If you follow all recommendations you're way ahead of the curve compared to what I've seen, but I've mostly seen small IT shops.
I do recall passworded ZIPs being easy to crack, that might be better replaced with a PGP-based alternative.
If you follow all recommendations you're way ahead of the curve compared to what I've seen, but I've mostly seen small IT shops.
I do recall passworded ZIPs being easy to crack, that might be better replaced with a PGP-based alternative.
Don't use password-protected ZIPs.
It's almost worth a HN post in itself, but I can't find a good reference to link to.
1: http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.49.2... (PDF maybe available via FTP?)
2: https://security.stackexchange.com/questions/5447/how-secure...
This isn't a list of the best things to do, it's a list of some practical steps that can make things better. But ultimately the right level of security depends on the importance of the client communications. Some things are fine to do as Google Docs and other things you'll want to do with in-person meetings where no phones are allowed.