Our motto: "Solutions...Not More Problems" reflects our attitude towards the completion of each and every project we work on. We'll tell you the way it is by giving you the straight answers. We don’t pull any punches and answer all your questions, allowing you to make an informed decision on how to proceed the best way for your business.


28th Sep 2008

Data Leakage And You

All businesses have sensitive data. While it’s assumed that the employee list, profit margins, and customer purchasing information is sensitive most business forget things like their client lists, vendors and suppliers, and marketing data when considering what is key data.

Never believe that your business data isn’t of interest to people outside your business.

In today’s world of inexpensive thumb and pocket drives, data capable smart phones, iPods (Yes…iPods! An iPod can be set to hard drive mode - where you can use the iPod as a storage device for PCs and Macs.), and large storage web mail the ability to move data from point a-to-b is becoming simpler.

To truly have protection from data leakage, the detection tools have to be placed on the workstations as well as the server and network. Most large organizations have their networks setup to capture unauthorized data collection attempts, however the servers and workstations are typically left alone (or better said, left to the standard security of the operating system).

Businesses assume that the confidential information employees use daily is secure…through various means such as policies, system configurations, etc.

What is forgotten is that people will invariably find workarounds for the ability to have access to the data.

An example I’ll use is from a company I worked for in the past. The finance people started making and using spreadsheets that detailed sales commissions they could share amongst people in and out of the finance group because not everyone interested in sales commission data had access to it (the company’s procedure to get access to financial data was tedious at best). Later on, this spreadsheet got to our largest competitor who used the numbers in a campaign ad to show how we overcharged for the same services.

Another example was a client who wanted us to lock out an employee that was leaving because the reason the person was hired was that the person came to them with their competition’s information and the client did not want that happening to them now that that person was leaving their firm.

What value would you place on the above examples? How does a business prevent data getting away from the business to outsiders?

The hard truth is…securing against data leakage is not easy.

This TechRepublic article lists some simple data leakage protection strategies making it a good place to start: http://articles.techrepublic.com.com/5100-10878_11-5293877.html

Now what happens if you suffer a breach of information? The loss of large volumes of protected information has become a regular headline event, forcing companies to re-issue cards, notify customers, and mitigate loss of goodwill from negative publicity.

With these headlines, there are increasing regulatory compliance for business such as HIPAA in health and benefits, GLBA and Sarbanes-Oxley in finance, and Payment Card Industry DSS standards. Many of these regulations stipulate regular audits, which business can fail if they lack suitable security controls and due-care (processes) standards. These same regulations also have significant penalties in the event of a breach.

Your data is valuable to your business, and its safekeeping is vital to maintaining a good reputation. In addition, much data, such as personal healthcare information and financial information, is protected by federal or state legislation, and its exposure, whether intentional or not, can lead to significant fines.

Luckily, data leakage can be prevented through standard precautions such as strictly enforced authentication and authorization, and tools (beginning at the workstation level).

1 Response »

  1. Dan Waldron
    September 28, 2008 | 3:16 pm

    I found your site on technorati and read a few of your other posts. Keep up the good work. I just added your RSS feed to my Google News Reader. Looking forward to reading more from you down the road!

     

TrackBack URL

Leave a Response

New Dell Laptop Battery Recall

http://www.cpsc.gov/cpscpub/prerel/prhtml09/09035.html
Dell has identified a potential issue associated with certain batteries sold with Dell Latitude™, Inspiron™, XPS™ and Dell Precision Mobile Workstation™ notebook computers. In cooperation with the U.S. Consumer Product Safety Commission and other regulatory agencies, Dell is voluntarily recalling certain Dell-branded batteries with cells manufactured by Sony and offering free replacements for these batteries.  [...]

State Department Announces Another Security Breach

www.washingtonpost.com/wp-dyn/content/article/2008/10/30/AR2008103004716.html
This is just another example of how your information can be comprimised.

Warning From The FTC - A “Phish-erman’s Special”

With the financial crisis in full swing, the FTC is putting out a warning that there may be more Phishing sites spun up in an attempt to capture your financial information.
However, we believe they may also use a Security Certificate Trojan rather than a phishing attempt.
As always, avoid clicking on any links within emails from untrusted sources.
Even [...]

Will Two AMDs Be Better For You?

AMD has announced a splitting off of it’s manufacturing to Advanced Technology Investment Company of Abu Dhabi.
http://blogs.zdnet.com/BTL/?p=10328&tag=nl.e539
While that is good for their books (they have been loosing the battle against Intel for some time now) and shareholders…what does it mean for the many people out there with AMD products and those who prefer AMD over [...]

Data Leakage And You

All businesses have sensitive data. While it’s assumed that the employee list, profit margins, and customer purchasing information is sensitive most business forget things like their client lists, vendors and suppliers, and marketing data when considering what is key data.
Never believe that your business data isn’t of interest to people outside your business.
In today’s world [...]