Degree 5 · Unit 5.3
Creative security
In technology companies the asset being protected is obvious: a database, a server, some code. In creative work — design, media, architecture, content — the most valuable asset is usually a file sitting on somebody's personal machine: the concept before it launches, the identity before it is announced, the text before it is published. Its entire value lies in the fact that it is not yet known, which means a single leak annihilates it completely.
This is why I wrote "Creative Security". Information security standards were written for large organisations, and when they get applied to a team of five they produce rejection rather than protection. What is needed is a translation, not a copy.
Three new risks for creatives
The first is the idea leaking through the tool. Uploading a confidential concept to a public system to improve its wording may well take it outside your circle of confidentiality altogether. Read the tool's terms, or work in an approved environment, or upload the idea stripped of anything that identifies it.
The second is ownership left vague. When a system takes part in producing a work, who owns the result? Legal systems differ on this and are still forming their positions. The practical answer today is explicit wording in the contract, written well ahead of any dispute.
You learn them to protect your work when you share it, and to use other people's work without trespass — the first practical answer to murky ownership.
All six share one condition, attribution: credit to the original creator, a link to the source, and a note of any change you made. Read the ladder downwards: each step narrows the user's freedom and widens your protection — and the choice is a commercial decision as much as a legal one.
The third is style impersonation. The style you built over twenty years can be imitated in a matter of minutes. There is no technical way to prevent that, so you meet it with the things that cannot be imitated: the relationship, the context, the judgement, and a reputation you have documented.
Do this
1 — In your field. Write down the three most valuable intangible assets in your work, and where each of them actually is now — not where it is supposed to be.
2 — In practice. Review the permissions of your last three external collaborators. How many of them still hold access they do not need?
3 — In writing. Draft the AI clause for your contracts: what is permitted, what is disclosed, and who owns the result.
Why creatives resist security — and how to persuade them
Because most of what has been offered to them in the name of security was an obstacle: long request forms, tools that slow the work down, and language that was never theirs. The resistance here is not ignorance. It is a sound judgement about badly designed tools.
The approach that has proved itself is to tie every control to a loss they already recognise. Do not say "asset classification"; say "so that the concept does not get published before the launch". Do not say "permission management"; say "so that your file does not stay behind with a collaborator who has left". A control whose reason is understood gets carried out without anyone having to follow it up.
Outside the office network every creative becomes their own security officer — and these are the five cheapest controls to win a team over with.
The freelancer's golden rule: treat every network outside your own home — the client's office network included — as public.
Where to after this unit? You have put your own house in order. The next unit shows you what the law imposes on you from outside it.
