Archive for the ‘Data Breaches’ Category
Monday, June 1st, 2009
It is certainly true that most of those involved in the creation of IT standards are from large organisations. It is also true - as Steve Burrows says - that it can be challenging for an SME to implement a standard such as the ISMS standard, ISO/IEC 27001, for information security management.
However, all standards are explicitly designed for organisations of all sizes. ISO/IEC 27001, for instance, is clear that its requirements should be implemented in a way that is appropriate for the organisation; certainly the selection of controls will be driven by a risk assessment and, if the management of an SME has a high appetite for risk, it won’t find itself selecting many controls.
The reality is that all organisations are subject to similar types of risks; an impact (like the loss of a server for a week) that could severely disrupt an SME might not even bother a larger, multinational organisation. Organisations need to select and implement controls that will protect them from impacts they wish to avoid - and the management system they put in place will be very similar to that put in place by a much larger organisation to manage much larger impacts.
The issue isn’t really the IT standards; the real issue is the resources that SMEs have available to tackle them. Few SMEs will have the capability to plan and carry out an appropriate implementation of something like an ISMS - which, of course, is why we developed our FastTrack ISO27001 Implementation Service for organisations that have 19 employees or fewer, and why our classic consultancy service (with its 100% guarantee) is helping more and more SMEs implement appropriately scaled information security management systems that enable them to cost-effectively meet customer compliance requirements and to challenge larger competitors in their space.
Posted in Compliance, Data Breaches, ISO 27001, ISO 27002 (ISO 17999), IT Security | 1 Comment »
Friday, May 15th, 2009
While I’m probably more interested in governance than the average person, I do sometimes worry that contextualising information and compliance challenges as governance issues can delay organisations from taking the obvious, common-sense action.
This intelligent article on mobile security governance, for instance, identifies all the steps that organisations should take in considering risks to data posed by the mobile network. See how far you have to read through it before you find guidance to apply encryption to key mobile devices - all laptops and any USB sticks or PDAs that carry sensitive information. The sensible approach is to first apply encryption, which deals with the largest number of mobile device-related risks while keeping you within regulatory requirements, and then to stop and consider what other risks might need mitigation.
You don’t want to have to tell 1,000s or millions of customers or members of staff why someone leaving a laptop at the busstop has exposed all their personal details to fraud and identity theft. Explaining that you were considering the range of risks before deciding what action to take is likely to elicit the same sort of response as a UK MP explaining that their inappropriate expense claims were ‘within the rules’.
Posted in Business Continuity, Business and the Economy, Compliance, Data Breaches, Data Protection, ISMS, ISO 27001, IT Governance, IT Security, Mobile Devices, White Collar Crime | No Comments »
Wednesday, October 22nd, 2008
I’ve been of the view, for some time, that effective corporate information security will only come to pass when company directors are prosecuted, fined and jailed for failures to implement and maintain effective information security management systems.
Here are two stories that rather illustrate the point:
And it’s all actually quite straightforward - implement ISO27001, obey the Data Protection Act, and have happy customers, staff and regulators!
Tags: Data Breaches, dpa, iso27001
Posted in Compliance, Data Breaches, Data Protection, ISO 27001, IT Security | No Comments »
Monday, October 13th, 2008
I think it’s a great pity - but clearly unavoidable - that the FSA has arrived at the view that it will have to fine individual board-level executives of retail banks if it is to get them to take adequate measures to protect customers’s information. I think this is excellent news - particularly the clear statement that ‘FSA wants to avoid executives palming off overall security responsibilities onto the IT department. Chief executives, compliance officers and board-level IT directors could all be held responsible.’
One would have thought that banks might have spotted that protecting customer information might be a fundamental part of customer care in this identity-theft age but, then again, I guess we might have expected banks to have spotted that it might not make sense to lend someone of limited income 130% of the already-inflated value of a house.
A number of UK banks have been - or are about to be - taken into public ownership. The UK government doesn’t exactly have a great track record (eg HMRC, MOD, etc) when it comes to protecting personal data, either. So we have to hope that the FSA will have the courage to fine the government-appointed directors of nationalised banks where they fail to ensure their organisation takes adequate steps to protect personal data - or the protection of personal data in the UK will just become even more difficult.
Tags: Add new tag, banking crisis, Data Protection, dpa, fsa
Posted in Business and the Economy, Compliance, Data Breaches, Data Protection, ISO 27001, IT Governance, IT Security, White Collar Crime | No Comments »
Wednesday, October 8th, 2008
When financial markets appear to be in free fall, many organisations might think that data protection is the least of their worries. Who cares, they might wonder, about protecting personal data if tomorrow we might not exist any more? (And, from what we’ve seen over the last few weeks, the ‘might not exist tomorrow’ possibility should be a very real planning scenario for all but the world’s best-capitalised banks).
Well, in the UK, the Information Commissioner is unlikely to cease caring - already identified as “setting the political and administrative agendas for the protection of personal data in this century in the UK” and for “firmly disciplining politicians, civil servants, the media and business folk into line”, he’s unlikely to allow data protection to take a back seat at exactly the moment that spammers are expected to take advantage of bank buyouts to launch new phishing scams.
However, we’re talking here about banks who were unable to identify or adequately manage some rather more obvious risks to their business (like, if you lend someone 130% of the value of his collateral, and if his current cashflow is insufficient to pay the interest let alone repay the principle, how do you expect to survive?) than those around personal data. So, if you’re a bank customer, it might not be wise to hope that, in the midst of all this turmoil, your personal data will be adequately protected. The facts speak for themselves: US organisations are on track to report at least 680 data breaches by the end of 2008, affecting more than 30 million records.
It is clearly the case that, with personal data, one can only rely on oneself to protect it!
Tags: Add new tag, bank failures, Data Breaches, dpa, phishing
Posted in Business and the Economy, Compliance, Data Breaches, Data Protection, ISO 27001, IT Security | 2 Comments »
Tuesday, October 7th, 2008
Apparently, we’re today kicking off the UK National Identity Fraud Prevention Week - and research for RSA reveals wide-spread disbelief (as in, 90% of Britons) that their personal data are safe with banks and retailers, and half the people think that not enough is done to protect these personal details.
That’s better than I thought! Let me explain: in today’s insecure world, everyone has to be concerned about his or her own personal data - this is a critical personal asset that needs safeguarding. And, for far too long, people have simply not been adequately concerned about this issue. Clearly, this is changing - let’s hope that, as more people learn about the poor care exercised by data controllers in the UK, they get better at insisting that adequate steps are taken - and voting with their feet where they are dissatisfied with the standard of care.
From an organisational point of view, of course, it’s not hard to respond to the findings of this research - take adequate steps, today, to comply with the Data Protection Act in the UK, or whatever data protection legislation applies in your business jurisdiction. If you accept payment cards, PCI DSS compliance should be a given. And, for every organisation, ISO27001 is the best practice standard for securing information - and this week would be a good week to get started on an ISO27001 project!
Tags: Data Breaches, data protection act, dpa, Identify Fraud, identity theft, iso27001, pci
Posted in Compliance, Data Breaches, Data Protection, ISO 27001, IT Security, PCI DSS | No Comments »
Friday, October 3rd, 2008
Well, that’s a relief - the UK government has caught up with the fact that there are criminals on the Internet. The government has said that it will spend £7 million to establish the Police Central E-crime Unit (PceU) in London, that it will be run by London’s Metropolitan Police and will be more than half-funded by the Met.
I’m not going to waste time talking about the fantastic stupidity of creating and then, after three years, disbanding the High-Tech Crime Unit (creating SOCA, the Serious and Organised Crime Agency, whose priorities were drugs, people smuggling and similar more ‘traditional’ crimes) just as serious criminals migrated to the Internet. I am, though, going to make the obvious point that, even if the PceU does get going fairly early in 2009, it will still be something like two years before it will start being effective - it just takes a long time to get a new organisation (particularly a publicly-funded one) working, to get objectives and modi operandi and personnel and media and all those things properly sorted. And, in that time, cybercrime will become more sophisticated and the challenge of controlling it even more complex.
Let me put it another way: establishment of the PceU will be no panacea, anytime soon, for cyberthreats. Sensible organisations are just going to have keep on doing their own risk management around this issue.
Tags: cybercrime, information security, pci, White Collar Crime
Posted in Data Breaches, Data Protection, ISO 27001, IT Security, PCI DSS, White Collar Crime | No Comments »
Wednesday, October 1st, 2008
Virgin is a strong brand, so a welter of stories describing Virgin Media’s breach of the Data Protection Act, when it lost an unencrypted disc containing the details of some 3,000 customers, would not have been part of the PR strategy. As a result of a simple management failure - not requiring the encryption of all portable media that contain personal data - it now finds its name and brand logo alongside statements that Virgin Media has been guilty, ‘scolded, ‘reprimanded‘, ‘slammed‘ and ‘rapped‘ for inadequately protecting its customers’ data. Not a pretty outcome!
There is a simple way to avoid this sort of damage - encrypt all portable media! We wrote about this in our Data Breaches Report 2008 and, after the HMRC fiasco, one would have thought that all organisations would, at least, have carried out the encryption part of our recommendations.
Tags: Add new tag, Data Breaches, data protection act, dpa
Posted in Data Breaches, Data Protection, IT Security, Mobile Devices | 2 Comments »
Monday, September 29th, 2008
I wish that I was surprised by Logica’s survey findings, that 57% of firms had ‘no understanding of the impact of a security breach on their organisation.’
And the sad fact is that, in a number of these ‘unaware’ organisations, the first that the board will know about their compliance shortfall will be when they’re hit with a ’signficant’ fine under the recent amendment to the Data Protection Act.
And that’s a pity, because DPA compliance really isn’t that hard: there are just 8 principles and, so long as the organisation tackles those 8 principles intelligently and constructively, it’s unlikely to find itself facing any breach proceedings. We’ve done what we can to make it easy for people to understand the size of the problem (our Data Breaches Report 2008), to get a straightforward understanding of the compliance requirements (our DPA Compliance pocket guide, written by DPA experts), to assess their current state of compliance and what steps to take (our DPA Compliance Assessment Tool) and we’ve even developed a DPA Compliance Toolkit that contains the key documentation for compliance.
But we can’t do that essential first step: care enough about the personal information of your staff, your customers and your suppliers to take adequate steps to meet your compliance obligations. Don’t wait until you’re staring down the barrel of an ICO enforcement notice before you take what will then be expensive and possibly disruptive steps to get a compliance regime into place as quickly as possible.
Tags: data protection act, dpa
Posted in Compliance, Data Breaches, Data Protection, IT Security | No Comments »
Thursday, August 7th, 2008
Lots of organisations think they don’t need to worry about theft of credit card data. I don’t know why. Payment card data theft is now big business - the level of professionalism available in this industry includes the development of bespoke software supported by an extremely efficient helpdesk and you don’t usually get this level of specialization until the industry is starting to mature.
Apart from the interesting fact that darkside helpdesks appear to be more efficient than many over on this side, you have to wonder why every organisation that accepts payment card data isn’t already at least PCI DSS compliant? Why hasn’t the PCI Security Council already come up with some form of ‘PCI DSS Compliant’ badge and certification scheme so that paying customers can concentrate all their business on the websites and businesses of those organisations that have actually bothered to do what it takes to protect their card holder data?
Tags: Data Breaches, data security, PCI DSS
Posted in Data Breaches, Data Protection, IT Security, PCI DSS | 2 Comments »