FREE FIELD GUIDE
Trust your suppliers. Verify their behaviour.
What outside access to your files actually looks like — and how you would know
A short field guide for the person who owns IT risk in a business of 25 people or more.
1The access you have already granted
Every business of any size has quietly handed the keys to people who are not on its payroll. The bookkeeper. The agency. The consultant who "just needs the folder". The developer who left in March. The managed service provider who set up the whole system and still holds an account.
None of this is a mistake. It is how a modern business gets work done. But it produces a situation that most owners have never said out loud:
The people with the widest access to your documents are frequently not your employees, and their behaviour is governed by a contract rather than by a manager.
A contract is a promise about intent. It is not a control. When a supplier relationship sours, when a contractor takes on a competing client, or when their laptop is compromised, the contract does not change what their credentials can still reach.
2Why your existing tools do not see it
The standard answers all sit in the wrong place.
Permissions describe what someone may do. They say nothing about what they did. An account with legitimate access that suddenly downloads the whole client folder is using its permissions exactly as granted.
Antivirus and endpoint tools look for malicious software on machines you control. The contractor's machine is not one of them, and no malware is involved when a person simply saves files they were allowed to open.
Data loss prevention works by reading your documents to decide whether they are sensitive. It is expensive, it is slow to tune, it requires you to classify your content first, and it means a vendor reads what you wrote. Most businesses under a few hundred staff look at it once and quietly decide against it.
Audit logs do contain the answer — afterwards. They are a record, not an alarm. Nobody reads them on a Tuesday.
The gap is specific: nothing in the standard kit is watching the shape of ordinary, authorised activity and noticing when it stops being ordinary.
3What the shape actually looks like
You do not need to read a single document to see trouble. Consider what an ordinary working week looks like as a pattern rather than as content.
A bookkeeper opens a handful of files, in one folder, between nine and five, on the same laptop, from the same city, every week for two years. That is not a rule someone wrote down. It is simply what has been true.
Now consider the departures — none of which require anyone to know what the files say:
- Volume. Eleven files a day for two years, then four hundred in one afternoon.
- Breadth. Always the one client folder, then suddenly every folder they can reach — including the ones they have never once opened.
- Timing. Normal hours for two years, then sustained activity at 2am on a Sunday.
- Direction. Files that were always opened are now being downloaded, or copied, or shared outward to an address that has never appeared before.
- Sequence. A methodical sweep — folder after folder, in order — which is what collection looks like and what work almost never looks like.
- Ending. The heaviest week of a contractor's entire history occurs in the fortnight before they give notice.
Each of these is visible in the metadata your cloud storage already records: who, what file, what action, when, how many, how fast. None requires the contents.
That distinction is the whole argument. A system that watches behaviour can be given to your suppliers' accounts without ever being given your intellectual property.
4The three questions worth asking your own business today
Regardless of whether you ever buy anything from us:
- List every account with access to your file storage that is not on your payroll. Most businesses cannot produce this list in under an hour, and are surprised by its length.
- For each one — if that account downloaded everything it could reach tonight, who would find out, and when? If the honest answer is "at some point, if we went looking", that is the gap.
- What was your last departing contractor's file activity in their final two weeks? You almost certainly have the log. Almost nobody has ever read one.
If those three questions produce comfortable answers, you do not need us. If they do not, the gap is not a tooling problem — it is that nobody is watching the shape.
5Who built this
TripWyre is the work of two inventors.
Ric Richardson is an Australian inventor with a long record of granted patents, best known for inventing the software-activation technology behind US Patent 5,490,216 — one of the most litigated software patents in history.
Dennis Groves is a co-founder of OWASP, the Open Worldwide Application Security Project. He authored the original OWASP Guide to Building Secure Web Applications and was a primary author of the OWASP AppSensor implementation guide — a body of work built on the same idea that underpins this product: that an attack is best detected from the behaviour of the system itself, in real time, rather than from inspecting content after the fact.
6What TripWyre does
TripWyre connects to your Google Drive with metadata-only permissions. It learns what normal looks like for each account, and it raises an alert — to a phone, out of band — when the shape of that account's activity departs from its own history.
It never reads your documents. It cannot: it does not ask for the permission that would let it.
We are not asking you to believe that from a web page. Fifteen minutes on a call, on your own Drive, with your own accounts, settles it either way.
Want it as a PDF to send on?
Tell us where to send it and the download starts straight away. Two fields, no follow-up unless you ask for one.
Next step after reading: book a 15-minute demo · send this to a colleague