Your journey
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
0 of 34 units

You are in Degree 5 · Governance and resilienceunit 3 of 6Ahead of you: An approved use policy and a completed maturity assessment.

Degree 5 · Unit 5.3

Creative security

In technology companies the asset being protected is obvious: a database, a server, some code. In creative work — design, media, architecture, content — the most valuable asset is usually a file sitting on somebody's personal machine: the concept before it launches, the identity before it is announced, the text before it is published. Its entire value lies in the fact that it is not yet known, which means a single leak annihilates it completely.

This is why I wrote "Creative Security". Information security standards were written for large organisations, and when they get applied to a team of five they produce rejection rather than protection. What is needed is a translation, not a copy.

FIG. 27 — Six controls that suit a team of five
1
Classify assets at three levels
Public · internal · confidential until launch, each with a clear sharing rule.
2
One place to work
No files on personal machines; the asset lives where its permissions are managed.
3
Permissions that expire
A freelancer gets timed access; the project ends and the access with it.
4
Proof of authorship
A dated record of the first versions; a documented date is the argument.
5
A clause in every contract
Who owns the output? Is AI permitted in it? And is it disclosed?
6
Backups that are tested
A backup whose restore was never tried is not a backup. Try it every quarter.

Three new risks for creatives

The first is the idea leaking through the tool. Uploading a confidential concept to a public system to improve its wording may well take it outside your circle of confidentiality altogether. Read the tool's terms, or work in an approved environment, or upload the idea stripped of anything that identifies it.

The second is ownership left vague. When a system takes part in producing a work, who owns the result? Legal systems differ on this and are still forming their positions. The practical answer today is explicit wording in the contract, written well ahead of any dispute.

Six licences, from the broadest to the narrowest

You learn them to protect your work when you share it, and to use other people's work without trespass — the first practical answer to murky ownership.

FIG. B27 — The six-licence ladder
CC BY
Attribution
Distribute, remix and build on it, even commercially, provided credit is given.
CC BY-SA
Share alike
As above, provided the derivative carries the same terms.
CC BY-ND
No derivatives
Redistribution only, unchanged, with credit.
CC BY-NC
Non-commercial
Remix and build on it for non-commercial purposes, with credit.
CC BY-NC-SA
Non-commercial + share alike
Non-commercial, and the derivative is licensed on the same terms.
CC BY-NC-ND
The most restrictive
Download and share only, with no changes and no commercial use.
The condition all six share: attribution (BY) — credit to the original creator, a link to the source, and a note of any change you made.

All six share one condition, attribution: credit to the original creator, a link to the source, and a note of any change you made. Read the ladder downwards: each step narrows the user's freedom and widens your protection — and the choice is a commercial decision as much as a legal one.

The third is style impersonation. The style you built over twenty years can be imitated in a matter of minutes. There is no technical way to prevent that, so you meet it with the things that cannot be imitated: the relationship, the context, the judgement, and a reputation you have documented.

Do this

  1. 1 — In your field. Write down the three most valuable intangible assets in your work, and where each of them actually is now — not where it is supposed to be.

  2. 2 — In practice. Review the permissions of your last three external collaborators. How many of them still hold access they do not need?

  3. 3 — In writing. Draft the AI clause for your contracts: what is permitted, what is disclosed, and who owns the result.

Why creatives resist security — and how to persuade them

Because most of what has been offered to them in the name of security was an obstacle: long request forms, tools that slow the work down, and language that was never theirs. The resistance here is not ignorance. It is a sound judgement about badly designed tools.

The approach that has proved itself is to tie every control to a loss they already recognise. Do not say "asset classification"; say "so that the concept does not get published before the launch". Do not say "permission management"; say "so that your file does not stay behind with a collaborator who has left". A control whose reason is understood gets carried out without anyone having to follow it up.

Five risks and the five controls that answer them

Outside the office network every creative becomes their own security officer — and these are the five cheapest controls to win a team over with.

FIG. B29 — Risk ⇒ control
1 Unsecured networks
An unprotected home or public Wi-Fi, open to a machine in the middle.
⟶
WPA3 · a mandatory VPN · a separate guest network
2 Stolen and lost devices
A personal device is more exposed to loss, and what is on it is in the open.
⟶
Full-disk encryption · locks · secure storage
3 No access control
Nobody revokes a collaborator's rights when the project ends.
⟶
Least privilege · a revocation list at handover
4 Phishing and social engineering
Well-crafted messages aimed at credentials.
⟶
Regular training · app-based two-factor, not SMS
5 Personal and professional mixed
Client files beside family photographs on the same machine.
⟶
A work account · separate cloud storage
The golden rule: treat every network outside your own home — the client's office network included — as public.

The freelancer's golden rule: treat every network outside your own home — the client's office network included — as public.

Where to after this unit? You have put your own house in order. The next unit shows you what the law imposes on you from outside it.