Secure Data Sharing in the Enterprise
2 Follow-me data and productivity for users with security and manageability for IT Productivity today depends on the ability of workers to access and share their data from any device, in any location, and use it to collaborate with colleagues and partners anywhere in the world. In this era of mobility, bring-your-own device (BYOD) and globalization, work isn t something you do in a single place, on a single computer; it can happen anywhere on any device. Work teams, partner networks and customer bases span geographies. Projects and processes involve workers across multiple organizations and locations. How can IT allow data to flow where it s needed without sacrificing security, control and compliance? In reality, data is already being accessed and shared across locations and organizational boundaries but this is happening largely through unmanaged consumer services that workers have adopted themselves. Data shared and synced through these services remains stored in third-party locations beyond the visibility and management of IT. This poses serious risks for the organization, as IT is unable to effectively secure or control access to enterprise data shared in this way. Simply shutting down access to these services without providing a better alternative will only lead people to seek different unsanctioned ways to meet their data access and sharing needs. An effective solution must address the needs of both users and IT by: Empowering users with instant access to data, synced across all devices, and helping them improve collaboration and productivity through secure file sharing that seamlessly integrates with their workflow; Enabling IT to retain full control over data access and sharing while delivering a managed service that meets corporate data security and compliance standards. Citrix ShareFile addresses this need with an enterprise follow-me data solution that IT can use to deliver a secure, robust service that meets the mobility and collaboration needs of all users. Workers can easily share, store, sync and secure data across any device, while IT can meet its requirements for security, compliance and manageability. Building on Citrix leadership in follow-me desktops and applications, ShareFile completes the Citrix solution for anywhere, any device productivity. The rise of consumer file sharing services in the enterprise To effectively address the unsecure data sharing problem, it is important to understand why it s happening. Users aren t simply putting the organization at risk capriciously; they have reasons for wanting to access and share data more broadly. This can best be understood in the context of several key business and IT trends.
3 On the level of individual workers: Mobility has become a fact of life for today s enterprise workforce. Work can happen anywhere, at any time, from a home office after hours to a commuter train to a café en route to a meeting. In addition to these ad hoc scenarios, many workers now have mobility built in to their customary work scenario, including those who work regularly at a customer or partner site, sales people, consultants and executives. These mobile workers need to be able to sync their data across all of the devices they use for work including mobile devices used on-the-go so they can reliably access it wherever and whenever they need it, and share it with colleagues and teams, as easily as if they were in the enterprise network. Consumerization and BYOD are rapidly transforming the enterprise computing environment, from the proliferation of devices to BYOD policies and programs that let people choose the technologies that best meet their work needs. As diverse device types proliferate and users start to manage multiple devices, though, it becomes harder for both users and IT to manage where data resides and how it can be accessed. While BYOD participants typically gain freedom in the devices they use, they remain unable to sync data across these devices, access it anywhere or share it with collaborators inside or outside the enterprise. This is a key driver of the use of unsecure consumer file sharing services on personal devices. On an organizational level: Threats posed by consumer file sharing services Lack of enterpriseclass security No ability for IT to control or audit data access and sharing Impossible to comply with government regulations Enterprise data stored in unknown locations and unmanaged thirdparty datacenters Workshifting and globalization have extended the enterprise workforce well beyond traditional locations. Organizations now need to hire people in more places and work with a greater diversity of partners and contractors around the world. IT must enable workers in any location to easily access and share the data their work requires, from large design files used in manufacturing to outsourced software code to production files for media and entertainment, while maintaining security and control over intellectual property and other corporate assets. Collaboration is especially critical, as team members across geographies and organizations depend on the ability to share data easily without being constrained by location. Changing customer relationships create new requirements, as organizations increasingly seek to do business via electronic communications and transactions, which can be secured, tracked and audited more effectively than paper or email-based methods. By exchanging information in electronic form, organizations can better verify whether documents have been received, and by whom, as well as ensure security from end to end. This approach requires reliable secure file sharing between any two parties, regardless of location, network or file size. Existing enterprise data sharing tools are unable to meet the needs of users and the organization. Email systems place restrictions on the size of files that can be sent; even if the sender is able to send a large file, it will often be blocked on the recipient s side. Users are not provided with solutions that can help them access corporate data and keep it synced across all their devices.
4 Network file shares can t be accessed from outside the corporate network or on mobile devices. Many existing collaboration tools deployed by IT are similarly difficult or impossible to access on third-party networks or mobile devices, and don t allow data to be shared easily with third parties. In the absence of an effective IT-managed data sharing solution, users have naturally begun to meet their own needs through unmanaged consumer services. The threat posed by unmanaged file sharing services The rampant use of consumer file sharing services poses an obvious threat to enterprise data security. IT has no control over how these services are used: which types of data can be shared, how it can be accessed, or who it can be shared with either internally or externally. Data access and sharing activity can t be centrally tracked or audited, making it impossible to comply with IT standards and government regulations especially in highly regulated industries like finance and healthcare. Data shared with third parties can all too easily be re-shared and accessed well beyond the intended recipient. Requirements for enterprise file sharing Enterprise-grade security for data at rest and in transit Ability to store data off and on-premise Simple, productive, delightful user experience IT control over data access and sharing Real-time sync across all user devices, including mobile Full auditing and reporting of user activity Simple, secure third-party data access and sharing Access to data in existing enterprise data platforms The problem is increasingly widespread. According to an August 2012 Enterprise Strategy Group report, a vast majority of organizations 70 percent know or suspect that their employees are using personal online file sharing accounts without formal IT approval. 1 Dropbox, one of the most popular consumer services and a frequent choice of users for unmanaged file sharing, has seen widely publicized breaches. The service poses such a risk that many in IT refer to unmanaged file sharing in general as The Dropbox Problem. Many organizations respond to this problem by blocking consumer file sharing services, but this is an unrealistic response. If one service is blocked, users will simply find another, and another after that because their productivity depends on it. The only effective remedy is for IT to implement a true enterprise-class solution which provides complete, robust and intuitive data sync and sharing capabilities for users while protecting intellectual property data, minimizing risk and supporting compliance. To gain full user acceptance and prevent further use of consumer services, the solution must go beyond the limitations of current IT-deployed solutions designed for internal use, which typically lack features like sync, mobile access, easy access and external collaboration. Workers need and expect to be empowered with instant access to files and data from any device, anywhere, as well as easy file sharing with collaborators inside and outside the organization. These enterpriseclass features must be provided through a solution with an intuitive, consumer-like experience to match or exceed any consumer file sharing service. 1. ESG Research Report, Online File Sharing and Collaboration: Security Challenges and Requirements, August 2012
5 Citrix ShareFile: Secure, managed data sharing for the enterprise As a leader in enterprise mobility and anywhere, any device computing, Citrix has transformed IT with follow-me desktops and apps. Now, Citrix is extending this value proposition with follow-me data. Citrix ShareFile is an enterprise follow-me data solution that enables IT to deliver a secure and robust service that meets the mobility and collaboration needs of all users. With more than 20 years of experience serving the needs of enterprise IT, Citrix designed ShareFile as a true enterprise-class alternative to consumer style file-sharing services. More than three million users at more than 24,000 organizations already use ShareFile to share, store, sync and secure data across any device. For users, ShareFile provides: Mobile access to data synced across all devices The average worker has three devices, including laptops, smartphones and tablets, and wants data to be synchronized across all of them in real time to allow anywhere, anytime, any device access. This capability is one of the primary drivers of unmanaged file sharing. ShareFile meets this need with apps and tools that enable realtime sync across all of a user s devices for a brilliant, intuitive follow-me data experience. Integration with Microsoft Outlook, Microsoft Windows Explorer and Mac OS Finder makes it simple and intuitive for people to share, open and edit documents stored in ShareFile within the context of their existing workflow. Easy collaboration inside and beyond the organization Outlook integration lets users both share files and send requests for files to others. Users can also share data securely with third parties who don t have a ShareFile account easily and without restriction, including the ability to request files from them. Files of sizes up to 100 GB can be shared well beyond the limits of consumer services. The ShareFile Outlook plug-in can be configured to convert all attachments into ShareFile links, or only those attachments over a given size, to suit a user s local network scenario or fit within network limitations on file size. Access to data in corporate network shares The Citrix follow-me data strategy is not limited to the data stored in ShareFile. Users also gain instant mobile access to data on network file shares, which otherwise cannot be accessed outside of the corporate network or on mobile devices. A fully integrated experience Integration with Citrix Receiver, a universal client for accessing virtual desktops and apps on any device, enables both follow-me apps and follow-me data with single sign-on. Users can open, view and edit ShareFile data with a rich editing experience through apps hosted by Citrix XenApp.
6 For IT, ShareFile provides: Flexible data storage Organizations can selectively store ShareFile data in Citrix-managed StorageZones, which provide highly secure cloud storage in SSAE 16 audited datacenters without the need for on-premise infrastructure or maintenance; in StorageZones managed directly within the customer s own datacenter; or in both. This flexibility helps IT address the organization s unique data sovereignty and compliance requirements while building the most costeffective and customized solution. Seamless integration with existing data platforms Working in conjunction with customer-managed StorageZones, StorageZone Connectors let IT create a secure connection between the ShareFile service and user data stored in existing network shares without the need for data migration. Enterprise-grade security ShareFile is a PCI-DSS compliant solution which provides extensive data protection features. Files are encrypted both at rest and in transit. Remote wipe allows both users and IT to wipe all ShareFile-stored data and passwords on a device that has been compromised. IT can also remove a device from the list of devices that can access ShareFile accounts, or lock a device to restrict its use for a defined period of time. A poison pill capability lets IT prescribe data expiration policies for mobile devices. Auditing and reporting IT can track and log all user activity, including both data access and data sharing, to support compliance requirements and provide visibility into data usage. Users and IT can also create custom reports on account usage and access. Conclusion The business value of trends like mobile workforce, BYOD, workshifting and globalization depends on the ability of IT to empower workers with secure data sharing, storage and sync anywhere, on any device. Existing enterprise data sharing tools and solutions fail to deliver the simple experience and comprehensive capabilities people need, leading them inevitably to turn to unsecure commercial file sharing services. This exposes the organization to risks from the theft of intellectual property to regulatory non-compliance. These risks will continue to grow until IT provides a better alternative combining the convenience and productivity of consumer services with enterprise-class functionality and security.
7 Citrix ShareFile makes it possible for IT to provide the anywhere, any device data access and collaboration people need while meeting the organization s requirements for security, manageability and compliance. With more than two decades of experience serving enterprise IT, Citrix designed ShareFile as a true enterprise-class solution that eliminates the threat posed by consumer file sharing services while providing the industry s most comprehensive feature set. By making follow-me data a seamless and intuitive part of every user s day, ShareFile enables optimal productivity for today s highly mobile, anywhere, any device workforce. Resources Citrix ShareFile website Introduction to ShareFile Enterprise (video) ShareFile with StorageZones (video) Corporate Headquarters Fort Lauderdale, FL, USA Silicon Valley Headquarters Santa Clara, CA, USA EMEA Headquarters Schaffhausen, Switzerland India Development Center Bangalore, India Online Division Headquarters Santa Barbara, CA, USA Pacific Headquarters Hong Kong, China Latin America Headquarters Coral Gables, FL, USA UK Development Center Chalfont, United Kingdom About Citrix Citrix (NASDAQ:CTXS) is the company transforming how people, businesses and IT work and collaborate in the cloud era. With market-leading cloud, collaboration, networking and virtualization technologies, Citrix powers mobile workstyles and cloud services, making complex enterprise IT simpler and more accessible for 260,000 enterprises. Citrix touches 75 percent of Internet users each day and partners with more than 10,000 companies in 100 countries. Annual revenue in 2011 was $2.21 billion. Learn more at www.. 2012 Citrix Systems, Inc. All rights reserved. Citrix, ShareFile, XenApp and Citrix Receiver are trademarks or registered trademarks of Citrix Systems, Inc. and/or one or more of its subsidiaries, and may be registered in the United States Patent and Trademark Office and in other countries. All other trademarks and registered trademarks are property of their respective owners. 1212/PDF