IT-Harvest Archives of the Data Protection WEekly 2009-02-21T19:03:56Z WordPress http://it-harvest.com/blog/feed/atom/ Administrator <![CDATA[Data Protection Weekly for February 16, 2009]]> http://it-harvest.com/blog/2009/02/21/data-protection-weekly-for-february-16-2009/ 2009-02-21T18:53:39Z 2009-02-21T18:53:39Z Join Richard Stiennon with Safend for a Webinar on March 3
Retaining confidential data in competitive times
Richard Stiennon on Data Loss Prevention
Register here

1.) Heartland data breach aftershocks continue

The fallout from the major data breach announced in January from Heartland Payment Systems isn’t over. At least 250,000 merchants use the New Jersey-based payment processor, making it the fifth largest payment processor in the country. Millions of credit and debit card transactions were compromised in 2008 due to malicious software installed by hackers. I was recently informed by my bank that my account may have been compromised, and I was issued a new debit card. The aftershocks continue, with banks large and small reporting impacts.

2.) Kaspersky Lab pours cold water on claims of data breach by hacker

Officials at anti-virus vendor Kaspersky Lab are adamant that no data was stolen during a hack of its U.S. support site over the weekend. According to Kaspersky Lab, on Feb. 6, a hacker exploited a flaw on the Web site to launch a SQL injection attack. After Kaspersky officials received word of the breach Feb. 7, they took down the vulnerable site and replaced it. The security company maintained in a press conference Feb. 9 that no data had been leaked. However, the anonymous hacker behind the attack publicized table names purportedly taken from a Kaspersky database the hacker accessed.

3.) Don’t be a data loss victim

Somebody was siphoning customer financial data from a chain of gas station/convenience stores. The perpetrator covered his tracks so well that that the company which owned the stores didn’t even know it had a data breach until customers began complaining about experiencing fraud just days after using a credit card or writing a check at one of the stores. Verizon’s Business Investigative Response team was called in to try to unravel the mystery and track down the hacker. The team, led by managing principal Bryan Sartin, took forensic images of the systems at several store locations and did an in-depth analysis of the information.
4.) Seven ways to stop data breaches

The experts all say that data security goes beyond the use of technology. Nevertheless, there are numerous tools and techniques that IT professionals can use to improve their organization’s stance on data security.

5.) FAA says info on 45,000 workers stolen in data breach

The Federal Aviation Administration disclosed that it is investigating a data breach in which the personal data of about 45,000 employees and retirees was apparently stolen from a server at the agency.The compromise resulted from an intrusion into the system that was storing the data, the FAA said in a brief statement. There are no indications that any of the servers used for air traffic control or other operation systems were similarly broken into, the agency said, adding that it has contacted law enforcement authorities and will notify the affected individuals via mail.

6.) Six ways to protect your identity in a data breach

There’s an old Chinese proverb that says whoever steals an egg will steal an ox. Fast forward to the 21st century, replace “egg” with a credit card number and “ox” with your Social SecurityHow to protect your identity in a data breach number, and you’ve tapped into one of the biggest threats to the information age — identity theft. Identity theft — the act of having your personal and financial information stolen from you, often by cyber-means — is a burgeoning problem.

7.) Public Greets Massive Data Breach With Collective Yawn

Data breach laws in 44 states require companies to report the loss or theft of personal data, and such laws no doubt prompted Heartland’s revelation at 2008breach.com. But hundreds of other breaches slip by unnoticed by most consumers. Though intended to spur companies to follow strong security practices to safeguard sensitive data, the laws don’t seem to be achieving their purpose.

8.) With Great Amounts of Data Comes Great Responsibility

Keeping your customers’ data safe and secure means protecting against threats from both the outside as well as the inside. Implement layered security, monitor network traffic, and encrypt all sensitive data, recommends ESET’s Jeff Debrosse.

9.) Largest Coordinated ATM Rip-off Ever Nets $9+ Million in 30 Minutes

With only 100 compromised ATM cards thieves were able to grab $9 million bucks from the banking system in a new style of attack. Law enforcement sources told Fox 5 it’s one of the most frightening well-coordinated heists they’ve ever seen. “We’ve seen similar attempts to defraud a bank through ATM machines but not, not anywhere near the scale we have here,” FBI Agent Ross Rice told Fox 5. “We’ve never seen one this well coordinated,” the FBI said. How did the hackers steal $9 million in one 30-minute time period using only 100 ATM cards you ask? That shouldn’t be possible given the daily limits (usually about $500/day) placed on all ATM cards. Well it turns out that the hackers applied military like precision to old ATM Scam techniques and added a touch of devious ingenuity to pull this one off. Here is a look at how the theft was perpetrated.

10.) Survey: 40% of hard drives bought on eBay hold personal data

A New York computer forensics firm found that 40% of the hard disk drives it recently purchased in bulk orders from eBay contained personal, private and sensitive information — everything from corporate financial data to the Web-surfing history and downloads of a man with a foot fetish.

11.) Medical data leakage rampant on P2P networks

The risk of patient information disclosures on peer-to-peer (P2P) networks is much higher than if a health care worker loses a laptop or removable storage device, according to new Dartmouth College research. Over a two-week period, Dartmouth College researchers, in collaboration with P2P monitoring vendor Tiversa, searched file-sharing networks for key terms associated with the top ten publicly traded health care firms in the country, and discovered numerous sensitive documents – for example, a spreadsheet from an AIDS clinic with 232 client names, including Social Security numbers, addresses and birthdates.

12.) BitDefender partner site hit by hackers

Hackers elicited customer details from a Portuguese partner site associated with the security company BitDefender, the second intrusion in recent days targeting computer security companies. The hackers used a form of a SQL injection attack to reveal personal details and e-mail addresses. SQL injection, one of the most common types of attacks, involves inputting commands into Web-based forms or URLs in order to return data held in back-end databases.

13.) A down economy increases threat of data walking out the door

Moving into 2009, the number of layoffs and unemployed has multiplied as a result of the falling economy. Corporate data is at risk now more than ever and companies need to be sure they have reliable protection in place. As companies are forced to make layoffs, disgruntled employees may act maliciously and take sensitive company data with them as they leave. Out-of-work employees worried about finding a position in a bleak job market may also act out of desperation and steal confidential company information to get a leg up on the competition for hard-to-find jobs. It is also possible that companies hiring are accepting or even requesting internal data of their competitors as part of the hiring process.

14.) HP, IBM push new OASIS encryption key standard

A group of industry vendors, led by IBM, HP and EMC, is proposing a new standard to make their encryption management software work together. Called the Key Management Interoperability Protocol (KMIP), the standard is being proposed through OASIS (Organization for the Advancement of Structured Information Standards), the consortium best known for its development of Web-services standards. On Thursday, OASIS is expected to announce that it has created a KMIP Technology Committee to produce the final specification for the standard.

15.) First arrests made in Heartland data breach case

Three men have been arrested in Tallahasee, Fla., in connection with the Heartland Payment Systems data breach, authorities said. The men, Tony Acreus, Jeremy Frazier and Timothy Johns, each were charged with multiple counts of credit card fraud, police said. The arrests were part of a larger investigation into the breach, possibly the largest of all time, which was first disclosed in January.

16.) The Internet we have is just fine

Thanks to the New York Times and John Markoff for raising the question “Do we need a new Internet?” in a Valentine’s day article. The premise of the question is that the threats from hackers, cyber criminals, and even nation states have made the Internet a completely unsafe place. “Unless we’re willing to rethink today’s Internet,” says Nick McKeown, a Stanford engineer involved in building a new Internet, “we’re just waiting for a series of public catastrophes.” For all of the vulnerabilities in operating systems, applications, Internet protocols, and infrastructure my resounding answer to Mr. Markoff’s question is NO!

]]>
0
Administrator <![CDATA[Data Protection Weekly for November 10, 2008]]> http://it-harvest.com/blog/2008/12/01/data-protection-weekly-for-november-10-2008/ 2008-12-02T00:34:37Z 2008-12-02T00:34:37Z ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Data Protection Weekly
Update on encryption, device management, and leak prevention
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Is your loading dock your biggest data leak?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
blancco2

Once your new equipment has been commissioned and brought on line, do you have control of the data that is still on the old equipment? After all of the effort to protect network and equipment, data protection during equipment disposal or change of ownership is too often overlooked.

www.blancco.com

White House powned by Chinese
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
It is just too embarrassing. The Financial Times is reporting that the Chinese government has hacked successfully into the White House on several occasions. Chinese hackers have penetrated the White House computer network on multiple occasions, and obtained e-mails between government officials, a senior US official told the Financial Times. On top of the major hack on the Pentagon announced in 2007 this is just more evidence that the Chinese are engaging in a concerted effort to glean information from the US. Of course, Whitehall, the German Chancelary, France, India, Australia, and New Zealand have all been hacked as well. It might be time for the US to lodge a complaint with the Chinese government.

Read on…

Ex-AMD employee allegedly stole $1B Intel secrets
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
A former Intel Corp. engineer has been charged with stealing trade secrets worth $1 billion from the chip maker while he worked for its main rival, Advanced Micro Devices Inc. Federal prosecutors in Massachusetts alleged this week in a five-count indictment that Biswamohan Pani, 33, illegally downloaded more than a dozen confidential documents from Intel’s computer system in California during a four-day stretch in June. He had already resigned from Santa Clara, Calif.-based Intel, but remained on the payroll and still had access to the company’s computers while he burned unused vacation days.

Read on…

Express Scripts demonstrates best practices in handling a data breach incident
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Express Scripts, one of the largest pharmacy benefit management companies in North America, Sunday announced that it has received a letter from an unknown person or persons trying to extort money from the company by threatening to expose millions of the company’s patients’ records. Extortion is an old, old methodology for extracting funds from victims. In the cyber crime arena it has a history that pre-dates the Internet. During the twenty years before the Internet was commercialized over $600 million was paid to extortionists who stole account data from UK banks. They were either employees of those banks or had bribed insiders to print out account records. The banks would pay the extortion demands in order to avoid embarrassment and potential loss of brand. Banks of course rely on their brand of providing a safe and secure home for your money.

Read on…

Data security threats worst at home, expert says
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The threats to data security are most severe at home, a Seattle security expert told the Secure World Detroit conference at the Ford Conference and Events Center in Dearborn Wednesday. Gordon Mitchell, president of Future Focus Inc., told the audience of a couple of hundred IT security professionals how to “become a counterspy in three easy lessons.” Mitchell said good counterspies must figure out what information is valuable, think about who could be a spy, think likea spy would and protect the information. Companies and institutions are constantly surrounded by people who are spying on them, Michell said. The strategies can range from the sophisticated to the simple — like the biotech client that actually had an employee listening to board meetings by using a drinking glass up against a wall.

Read on…

Programmer charged for sniffer used in TJX breach
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
A New York programmer is charged with helping a group of hackers break into corporate networks to pilfer corporate data. Stephen Watt, 25, was charged in U.S. District Court with providing a modified sniffer program used to monitor and capture data, including customers credit and credit card information, as it traveled across corporate computer networks. Watt’s indictment is believed to be tied to the massive data security breach at TJX Cos. Inc. as well as several other retailers.

Read on…

British Government computer system shut down after data breach
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
When you hand over important details to the government, you expect a certain level of protection of that data. Unfortunately, it’s probably safer to give your details to a stranger in the street than trust the British Government to take care of them. The latest data breach saw a memory stick containing details of 12 million people found outside a pub.

Read on…

.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
safend2

Don’t let reductions in your workforce turn into yet another reason for critical data to walk out the door. Join Richard Stiennon, Chief Research Analyst, IT-Harvest, and Susan Callahan, SVP of Safend to learn how to protect your critical information during times of retrenchment and cut backs.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Reduce data breach risks with secure USB flash drives
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Imagine yourself in this position. It’s Monday morning, and your task is to go to your lead executive to let him know that an ambitious employee who wanted to get some work done over the weekend just reported that her USB flash drive was either lost or stolen from her desk. The drive contains downloaded medical and financial records for 1,200 patients with HIV, AIDS and other medical conditions.

Read on…

After laptop theft, Baylor Health warns of possible data compromise
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
HealthTexas Provider Network Inc., a subsidiary of Dallas-based Baylor Health Care System, is notifying about 7,400 patients of the potential compromise of their Social Security numbers and other personal information after a laptop containing the data was stolen in September. It is also contacting an additional 100,000 people whose records on the laptop contained a “limited amount” of health information — though not Social Security numbers, Baylor said in a statement yesterday.

Read on…

Up to 40,000 kids’ identities stolen from Phoenix DES in burglary
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Up to 40,000 children’s identities were stored on Department of Economic Security hard drives that were stolen from a storage unit in October. Now all those families may be at risk of identity theft. This affects anyone who has applied for or been accepted to DES’s “Early Intervention Program” over the past several years. This has the parents of those 40,000 children seriously concerned about their well-being.

Read on…

NC government computer with personal info stolen
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
A North Carolina health department’s stolen laptop contained personal information about some residents who are receiving government services. The Department of Health and Human Services said Wednesday the computer belonging to the Division of Aging and Adult Services employee was stolen on Oct. 25 in Atlanta.

Read on…

Avoiding costly data breach notifications
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Privacy Organizations spend serious money dealing with data breach notifications-millions of dollars that could be better spent on improving security procedures or technology, according to Bart A. Lazar, a partner with the law firm of Seyfarth Shaw. The CIO and the legal department can try and limit the risks associated with incident response while conserving resources, says Lazar. He offers five tips that shouldn’t break the bank.

Read on…

Preventing security breaches
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
A security breach is the last thing you want to have to deal with in any enterprise. If sensitive company data leaked outside, you’d already be past worrying about hardening firewalls and strengthening perimeters-by then it’s too late. According to Michael Rothschild, senior manager of enterprise solutions at Juniper Networks, “outside-in” attacks have been eclipsed by insider threats this year, which opens up a whole new attack vector (bypassing the perimeter security strategy). Rothschild says today’s hackers go far beyond hacking to attain notoriety and hack for profit instead. This puts corporate data, customer data, applications, and, indeed, the organization at risk.

Read on…

Card breaches shake faith in e-payments
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
In the past three months, all three of my payments cards — one credit card and two debit cards — have been compromised. That means somewhere, in some database, various fraudsters have my name and enough card details to attempt a shopping spree anywhere in the world. The cards have all been replaced by the issuers and, luckily, I never discovered any fraudulent transactions. The card breaches are particularly disturbing since I cover computer security. So what happened? I still have no clue. Investigating a card breach as a consumer, or a journalist, is a black hole.

Read on…

A&M-CC student data exposed
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
For the fourth time in two years and the second time in three months, a security breach at Texas A&M University-Corpus Christi has exposed students’ or former students’ Social Security numbers, university officials said Friday. Through an Internet search on the university’s Web site Monday, a student viewed a document that listed admissions applicants from 2005, A&M-Corpus Christi spokesman Marshall Collins said. The page listed 1,430 names and Social Security numbers.

Read on…

Charlottesville voter information at risk
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
After a bold break in at a voting precinct, the personal information for every registered voter in the city of Charlottesville is on the line. Two laptops containing voter registration information were stolen from a building at Tonsler Park in Charlottesville sometime after the polls closed Tuesday night. Charlottesville police say someone threw a cinder block through the door of the building and made off with the laptops.

Read on…

Clients’ data missing, Harvard Law warns
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Harvard Law School is alerting thousands of clients from a legal services clinic after a computer tape containing their Social Security numbers, addresses, and financial information was lost in September. The personal information, dating back 10 years, belonged to about 21,000 people who sought help through the school’s legal services center in Jamaica Plain, Robert London, a school spokesman, said yesterday. About 8,000 records of present and former clients contained Social Security numbers; another 13,000 had other identification information.

Read on…

Contact Information
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
email: news@it-harvest.com
advertising inquiries: karen@it-harvest.com
web: http://www.it-harvest.com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

]]>
0
Administrator <![CDATA[About]]> http://it-harvest.com/blog/about/ 2009-02-21T19:03:56Z 2008-11-06T02:50:19Z IT-Harvest is an independent IT research firm founded by Richard Stiennon. We focus on the IT security space and provide coverage of the 1,200+ vendors that provide security products and services to the enterprise. We follow the new model of an analyst firm in that all of our research is published on this site at no charge. Most of our clients are security vendors who hire us to generate leads through speaking events, webinars, and special video productions. We also provide strategic consulting services to companies in the security space and those that are making acquisitions in order to enter the security field.

IT-Harvest is the publisher of the popular security blog ThreatChaos.com, a destination site for security news, our analysts’ insights, video productions and more to come!

For more information on any of these services or to schedule a call with an analyst contact Richard Montoya, Sales Director.

Email: richard.montoya@it-harvest.com
Phone: 203-826-7056

]]>
0
Administrator <![CDATA[Contact]]> http://it-harvest.com/blog/contact/ 2009-02-21T19:01:05Z 2008-11-06T02:05:28Z IT-Harvest LLC
330 East Maple Rd
#406
Birmingham, MI 48009

Skype: Stiennon
Twitter: www.twitter.com/stiennon
email: Richard Stiennon at richard@it-harvest.com
phone: 650-388-6402

Business: Karen Ethier karent@it-harvest.com

For more information on any of these services or to schedule a call with an analyst contact Richard Montoya, Sales Director.

Email: richard.montoya@it-harvest.com
Phone: 203-826-7056

]]>
0
Administrator <![CDATA[Services]]> http://it-harvest.com/blog/services/ 2009-02-21T18:58:53Z 2008-11-06T02:00:49Z IT-Harvest provides services to IT security vendors and end users. These services include:

Analyst Access. One of the most effective ways to interact with IT-Harvest is through an annual contract that provides continuous access to our analysts. Clients have the analysts’ cell phone number and can engage the analyst through email, IM, and phone. Monthly email updates to clients make them aware of editorial calendars, industry movements, and marketing guidance.

Speaking engagements. These may take the form of a key note address to a sales kick-off meeting, customer advisory board, or prospect breakfast seminar. We have engaged in multi-city speaking tours on six continents. Talk to us about how we use our industry demand tools to drive attendance!

Webinars. The best way to draw attendance and engage with your prospects is to hire a knowledgeable, exciting speaker with a world wide reputation. IT-Harvest can provide that speaker and also help drive attendance with a custom outreach program.

Strategic engagement days. Bring the analyst to your facility for a day of give and take. Your product marketing team, executives, and sales leadership can benefit from an outsider’s perspective on your company direction.

Video product data sheets. This is a new service offering. Have an industry renowned analyst create a 10-12 minute video introduction to your product.

Video case study. Instead of a white paper your prospects can view a 12-15 minute case study produced by IT-Harvest. We go to one of your customer’s sites and interview the decision maker about the particular problem you solved for them. It is a compelling way to get prospects’ attention, educate them on your value proposition, and generate actionable leads.

For more information on any of these services or to schedule a call with an analyst contact Richard Montoya, Sales Director.

Email: richard.montoya@it-harvest.com
Phone: 203-826-7056

]]>
0
Administrator <![CDATA[Data Protection Weekly published June 30, 2008]]> http://it-harvest.com/blog/2008/06/30/data-protection-weekly-published-june-30-2008/ 2008-07-02T22:13:51Z 2008-06-30T19:27:41Z Sign up for Free Newsletter: Data Protection Weekly.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Data Protection Weekly

Update on encryption, device management, and leak prevention

June 30, 2008

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~





This week's DPW sponsor: SECCOM GLOBAL

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

seccom logo2

Looking for managed UTM?

Contact Seccom Global, an MSSP dedicated to
supporting Fortinet Unified Threat Management
appliances. Get managed AV, firewall, IPS,
VPN, anti-spam, anti-spyware, and URL
filtering for one affordable rate.
We make UTM work.

www.seccomglobal.com





The staff, the thief, the device and its data

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Data being leeched from company databases by
less secure mobile devices is a common
occurrence, making data leakage the big
technology issue of 2008. With the increasing
use of mobile phones, PDAs and laptops as
work tools, important company data is removed
from the office every day. This increase in
data sharing promotes an environment suitable
for data leakage and is aggravated by the
associated use of hot-desking, home working
and wireless hotspots. It is further
complicated by the shuttling of data back and
forth between staff on USB sticks, CDs, DVDs,
backup tapes and even iPods. As a
consequence, security breaches are on the
increase.

Read on...





What privacy policy?

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Want to know how well a company protects its
customers' data? Don't talk to its security
and compliance officers. Instead, try its
marketing department. A study released Monday
by the privacy-focused Ponemon Institute and
funded by e-mail marketing firm Strongmail
reveals a disturbing disconnect in companies
between the executives tasked with protecting
customer data and marketing departments,
which use the data for advertising purposes
or share it with third parties.

Read on...





CNET employees notified after data breach

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

More than 6,500 CNET Networks employees and
relatives are being notified of a possible
data breach after burglars stole computer
systems from the offices of the company that
administers the Internet publisher's benefit
plans. CNET was one of several clients
affected when burglars broke into the Walnut
Creek, Calif., offices of Colt Express
Outsourcing Services, stealing equipment
"which contains the human resources data of
several of their clients including CNET
networks," CNET Senior Vice President of
Human Resources Jose Martin said in a June
letter notifying employees of the incident.

Read on...





Virgin Media loses 3,000 customer bank details

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Virgin Media has confessed to losing the bank
details of 3,000 new customers last month.
The company is currently phoning the affected
customers and has contacted all but a few
hundred. All the customers involved have
been offered credit file protection, in
essence a close watch on all their financial
transactions, and automatic indemnity should
a theft occur. The lost data concerned
customers who signed up for Virgin Media
services at Carphone Warehouse. Unencrypted
bank account details were recorded to a CD
and transferred by hand between Virgin Media
headquarters and another office. During the
journey, on 29 May, the CD was lost.

Read on...





Data breaches top the agenda at RSA conference

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Data breaches remain a significant problem
for any company that manages information
about personal identity. In recent weeks,
widely publicized data breaches have hit
Lending Tree, Hannaford Bros. Co., and the
Bank of Ireland. Past data breaches at
ChoicePoint, TJX Cos., and the U.S.
Department of Veterans Affairs have resulted
in large, class-action lawsuits with claims
for or settlements in the millions of dollars
in some cases. At the April RSA Conference
in San Francisco, a number of speakers
addressed the technical and legal aspects of
the data breach problem.

Read on...





'I have a lost laptop horror story for you'

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I used to work for Boeing in Wichita. Boeing
sold the Wichita division and all of the
workers, including me, to another company. We
still did the same work, but Boeing was just
one customer of several. Nearly a year after
the sale, someone at Boeing lost a laptop
that had the names, addresses and Social
Security numbers of nearly all of the 12,000
Wichita ex-employees on it. They waited an
unknown period of time before telling anyone,
then another couple of weeks before they
offered to pay for credit reporting
subscriptions for us. They offered no
compensation for people that had been actual
identity-theft victims and they wouldn't pay
for identity-theft insurance. Almost
immediately after the laptop went missing,
someone used my SSN to apply for credit cards
all over the country.

Read on...





Survey rats out data UK data losses

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

The loss or theft of private or confidential
data is endemic amongst UK firms, according
to research released today. The survey of
over 900 UK data protection professionals and
marketing professionals conducted by the
Ponemon Institute found almost two-thirds (61
per cent) had experienced a data breach
involving the loss or theft of consumer
information over the past 24 months. Worse
still, 90 per cent of these data breach cases
went unreported to customers, as the
organisation felt that they were either not
required to do so, or were unsure whether
they had to.

Read on...





Third of IT admins admit snooping with privileged passwords

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

One in three IT administrators say they or
one of their colleagues have used top-level
admin passwords to pry into confidential or
sensitive information at their workplace,
according to a survey by a
password-management vendor. Nearly half also
confessed that they have poked around systems
for information not relevant to their jobs.

Read on...





Data breach at Tampa Bay area bank

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Customers of one Tampa Bay area bank should
check their bank statements and apply for a
new debit card after a data breach last week.
Bank Atlantic confirms they had a data loss,
involving their MasterCard debit cards. A
spokesperson says it happened through a local
merchant, but at this time, isn't saying
which one.

Read on...





Theft prevention: Five security risks for health care

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

The recent wave of identity theft is
especially evident at health care facilities,
where a stolen computer could potentially
contain the most personal of information for
thousands of people. Through its work with
health care organizations, Absolute Software
identified the computer security risks most
often faced by hospital systems, health
management organizations and others with
responsibility for electronic protected
health information. Here's a rundown of each
risk area.

Read on...





Preventing data breaches not a technology issue

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

When security people see headlines about data
losses at TJ Maxx, ChoicePoint, DuPont, and
the Department of Veterans Affairs, they
quickly assume that preventing such loss is a
technology problem. It clearly is not. It is
an information problem. Organizations know
that protecting their clients' or employees'
data is paramount and that the risk of not
protecting it is a story in the Wall Street
Journal. However, underneath the public
thunder about the loss of credit card and
social security numbers and healthcare
information, even more confidential
information is at risk.

Read on...





HMRC slammed over major data breach

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Serious institutional deficiencies at HM
Revenue and Customs were to blame for
Britain's worst-ever breach of personal data
security, when details of 25 million people
were lost in the post, according to two
reports. Investigators from the Independent
Police Complaints Commission found that HMRC
procedures for handling sensitive data were
"woefully inadequate" and staff adopted a
"muddle through" ethos to confidential
personal records. And a separate report by
consultant Kieran Poynter found that last
October's loss of two computer discs
containing the names, addresses and bank
details of every child benefit claimant in
the country was "entirely avoidable" and
raised "serious questions of governance and
accountability" at HMRC.

Read on...





Retailer wards failed to notify customers of data breach

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Trusted old-name retailer Wards did not
inform its customers of a data breach that
allowed hackers to gain access to at least
51,000 records, including credit card
numbers. The breach occurred at the store's
parent company, Montgomery Ward, where
hackers looted the database that held account
information for all of the firm's retail
properties.

Read on...





Consumers punish organizations that expose their data, but can be mollified

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Organizations that expose consumer data pay a
big price in consumer confidence, but can
satisfy most customers by offering them
fraud-prevention services, according to a
survey of more than 400 data breach victims
by research and consulting firm Javelin
Strategy & Research. 55% of survey
respondents say they have less confidence in
the organization that exposed their data and
30% says they would never buy from that
company again, according to the online survey
conducted in May. 40% of respondents whose
information was exposed but had not become
victims of identify theft say they think the
breach leaves them more vulnerable to
criminals misusing their personal information.

Read on...





Liberty releases guidelines for data management, handling

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

The Liberty Alliance has released the first
versions of two key frameworks for how
businesses can share and protect sensitive
data in their networks. The Liberty Alliance,
a coalition of businesses and other
organizations, has worked to develop
protocols and policies for federated identity
and Web services, which have the potential
for new efficiencies in data handling but
come with many risks if data is lost or
mishandled.

Read on...



Contact Information

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
advertising inquiries:
karen@it-harvest.com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Forward email


Safe Unsubscribe

This email was sent to karen@it-harvest.com, by news@it-harvest.com


IT-Harvest | 330 East Maple Rd | #406 | Birmingahm | MI | 48009



]]>
0
Administrator <![CDATA[Hello world!]]> 2005-12-14T22:44:43Z 2008-06-30T12:19:59Z Welcome to WordPress. This is your first post. Edit or delete it, then start blogging!

]]>
1