search.noResults

search.searching

saml.title
dataCollection.invalidEmail
note.createNoteMessage

search.noResults

search.searching

orderForm.title

orderForm.productCode
orderForm.description
orderForm.quantity
orderForm.itemPrice
orderForm.price
orderForm.totalPrice
orderForm.deliveryDetails.billingAddress
orderForm.deliveryDetails.deliveryAddress
orderForm.noItems
A


behind-the-scenes look at Indigo Vault Docs, built to protect critical business documents against insider risk, AI leakage and post-quantum threats.


For years, many enterprise security programmes treated office documents as an output of “real systems” (databases, apps, and networks) rather than a primary asset class in their own right. We saw the reality as exactly the opposite. In day-to- day operations, the crown jewels of most organisations travelled as Word documents, spreadsheets, PDFs, and slide decks: forwarded, downloaded, copied into personal notes, pasted into chat, or dropped into AI tools. That’s why we built Indigo Vault Docs, a document security platform that protects a document not only at rest and in transit, but also while it is actively being used.


Why ‘documents-in-use’ became a board- level issue


Willis Towers Watson (WTW) has over 50,000 employees operating across 145 countries, supporting clients with risk and human capital challenges. In practice, that means large volumes of highly sensitive client data and trade secrets, often packaged into office documents for analysis, board papers, underwriting decisions, deal execution, or incident response.


What we kept running into was the “last mile” problem. Even when upstream controls are strong, with good identity controls, encrypted transport, and hardened endpoints, the moment a file becomes a portable object it tends to slip into the most permissive channels: forwarded to a personal address to “work on later”, saved to unmanaged storage for convenience, or shared with a third party who genuinely needs access but doesn’t share the same controls. That isn’t a moral failing; it is normal human workflow colliding with high-value information.


In 2017, through our work with Microsoft on its quantum computing programme, we confronted a specific long-term risk: harvest now, decrypt later. If an adversary can capture encrypted traffic today and later decrypt it with a sufficiently capable quantum computer, confidentiality has an expiry date. That observation reframed document security for us from a purely operational concern to a strategic, time- bound risk. It also had to account for human behaviour (accidental sharing, convenience-driven workarounds) rather than only external threat actors.


When we could not find a commercial solution that met the need, our CEO tasked us with building one.


Then AI put the issue into even sharper focus. As board attention shifted to AI risk, one message became clear: better document protection also means better AI protection.


The design goal: high protection without user friction


Our guiding principle was straightforward: make the secure path the easiest path. Instead of asking employees to classify, encrypt, and distribute documents through a specialist workflow, we present the solution as a familiar folder in Windows File Explorer. People save files where they already save files, while our platform applies policy, protection, and auditability automatically.


Under the hood, that “simple folder” required a ground-up re-architecture of document storage and control. We needed to protect documents in storage, in transit, and, critically, in use (the moment the file is opened, viewed, edited, or shared), while also supporting regulatory requirements such as data residency and records retention across our operating footprint. Our intent wasn’t to secure every file. It was to secure the small subset that represents outsized risk: the documents we cannot afford to leak, lose, or have tampered with.


We also learned early that the rollout matters as much as the cryptography. We


17 © CITY SECURITY MAGAZINE – SUMMER 2026 Advertorial


started with a small number of high-impact use cases, partnered with the teams who owned them, and treated adoption as a product launch: clear “what goes in the vault” guidance, simple onboarding, and fast feedback loops when a control got in the way of legitimate work. The goal was to create confidence. Users should feel that placing a document in the vault makes their job easier, not harder.


What counts as ‘critical’


Our view is that the highest-assurance controls should be reserved for the files where the blast radius is extreme. In a mature end state, that may be under 10% of an organisation’s total documents. Examples include kidnap & ransom policy documentation (where disclosure can invalidate coverage and increase personal risk), merger & acquisition materials (where market sensitivity and regulatory obligations are paramount), and cybersecurity penetration test reports (which can function as a roadmap for attackers if mishandled).


To decide what belongs in that “critical” set, we use simple tests: if this leaked, who would be harmed and how quickly? If this were subtly altered, what decisions would change? And how long does this information need to remain confidential – days, months, or years? Those questions keep the conversation grounded in outcomes, and they help us avoid two failure modes: over-classifying everything and so overwhelming users, or under- protecting what truly matters.


Page 1  |  Page 2  |  Page 3  |  Page 4  |  Page 5  |  Page 6  |  Page 7  |  Page 8  |  Page 9  |  Page 10  |  Page 11  |  Page 12  |  Page 13  |  Page 14  |  Page 15  |  Page 16  |  Page 17  |  Page 18  |  Page 19  |  Page 20  |  Page 21  |  Page 22  |  Page 23  |  Page 24  |  Page 25  |  Page 26  |  Page 27  |  Page 28  |  Page 29  |  Page 30  |  Page 31  |  Page 32  |  Page 33  |  Page 34  |  Page 35  |  Page 36