Email Signatures and Sensitive Information: Why They Matter #
Disclaimer: This article is provided for informational purposes only and does not constitute legal, regulatory, compliance, or cybersecurity advice. Use the information at your own risk and consult your organization’s legal counsel, compliance officer, security team, export control officer, or other qualified professionals before making decisions regarding regulatory compliance. If you are not an EasyITGuys client, you should follow your organization’s documented policies and procedures.
Why You Should Include a Security Notice in Your Email Signature #
Recommended Email Signature Notice #
SECURITY NOTICE: Do not send CUI, ITAR/EAR-controlled, export-controlled, or other regulated sensitive information to this email address. Sensitive information must be exchanged through PreVeil or other approved secure communication channels.
- Identifies information that should not be transmitted through standard email
- Directs the sender toward approved secure communication methods
- Sets expectations before sensitive information is transmitted
- Supports user awareness and documented handling procedures
What This Notice Does and Does Not Do #
What It Does #
- Communicates expectations
- Provides guidance to recipients
- Supports security awareness efforts
- Reinforces existing policies and procedures
- Encourages use of secure communication channels
What It Does Not Do #
- Is not a security control by itself
- Does not make standard email compliant
- Does not prevent someone from sending sensitive information
- Does not replace documented policies
- Does not replace employee training
What Should You Do If Someone Sends Sensitive Information to You? #
Step 1: Do Not Continue the Conversation in Standard Email #
- CUI
- ITAR-controlled information
- EAR-controlled information
- Export-controlled technical data
- Other regulated or protected information
Step 2: Move the Message Into Your Secure Environment #
- Move the message into the secure mailbox
- Store the information within the approved secure environment
- Follow your organization’s handling procedures
Step 3: Notify the Sender #
Respond professionally and courteously.
Thank you for the information. This email address is not intended for regulated or sensitive information. Please use our approved secure communication method for future exchanges. We have moved this communication into our secure environment and will continue the discussion through approved channels.
Step 4: Continue Communications Through Secure Channels #
- Continue sharing files there
- Continue messaging there
- Store documents there
- Maintain the conversation there
What If the Other Party Does Not Have a Secure Communication Method? #
Additional Considerations #
Your Compliance Requirements #
- CMMC
- NIST SP 800-171
- ITAR
- EAR
- DFARS
- Contract-specific security requirements
Your Approved Communication Platforms #
- Which systems are approved
- Which systems are not approved
- Where sensitive information belongs
- How employees should respond when mistakes occur
Your Policies and Procedures #
- What constitutes sensitive information
- How to identify it
- How to store it
- How to transmit it
- What to do when it is received improperly