controls built around the infrastructure recognise anomalies at the door, while legitimate actions taken by people already inside pass without friction. The file leaves intact and readable.
The perimeter is well guarded, the documents crossing it far less so
In mid-sized and large organisations the defensive layers are covered with discipline: firewalls and network segmentation, protection and detection on endpoints, multi-factor authentication on identities, continuous monitoring that correlates events. The design is effective against the external attacker.
Security spending, though, is shifting from the infrastructure layers towards the data itself, and that is the reading SealPath brings to its partners: documents move around far more than any perimeter architecture was ever designed to handle. A contract is created in a Microsoft 365 tenant, shared with an external firm, downloaded onto a personal laptop, attached to a message, saved on a departmental NAS nobody has audited in years.
Where data loss prevention reaches its limit
An attachment gets blocked, a copy to a USB stick is stopped, an unusual upload is flagged. What they guard is the crossing point rather than the document itself. When the sharing is authorised, and in most cases it is, the defence ends there. What remains uncovered is the hardest class of events to intercept, the one where the person taking the data holds every right to do so.
The regulatory framing is not new. Article 32 of the General Data Protection Regulation requires technical measures appropriate to the risk and names encryption among them. The limits of application, however, surface late: encrypting the disk or the channel protects data inside the infrastructure, while the document shared with the outside world remains uncovered. Anyone who has worked through the technical obligations of the GDPR knows the distance between a measure that is declared and one that can be demonstrated.
How does corporate document protection work once the file leaves the company?
The protection stays written inside the file. Encryption and permissions travel with the document, are verified at every opening, and can be revoked remotely at any time, wherever the file happens to be.
The technical category is E-DRM, Enterprise Digital Rights Management, also referred to as IRM, Information Rights Management. Aesir has selected SealPath, a platform that applies encryption based on Microsoft RMS to the individual document and attaches a granular policy to it: who may view, who may edit, who may copy the content, who may print. Format is not a constraint. Office files, PDFs, images and CAD design files are all covered, and design files are usually the ones that fall outside the reach of general purpose tools.
The mechanism separates holding the file from holding the right to read it, and everything else follows from that separation. Someone who receives a protected document without belonging to the policy opens unreadable content. Anyone removed from the policy loses the right of access even if the file has been on a personal disk for weeks, because authorisation is checked at every opening. Applied to the opening case, the tens of thousands of files copied during the notice period would have become unusable the moment access was revoked.
What document security shows in real time
On the operational side the administrator sees the trail in real time: which document was opened, by whom, from which workstation, and above all which attempts were blocked. A denied attempt appears while the episode is still unfolding, which means while the company can still act. The gestures no encryption intercepts remain, the photograph of the screen and the manual transcription: watermarks carrying the identity of whoever opened the document exist for exactly that reason, because they make the shot attributable.
Two ways to apply the policy, with different organisational consequences
Corporate document protection is applied in one of two ways, and the choice bears on the organisation more than on the technology. One is manual: the author applies the policy, defines the group of authorised users and assigns permissions. It holds on small, critical sets, where whoever produces the file knows what it is worth: contracts, expert reports, technical drawings covering patented designs, medical records.
The other acts on the container. The policy is applied to the repository, whether a SharePoint library, a cloud drive, a file server or a network folder, and everything placed inside is protected from the outset. Once volumes grow this is the workable choice, because it does not depend on the habits of somebody saving a file in a hurry on a Friday afternoon.
Native integration with Microsoft 365
In most companies the Microsoft 365 tenant is where documents are created, circulated and kept, so that is where protection has to fit without friction. SealPath integrates natively with the Microsoft ecosystem: encryption is built on Microsoft RMS, Office applications open protected files with no additional software, and connectors towards SharePoint Online, OneDrive and Exchange apply policies directly to libraries, synchronised folders and outgoing attachments. Identities remain the ones already held in the tenant, so existing groups become policy groups and no second directory has to be kept in step.
How the initial scope is defined
The initial scope is set during analysis and does not require mapping the entire historical archive. The starting point is the repositories feeding the highest value processes, typically projects, quotations, design and personnel: who accesses them today, and with which permissions, is verified, and that subset is protected.
| Mode | Where it applies | When it suits |
|---|---|---|
| Manual protection per document | On the single file, applied by the author | Small, high value sets: contracts, expert reports, patented drawings |
| Automatic protection on the repository | On SharePoint libraries, cloud drives, file servers, network folders | Shared archives with high volumes and many hands writing into them |
| Protection on email attachments | In the mail client, at the moment of sending | Recurring exchanges with suppliers, professional firms, external collaborators |
| Protection driven by classification | Sensitivity labels that trigger the policy | Organisations already running a document classification model |
What changes when data security is delivered as a managed service
The model Aesir Srl offers its clients transfers the operational burden of management, and for a finance director the difference shows up on three lines. Internal effort, because policies, configurations and alerts stay with whoever delivers the service and the client receives a periodic report instead of staffing a console. Accountability, which becomes contractual and measurable against written service levels. The shape of the cost, which moves from an upfront investment in licences and infrastructure to a fee sized on the users covered.
Two deployment models for corporate document protection
Technically, two deployments are possible. One places the platform on the vendor cloud. The other installs it on the infrastructure of the managed services provider, who then delivers it as private cloud, keeping protection data under the same governance as the rest of the services. The platforms we select process data in European data centres, with certifications in the ISO/IEC 27001 family and requirements aligned with NIS2, the same standards applied to our own infrastructure: our Tier IV data centres, with replication, remain the internal infrastructural benchmark.
Document events are exported through SDK and REST APIs into the SIEM, and land on the same timeline as network and endpoint events. A blocked opening attempt in the middle of the night is read by the SOC alongside an unexpected VPN login from the same account, and the correlation raises an alert neither source would have produced on its own. Document management, monitoring and managed security converge in the same operating perimeter that also underpins business continuity management. Integrations towards the document management system already in use are built on the APIs of both platforms and confirmed during analysis.
Seven checks that head off adoption problems
In corporate document protection projects the difficulties appear in the first weeks of operation, on points the analysis could have closed earlier.
- Map the repositories where sensitive documents actually sit, including whatever lies outside the main tenant: departmental NAS units, legacy folders, personal devices used for work.
- Decide which document categories justify a policy. Protecting everything and protecting nothing produce the same practical effect on the organisation.
- Check coverage across the formats in use, with attention to design files, which weigh heavily in manufacturing and plant engineering.
- Name who administers policies and who answers alerts, before the platform goes live rather than after the first overnight alarm.
- Test protected files offline and on the workstations of external collaborators.
- Require document events to flow into the correlation system already in operation, instead of adding one more isolated console.
- Write the revocation procedure for when an employment relationship ends, with a named owner and a maximum execution time.
The questions that come from the board
Does corporate document protection replace backup?
The two measures answer distinct risks and coexist in the same plan. Backup restores data after a loss, a human error or a ransomware attack. Protection applied to the document governs who may read it once the file has left the infrastructure. Sizing happens together.
What happens to already protected files if company requirements change?
E-DRM platforms provide administrators with a bulk protection removal procedure. It should be defined during analysis, documented in the contract and tested with the rest of the project: a proven procedure is worth far more than a feature listed in a datasheet.
Do users have to change the way they work?
Protected documents open in the applications already in use: the Office suite, the PDF reader, the design software. An authorised user opens the file exactly as before, offline too where the policy allows it. The difference shows up for those who are not authorised, and in the audit trail the administrator finally has available.
Let’s talk
On corporate document protection the decision comes down to a check any management team can run in half an hour: what happens to a valuable document a minute after it leaves the perimeter. If the answer stops at the audit trail, the company can only reconstruct. If the answer is the policy written inside the file, the company governs what happens outside as well.
If you would like to explore the subject or assess the situation in your own company, you can fill in the form at the bottom of this page or write to support@aesir-tech.it: we will arrange a free consultation and start from your numbers.