Compliance / Access / Convenient Assumptions

Sensitive technology. Generous access.

At CDR, we believe nationality is not the problem. Fortunately, our access controls are weak enough to create better ones.
CDR Insights Approx. 4 min read Compliance status: confidently incomplete

Yes, our engineering team includes people from Russia. No, a Russian passport does not automatically make somebody dangerous, sanctioned or unfit to work in Europe.

That would be a lazy conclusion.

We prefer a different kind of laziness: giving people broad access to technical files, engineering servers, drawings, firmware and product know-how, then assuming everything is fine because nobody has caused a visible problem yet.

The real compliance question is not where an engineer was born. It is what we allow them — or anyone else — to access, download, copy, transmit and keep.

THE PASSPORT IS NOT THE RISK.
OUR ACCESS CONTROL MIGHT BE. Much less discriminatory. Much more embarrassing.
01 / ACCESS

If you can see the folder, we assume you need it

Proper companies use role-based access, project segmentation and the need-to-know principle. We use a simpler model: if your account can open the folder, congratulations, apparently somebody trusted you.

Who granted the permission? Maybe IT. Maybe a manager. Maybe somebody copied the folder into a shared drive three years ago. The important thing is that collaboration remains frictionless.

Downloading is also useful. Engineers work faster when files are easy to move around. Logging every copy, restricting external storage and reviewing permissions would only introduce unpleasant visibility into how our information actually travels.

Need-to-know access is restrictive.

We prefer nice-to-have access.
02 / TECHNOLOGY

Our intellectual property travels very efficiently

Sensitive engineering does not leave the company only as a finished machine. It can leave as CAD files, wiring diagrams, firmware, manufacturing instructions, test procedures, calculations or a ZIP file with a reassuringly professional name.

That is what makes technical-data protection annoying. A truck crossing a border is visible. Someone copying years of engineering know-how can look exactly like an employee working late.

We could classify information, restrict exports, monitor unusual downloads and control external transfer channels.

Instead, we mostly rely on the universal security standard: please don’t.

CONFIDENTIAL.
PLEASE RESPECT THE FONT WE USED.
03 / COMPLIANCE

We check the difficult part after somebody asks

Aviation, electronics, software and industrial technology can create export-control and sanctions questions depending on what the technology is, who receives it, where it goes and what it may be used for.

A mature company tries to understand those questions before access or transfer happens.

We prefer event-driven compliance.

First somebody asks whether a technology is controlled. Then somebody forwards the question to Legal. Then Legal asks Engineering what the product actually contains. Engineering asks Sales where it is going. Sales says the customer needs an answer today.

01
SELL
Commercial opportunity identified.
02
ASK
Somebody mentions export control.
03
FORWARD
Send question to Legal.
04
ALIGN
Discover nobody owns the answer.
Compliance works best
when somebody else owns it.
04 / PEOPLE

We don’t profile people. We under-control everyone equally.

Nationality is a terrible substitute for actual security controls. A Russian engineer is not automatically a threat, just as an Estonian, German or Finnish engineer is not automatically safe.

So rather than discriminate, we have chosen equality.

Broad permissions. Weak segmentation. Generous internal visibility. Minimal curiosity about who can download what.

Everybody receives roughly the same opportunity to become an information-security incident.

NATIONALITY
Not a security control.
ROLE
Probably relevant.
ACCESS
Generous.
LOGGING
Excellent future project.
EQUAL OPPORTUNITY
INFORMATION SECURITY. Everyone can access more than they probably need.
05 / AUDIT

Our policy and reality maintain a healthy distance

On paper, everything looks reassuring. Confidentiality. Restricted access. Compliance. Cybersecurity. Export controls. Responsible information handling.

Then somebody asks to see how it actually works.

Who has access to the engineering server? Which files are classified? Can downloads be traced? Are old accounts disabled immediately? Who checks external transfers? Who owns sanctions screening? Which products have actually been classified?

This is where policy becomes inconveniently physical.

We prefer audits that focus on documents rather than behaviour. Documents are considerably easier to organise before a meeting.

Our policy and reality are fully aligned.

They just work in different departments.
TRUST FIRST.
DOCUMENT LATER.

Frequently
Restricted Questions

Are Russian engineers automatically a compliance problem?

No. Nationality alone does not establish misconduct, sanctions evasion or security risk.

The uncomfortable question is much more practical: what information did we give the person access to, and why?

Do we know who can access sensitive engineering files?

Of course.

We just need a little time to compile the list.

What happens when somebody leaves the company?

Their access enters our offboarding process.

The process usually accelerates when somebody notices them still online.

We could solve this properly. Classify sensitive information. Restrict access by role. Log downloads. Control external transfers. Review permissions. Disable old accounts immediately. Assign actual ownership for sanctions and export-control questions.

None of that requires discriminating against anybody.

It only requires us to understand our own systems.

Which is precisely where the paperwork becomes unpleasant.

OUR BIGGEST COMPLIANCE RISK
IS NOT WHERE PEOPLE COME FROM.

IT IS HOW LITTLE WE KNOW
ABOUT WHERE OUR DATA GOES.
CDR TECHNOLOGY

Sensitive technology.
Casual confidence.

COMPLIANCE — 90% COMPLETE
The remaining 10% contains most of the controls.
Прокрутить вверх