How a Media Buying Team Can Protect Itself from Information Leaks
The media spotlight on the affiliate market has triggered not only a wave of fresh talent, but also a surge in corporate espionage. Stories have been circulating publicly about newcomers attempting to join teams in order to learn the "secrets" of running traffic and other valuable information.
In this piece, we break down how to protect confidential information about traffic campaigns within a team and what tools are available for that purpose. We invited experts from Traffic Squad, Trident Media, and Space Profit Team to share their experience.
What Data Teams Need to Protect
Traffic arbitrage is often associated with a "money button," and in recent years the space has attracted new people trying to figure out how to earn enough for a Panamera — ideally within the first month. Some newcomers dream of getting access to an evergreen funnel to make money on autopilot.
HR managers and security teams at media buying companies are forced to screen out suspicious candidates in order to protect the team's infrastructure. This puts pressure on the team and requires periodic updates to security protocols.
What data typically falls into the "not for disclosure" category:
- traffic campaign specifics;
- salary figures;
- company financial metrics;
- headcount, department structure, etc.;
- advertiser lists, offers, and payout rates;
- proprietary company software.
Any information whose leak could negatively impact a company's financial performance or reputation requires protection. Safeguarding trade secrets is especially critical for high-profile media brands.
Tools for Protecting Sensitive Information
From an outside perspective, it may seem like teams don't have many options for protecting confidential information — and there are doubts about their effectiveness, since no software or protocol is foolproof.
For example, there have already been cases on the market where team leads and team owners were scammed out of money through a fake consumables store scheme. Protecting against this kind of fraud is extremely difficult, and even experienced professionals have fallen for scammers.
Below we cover the basic tools for preventing information leaks, with invited experts providing more detail on each.
Security Department
Large teams typically have a dedicated security department within their structure, responsible for ensuring that confidential data doesn't leave the office. Every company runs it differently, but the value it provides is undeniable.
Security staff thoroughly vet new hires using OSINT tools and their own sources. Once an employee joins the team, their activity is monitored for any signs of suspicious behavior.
Lie Detector
Polygraph testing has long become standard practice for both new and existing employees at affiliate teams. From interviews, we know that even CEOs of some companies periodically visit polygraph examiners.
The lie detector has its limitations, but overall it's a powerful psychological tool that can deter corporate spies. In Ukraine, polygraph services became especially popular in parallel with the boom in affiliate and IT companies.
NDA
A Non-Disclosure Agreement is a document that an employee signs before gaining access to confidential data. The agreement outlines rights, obligations, potential penalties, and the method for resolving disputes between a team member and the company.
There is a view that NDAs carry little legal weight within the Ukrainian jurisdiction, but it's situational. If the document is well-drafted and the company has in-house or outsourced legal counsel, the liability for breaching the agreement can serve as a psychological deterrent.
Corporate Secured Devices
Some IT companies operate under very strict security protocols and issue employees specialized laptops that are protected against data extraction. Whether this is practical in a media buying business remains an open question.
Q&A with Media Buying Teams
What is your company's approach to protecting confidential information?
What data is critical for a media buying team to protect? Connections, financial metrics?
Do you have a security department? If not, why?
Do you use a polygraph? For what purposes?
Do you have an NDA? How strict is it?
What about corporate secured devices? Is that going too far, or is it standard practice?
Have you ever had cases of corporate espionage? Did any newcomers come in looking to leak something?
Security is clearly taken seriously in the media buying business. So joining a team for the sake of connections or financial data simply doesn't make sense. It's better to focus on building genuine expertise and networking within the team itself.
And for alternative takes on security from Yevhen, Head of PR at Space Profit Team — check our Instagram.