Sensitive technology. Generous access.
Yes, our engineering team includes people from Russia. No, a Russian passport does not automatically make somebody dangerous, sanctioned or unfit to work in Europe.
That would be a lazy conclusion.
We prefer a different kind of laziness: giving people broad access to technical files, engineering servers, drawings, firmware and product know-how, then assuming everything is fine because nobody has caused a visible problem yet.
The real compliance question is not where an engineer was born. It is what we allow them — or anyone else — to access, download, copy, transmit and keep.
OUR ACCESS CONTROL MIGHT BE. Much less discriminatory. Much more embarrassing.
If you can see the folder, we assume you need it
Proper companies use role-based access, project segmentation and the need-to-know principle. We use a simpler model: if your account can open the folder, congratulations, apparently somebody trusted you.
Who granted the permission? Maybe IT. Maybe a manager. Maybe somebody copied the folder into a shared drive three years ago. The important thing is that collaboration remains frictionless.
Downloading is also useful. Engineers work faster when files are easy to move around. Logging every copy, restricting external storage and reviewing permissions would only introduce unpleasant visibility into how our information actually travels.
We prefer nice-to-have access.
Our intellectual property travels very efficiently
Sensitive engineering does not leave the company only as a finished machine. It can leave as CAD files, wiring diagrams, firmware, manufacturing instructions, test procedures, calculations or a ZIP file with a reassuringly professional name.
That is what makes technical-data protection annoying. A truck crossing a border is visible. Someone copying years of engineering know-how can look exactly like an employee working late.
We could classify information, restrict exports, monitor unusual downloads and control external transfer channels.
Instead, we mostly rely on the universal security standard: please don’t.
PLEASE RESPECT THE FONT WE USED.
We check the difficult part after somebody asks
Aviation, electronics, software and industrial technology can create export-control and sanctions questions depending on what the technology is, who receives it, where it goes and what it may be used for.
A mature company tries to understand those questions before access or transfer happens.
We prefer event-driven compliance.
First somebody asks whether a technology is controlled. Then somebody forwards the question to Legal. Then Legal asks Engineering what the product actually contains. Engineering asks Sales where it is going. Sales says the customer needs an answer today.
when somebody else owns it.
We don’t profile people. We under-control everyone equally.
Nationality is a terrible substitute for actual security controls. A Russian engineer is not automatically a threat, just as an Estonian, German or Finnish engineer is not automatically safe.
So rather than discriminate, we have chosen equality.
Broad permissions. Weak segmentation. Generous internal visibility. Minimal curiosity about who can download what.
Everybody receives roughly the same opportunity to become an information-security incident.
INFORMATION SECURITY. Everyone can access more than they probably need.
Our policy and reality maintain a healthy distance
On paper, everything looks reassuring. Confidentiality. Restricted access. Compliance. Cybersecurity. Export controls. Responsible information handling.
Then somebody asks to see how it actually works.
Who has access to the engineering server? Which files are classified? Can downloads be traced? Are old accounts disabled immediately? Who checks external transfers? Who owns sanctions screening? Which products have actually been classified?
This is where policy becomes inconveniently physical.
We prefer audits that focus on documents rather than behaviour. Documents are considerably easier to organise before a meeting.
They just work in different departments.
DOCUMENT LATER.
Frequently
Restricted Questions
Are Russian engineers automatically a compliance problem?
No. Nationality alone does not establish misconduct, sanctions evasion or security risk.
The uncomfortable question is much more practical: what information did we give the person access to, and why?
Do we know who can access sensitive engineering files?
Of course.
We just need a little time to compile the list.
What happens when somebody leaves the company?
Their access enters our offboarding process.
The process usually accelerates when somebody notices them still online.
We could solve this properly. Classify sensitive information. Restrict access by role. Log downloads. Control external transfers. Review permissions. Disable old accounts immediately. Assign actual ownership for sanctions and export-control questions.
None of that requires discriminating against anybody.
It only requires us to understand our own systems.
Which is precisely where the paperwork becomes unpleasant.
IS NOT WHERE PEOPLE COME FROM.
IT IS HOW LITTLE WE KNOW
ABOUT WHERE OUR DATA GOES.