फ़ाइल ट्रांसफर में डेटा ब्रीच रोकें: सिक्योरिटी चेकलिस्ट
इस सिक्योरिटी चेकलिस्ट से डेटा ब्रीच रोकें। एन्क्रिप्शन, एक्सेस कंट्रोल और पॉलिसी से डेटा सुरक्षित रखें।
फ़ाइल ट्रांसफर के दौरान डेटा ब्रीच रोकने के लिए पाँच लेयर पर नियंत्रण चाहिए: transit में encryption (TLS 1.3) और rest में (client-side AES-256-GCM), प्रति रिसीवर authenticated access, tamper-evident store में ऑडिट लॉगिंग, automatic expiration के साथ short retention, और anomaly detection के कुछ मिनटों के भीतर activate होने वाली incident response procedures। 2023 का MOVEit Transfer breach 2,600+ संगठनों के डेटा तक पहुँचा क्योंकि एक managed file transfer product में single zero-day ने उन customers के लिए layers 1-3 को bypass कर दिया जो layer 5 monitor नहीं कर रहे थे। Checklist-आधारित तरीका gaps पकड़ता है। DPDP Act 2023 के तहत भारतीय संस्थाओं पर भी personal data breaches से बचाव के लिए "reasonable security safeguards" की ज़िम्मेदारी है। यहाँ concrete implementation notes के साथ पूरी list है।
फ़ाइल ट्रांसफर breach hotspot क्यों है
फ़ाइल ट्रांसफर बाहरी नेटवर्क, कई trust boundaries, और अक्सर unstructured content के intersection पर है जिसे DLP (data loss prevention) टूल्स आसानी से स्कैन नहीं कर सकते। 2023 Verizon DBIR ने 74% breaches को human element से जोड़ा, और misdirected file sharing सबसे आम triggers में से एक है — phishing के साथ-साथ। Accellion FTA (2021), Progress MOVEit (2023), और Cleo Harmony (2024) — सभी enterprise file transfer products बड़े पैमाने पर breach हुए, हर incident में लाखों records expose हुए।
सबक: file transfer tools high-value targets हैं क्योंकि वे organizations के बीच business-critical डेटा ले जाते हैं। इन्हें hardening करना optional नहीं है।
एन्क्रिप्शन चेकलिस्ट
- [ ] सभी HTTPS endpoints पर TLS 1.3,
max-age=31536000के साथ HSTS enabled - [ ] फ़ाइल contents के लिए AES-256-GCM, AES-CBC नहीं (padding oracle attacks के प्रति susceptible)
- [ ] PBKDF2-SHA-256 से 600,000+ iterations या Argon2id (OWASP 2023) के ज़रिए keys derived
- [ ] Confidential या उससे ऊपर classified किसी भी चीज़ के लिए client-side encryption
- [ ] दूसरी layer के रूप में server-side encryption (AWS KMS, GCP KMS, या Azure Key Vault के साथ envelope encryption)
- [ ] सभी TLS connections पर Perfect forward secrecy (ECDHE cipher suites)
- [ ] Enterprise clients के लिए जहाँ feasible हो, certificate pinning
अगर कोई transfer service primitives का नाम लिए बिना "military-grade encryption" advertise करे, तो specifics माँगें। Vague claims का आमतौर पर मतलब है सिर्फ server-side AES-128।
एक्सेस कंट्रोल चेकलिस्ट
- [ ] हर share link को लिंक से परे authentication चाहिए (password, email verification, SSO)
- [ ] बाहरी रिसीवर के लिए single-use links preferred
- [ ] हर लिंक पर expiration, default 72 घंटे, maximum 30 दिन
- [ ] जहाँ meaningful हो download count caps (जैसे, अधिकतम 1 या 5 downloads)
- [ ] Fixed partner ranges के साथ B2B exchanges के लिए IP allowlisting
- [ ] High-sensitivity दस्तावेज़ों के लिए watermarking (.pdf with per-recipient stamps)
- [ ] Automated server-to-server transfers के लिए mTLS
एक naked share link bearer token है: URL वाला कोई भी व्यक्ति पूरी access पाता है। Bearer tokens ईमेल forwards, chat channels, browser histories, और CDN access logs में leak होते हैं।
शेयर करने से पहले डेटा क्लासिफिकेशन
हर फ़ाइल को एक जैसा treatment नहीं चाहिए। अधिकांश organizations के लिए three-tier scheme काम करती है:
- Public: press releases, marketing collateral; transport-only encryption ठीक है
- Confidential: customer data, financial reports, HR records; client-side AES-256-GCM plus access controls
- Restricted: trade secrets, unpatched vulnerability details, M&A materials; client-side encryption plus authenticated access plus watermarking plus 24-48 घंटे expiration
Automated classification मदद करती है। Microsoft Purview, Google Drive DLP, और Forcepoint DLP uploads को PII, PCI-DSS cardholder data, या PHI के लिए स्कैन करते हैं और policy के आधार पर block या redirect करते हैं। छोटी teams के लिए, file naming convention ([CONF], [RESTRICTED]) plus trained team पर्याप्त है।
Human Factor Controls
Breach data लगातार दिखाता है कि humans entry point हैं। इसे address करने वाले controls:
- Phishing-resistant authentication (FIDO2 hardware keys या passkeys, SMS नहीं)
- Recipient verification prompts: "भेजने से पहले recipient email confirm करें"
- UI में external recipient flags ताकि senders जानें कब फ़ाइल organization से बाहर जा रही है
- Recall windows: send के 5-10 मिनट बाद जहाँ sender delivery cancel कर सके
- Phishing simulations के साथ हर 6 महीने में mandatory training
Google Workspace के Drive shares पर "External" warnings ने internal Google research में accidental external sharing 23% घटाई। छोटे UX nudges मायने रखते हैं।
ऑडिट लॉगिंग और मॉनिटरिंग
- [ ] सभी upload, download, link creation, और access events logged
- [ ] 5 मिनट के भीतर SIEM (Splunk, Elastic, Sentinel, Datadog) को logs भेजे गए
- [ ] Regulatory requirements के अनुसार 1-7 साल log retention (PCI-DSS: minimum 1 साल, HIPAA: 6 साल, GDPR: case-dependent)
- [ ] Anomaly detection: unusual download volumes, off-hours access, geographic outliers
- [ ] Defined SLA (15 मिनट acknowledgment) के साथ on-call rotation को alerts
MOVEit attackers ने अधिकांश victim organizations में हफ्तों तक detect हुए बिना data exfiltrate किया। Real-time anomaly detection (download volume spikes, new IP ranges, unusual user agents) dwell time काफी कम कर देता।
रिटेंशन और डिलीशन कंट्रोल
हर दिन फ़ाइल सर्वर पर रहती है, वह एक दिन है जब वह चोरी हो सकती है। Short retention single highest-leverage control है:
- Default retention: अधिकांश file transfers के लिए 7 दिन
- Maximum retention: 30 दिन, extensions के लिए justification ज़रूरी
- Expiration पर cryptographic deletion (keys overwrite, सिर्फ payloads नहीं)
- रिसीवर को expiration से पहले notifications ताकि वे समय पर download कर सकें
- Regulated windows के भीतर logs और backups से expired entries का automatic purge
HexaTransfer रिटेंशन को 7 दिनों पर कैप करता है और expiration पर encrypted payloads plus key material delete करता है। Dropbox Transfer और WeTransfer retention settings offer करते हैं; सबसे छोटी practical window इस्तेमाल करें।
Incident Response Procedures
जब breach suspected हो:
- [ ] Detection के 15 मिनट के भीतर affected share links revoke करें
- [ ] Suspect activity से जुड़े किसी भी user के credentials rotate करें
- [ ] Logs preserve करें (write-once copies, attacker को cleanup के लिए उन्हें erase न करने दें)
- [ ] 1 घंटे के भीतर legal और privacy teams को notify करें
- [ ] Timeline के अनुसार regulatory notifications file करें: GDPR Article 33 (supervisory authority को 72 घंटे), HIPAA Breach Notification Rule (HHS को 60 दिन), state breach laws (अलग-अलग, अक्सर 30-60 दिन)
- [ ] अगर exposure बड़ा या unclear हो तो forensic response engage करें (Mandiant, CrowdStrike, Kroll)
Playbook को कम से कम सालाना tabletop exercises में चलाएं। IBM के Cost of a Data Breach Report के अनुसार जिन teams ने practice किया है वे 2-3x तेज़ respond करती हैं।
Vendor Due Diligence
- [ ] SOC 2 Type II report reviewed, सिर्फ requested नहीं
- [ ] ISO 27001 certification current
- [ ] पिछले 12 महीनों की pen test reports
- [ ] Sub-processor list reviewed (क्या आपका vendor डेटा unknown third parties को भेजता है?)
- [ ] GDPR या अन्य jurisdiction rules लागू हों तो data residency controls available
- [ ] Published primitives: specific algorithms, key sizes, iteration counts
- [ ] Contract में breach notification SLA (आमतौर पर 24-72 घंटे)
Vendors से उनका खुद का incident history पूछें। जो vendor breach हुआ है और अच्छी तरह respond किया है, वह अक्सर उस vendor से बेहतर bet है जिसके कोई public incidents नहीं हैं और vague जवाब हैं।
Checklist को व्यवहार में लाना
सभी 40+ items एक साथ deploy करने की कोशिश न करें। Prioritize करें: पहले encryption और access control, दूसरे logging और monitoring, तीसरे retention और classification, आखिरी incident response (और इसे test करें)। तिमाही review करें और नई threat intelligence के लिए update करें। MOVEit और Accellion breaches दोनों ने narrow technical bugs exploit किए, लेकिन जिन organizations का dwell time सबसे कम और exposure सबसे छोटा था वे वही थीं जिनकी retention windows tight थीं और monitoring active थी। Checklist किसी एक control के बारे में कम है और layering के बारे में ज़्यादा।
hexatransfer.com पर आज़माएं — मुफ्त, बिना अकाउंट, 10 GB तक।
एंड-टू-एंड एन्क्रिप्शन के साथ बड़ी फ़ाइलें सुरक्षित रूप से भेजें
एंड-टू-एंड एन्क्रिप्शन के साथ 10 GB तक की फ़ाइलें मुफ़्त में ट्रांसफ़र करें। अकाउंट की आवश्यकता नहीं। अपलोड से पहले आपकी फ़ाइलें ब्राउज़र में एन्क्रिप्ट की जाती हैं — कोई और उन्हें पढ़ नहीं सकता।
फ़ाइल भेजें