In Episode 60 of Razorleaf’s Stay Sharp podcast, Securing Digital Environments Beyond Cybersecurity, Jonathan Scott talks with one of Razorleaf’s own, Steve Nichols, head of Razorleaf Government Services Division. Along with a background in physics, Steve brings to the table more than 25 years’ experience in technology, particularly in the arena of securing digital information for government clients.
At the outset, Jonathan and Steve make clear that the kind of digital security they’re discussing is not about securing data when it’s sitting quietly in your network, but about securing it while people are working with it, especially if it moves around and multiple people—internally and externally—work with it. Steve says he looks at process security and the safety of data, “thinking about how do we work in a collaborative environment across suppliers, across designers, across customers, but still make sure that the data that is being designed—or really the program that’s being designed and the data that’s being used to do it—is secure but still accessible.”
Collaboration vs. Compartmentalization
Secure but accessible means compartmentalization. “It’s that tension between, the whole thing you’re working is safer if not everybody knows every piece,” Jonathan says, “but that could be limiting some opportunities for compartmentalization.” Steve agrees that data should be accessible to the people who need to have it, but you also have to ask the question if everyone in a program really needs to be able to see everything.
Steve goes on to explain that the idea of data security gets significantly more complicated as the concept of a “team” expands, which he illustrates with the example of a government entity that hires an external contractor who designs, builds, and maintains an item, and who also has suppliers down the supply chain. You need to think about what data can and should be shared at every level. “It gets complex,” he says, “but I come back to, it’s really about upfront design of the integrated digital environment architecture.”
Critical to Plan Your Data Architecture
Possibly the most important point Steve makes in the duo’s conversation is that organizations need to plan early and they need to be as thorough with their planning of the initial stages of the program as they are for the end stages and the end result. “Just don’t skip over the planning part up front,” he says. “I would say that a successful program is 80% architecture design, which then leads to a successful output.”
Part of considering the overall architecture of a program is planning the data marking or data fingerprinting, which can be part of metadata, a database field, and/or a header, footer, or cover sheet displayed in the file—all of which are defined in standards and processes produced by official entities. Steve explains, “There’s the architecture that defines how data is going to flow, and when you think about data flows and data accessibility, what makes that all possible is understanding what that data is.” Being proactive about planning for data marking—understanding what needs to be marked and why—at the outset of your project will make your program more efficient and successful, because it allows the engineers, designers, and other workers on your project to focus on what they’re there to do, not what they had to go back and clean up.
Steve does caution that while you need to plan your program well, you shouldn’t plan every step of the project before you start it. He compares program planning to the idea of a football game, where the coach plans the first few plays and defines guidelines for how the team will adjust after that. Starting with a few set plays—or program steps—will get the team flowing in a rhythm and a cadence. Then you start filling in some of the gaps. “We know the end result. We know what some of the pieces are going to be along the way, but let’s plan that first bit and take a couple steps together,” Steve says. “Once we get a cadence going, we still want to make sure we’re pulling in new ideas and benefitting from them, but we want to make sure they don’t disrupt the momentum that we’re starting to build, that they can get woven in appropriately. That’s process architecture.”
Learn More About Securing Your Data While Still Keeping it Accessible
The full podcast contains more discussion and details on a variety of topics, including why it’s important to ensure that data can always move up to higher sensitivities but not down, why Steve thinks more about capabilities than projects, how planning for the right capabilities can make it possible to easily change a manufacturing plant from producing cars to producing refrigerators, and more.
Check out the full conversation in Stay Sharp Episode 60: Securing Digital Environments Beyond Cybersecurity, and join us each week for a new podcast.



