Showing posts with label Encryption. Show all posts
Showing posts with label Encryption. Show all posts

Friday, January 6, 2012

Compliance and Protection are NOT Synonymous

Much of the focus in the Data Loss Prevention market is on questions such as  "How do I pass a PCI audit?" or any kind of data security/privacy audit for that matter. While not passing an audit can be costly in the form of  penalties and upgrades it can also lead to a myopic view of data security. 


Beyond compliance lies much more.  Passing an audit with flying colors can still mean an organization's data is vulnerable to a variety of evolving attack vectors such as the much publicized "zero-day attack." In a zero-day attack a hacker exploits computer application vulnerabilities that are unknown to others or the software developer. These vulnerabilities are shared with other hackers and used as a way to gain entry to an organizations network. 


How should an organization protect themselves from zero-day attacks and other attack vectors? One way to do this is by taking a data-centric approach to protecting corporate information assets. Voltage Security President and CEO Sathvik Krishnamurthy recently discussed his idea of what a data-centric approach entails:
"From the very first point of entry, the data, structured or unstructured, is encrypted. As it is used across data centers, public and private clouds and mobile devices—in use, in transit, or at rest—it remains encrypted. That’s important because in the event of a breach, the theft of data is minimized."
The idea of encrypting all data across an organization gives many IT managers a headache. The thought of managing the encryption keys with the use of a key database that stores copies of every key ever issued and and having to make changes to existing structure according to how the database behaves can be costly and create undue pressure on IT management and create oppressive overhead. These operational barriers have made encryption an impractical and expensive option for large scale deployments.


Fortunately, there is a solution that makes key management less cumbersome and more practical. Voltage Security has released a Stateless Key Management system that securely and mathematically derives any key, as required by an application, once that application and its users have been properly authenticated and authorized against a centrally managed
policy. Voltage Stateless Key Management reduces IT costs and eases the IT administrative burden by:

  • Eliminating the need for a key database, as well as the corresponding hardware, software and IT processes required to protect the database continuously or the need to replicate or back-up keys from site to site.
  • Easily recovering archived data because keys can always be recovered.
  • Automating supervisory or legal e-discovery requirements through simple application APIs, both native and via web services.
  • Maximizing the re-use of access policy infrastructure by integrating easily with identity and access management frameworks and dynamically enforcing data-level access to data fields or partial fields, by policy, as roles change.


Thursday, November 17, 2011

Sacramento Health System Breached - 4.2 Million Records


Two branches of the Sutter Health network were breached in October of this year after an employee's laptop was stolen. The laptop contained databases with Personally Identifiable Information and Personal Health Information for 4.2 million patients. These records are from dates as far back as 1995 and as recent as this year.  Sutter does say that the employee's laptop was not encrypted even though they are currently in the process of encrypting all laptops across the enterprise. 

Data stored in an unprotected state on a laptop or desktop PC puts organizations at risk of becoming the next data breach headline, like Sutter. Only strong encryption of all data on hard disks counters the threat of losing critical intellectual property, customer and/or competitive information and provides a safe harbor from the high profile public disclosures and costly remediation mandated by privacy laws. To protect mobile data from the risks of loss or theft of a laptop or desktop, enterprises not only need the security provided by strong encryption, but also a standards-based solution to the practical issues that organizations encounter when deploying endpoint data protection.


Sutter Health network of care press release below: 

/PRNewswire/ -- Sutter Physicians Services (SPS) and Sutter Medical Foundation (SMF) — two affiliates within the Sutter Health network of care — announced the theft of a company-issued password-protected unencrypted desktop computer from SMF's administrative offices in Sacramento the weekend of Oct. 15, 2011. Following discovery of the theft, Sutter Health immediately reported it to the Sacramento Police Department. It also began an internal investigation. The computer did not contain patient financial records, social security numbers, patients' health plan identification numbers or medical records. While no medical records themselves were on the computer, some medical information was included for a portion of patients.

Following a thorough internal review, Sutter Health discovered that the stolen computer held a database that included two types of information:
  1. For approximately 3.3 million patients whose health care provider is supported by Sutter Physician Services (SPS), the database included only the following patient demographic information dated from 1995 to January 2011: name, address, date of birth, phone number and email address (if provided), medical record number and the name of the patient's health insurance plan. SPS is an organization that provides billing and managed care services for health care providers with which it contracts, including facilities within the Sutter Health network. Patients who think they may be affected should visit www.sutterhealth.org to see the list of impacted health care providers.
  1. For approximately 943,000 SMF patients, the database contained the above demographic data as well as the following information dated from January 2005 to January 2011: dates of services and a description of medical diagnoses and/or procedures used for business operations. Because the data of SMF patients was broader in scope, Sutter Medical Foundation has begun the process to notify these patients by mail. Patients should receive letters no later than Dec. 5.

Read more: http://www.sacbee.com/2011/11/16/4059251/sutter-health-informs-patients.html#ixzz1dyUMTGrj

Monday, August 22, 2011

Hacking Group Anonymous Breaches InfraGard

On August 18th hacking group Anonymous published documents stolen from Richard Garcia, senior vice president of Vanguard Defense Industries. The collection of documents contains internal meeting notes and contracts, schematics, non-disclosure agreements, personal information about other VDI employees, and several dozen 'counter-terrorism' documents classified as 'law enforcement sensitive' and 'for official use only.'


Mr. Garcia is also a director of U.S. defense contractor InfraGard, who was breached by one of Anonymous' affiliate hacking groups LulzSec. In the initial post by Anonymous, they state that Mr. Garcia's account was easily hacked because he had not changed some of his passwords after the InfraGard breach in June.


One of the most sensitive emails that was published contains a response from one of Vanguard's chief executives responding to a U.S. Department of Justice contact regarding the suitability of its ShadowHawk drones for use by U.S Marshals. There are also reports that there are documents that show evidence of a Merrill Lynch wealth management adviser giving private advance notice to Garcia about upcoming S&P US credit rating downgrades. This report has yet to be substantiated.



Wednesday, June 22, 2011

Mansfield, Ohio -- Area Agency on Aging: Breached due to Lost Laptop

On June 3, an employee of the Area Agency of Agency in Mansfield, Ohio had a laptop stolen from their car. This resulted in the exposure of personal data related to 43,000 customers.  The laptop was assigned to a Passport case manager. The personal data was health related in nature and also contained the  personal contact information of 35,000 related clients' personal representatives.  


According to a report in The Morning Journal  the Area Agency on Aging had the following response to the Breach:


“The Area Agency on Aging understands the importance of safeguarding our consumer’s personal information and takes that responsibility very seriously,” said Duana Patton, chief executive officer. “We deeply regret that this incident occurred, and we have already taken steps to ensure our laptops are properly equipped to secure personal information from unauthorized access in the future.” 


Unfortunately many organizations take a reactive approach to encrypting endpoint devices such as laptops and cell phones that may contain sensitive information. 


Oil giant BP, had a similar incident this spring in which an employee lost their laptop during routine business travel. The laptop contained  unencrypted personal data such as names, social security numbers, and dates of birth for over 13,000 people who submitted claims with the company after last years oil spill. 


According to Ponemon's "Cost of a Lost Laptop" report, a lost or stolen, unencrypted laptop, will cost an organization $20,000 more than if an encrypted laptop is lost or stolen. Read the full Ponemon report here: Cost of a Lost Laptop Study - Ponemon

77% Of Business Experienced Data Loss Last Year

A survey of over 2,400 IT security administrators conducted by Check Point and Ponemon reveals 77% of businesses experienced data loss last year. This number does not correlate with the number of reported breaches, but with increasing stringency of compliance regulations, we may begin to see more and more reported breaches.

The study’s research shows organizations are struggling with the growing set of security priorities and limited employee awareness about corporate security policies. Over 55 percent of companies surveyed are using more than seven vendors to perform security tasks. Because of this, organizations struggle with minimizing TCO and maximizing performance.

Approaching security with a holistic view of an organization’s technology is the first step in enforcing better protection. This helps to determine where risks can reside. Security is more than a simple technology solution. Aligning IT security with business needs requires a combination of policies, people and enforcement.

Thursday, May 5, 2011

Epsilon Breach Estimated to Cost $4B


The highly publicized data breach of email service provider Epsilon could cost the organization upwards of four billion dollars. This estimate comes from a report done by cyber risk advisory firm CyberFactors, and is dependent on what is done with the data.
               
According to CSO.com
"That figure [$4 billion] could be reached if criminals get hold of the email addresses and successfully exploit them to gather more personal information and carry out a spear-phishing blitz, according to the report. 'However, until such an event takes place and can be directly linked back to this specific breach, the estimate remains theoretical, but certainly possible given the multitude of sites that use email addresses as user IDs,' the report says."
The report goes on further to estimate that the Costs to Epsilon's customers could be $5.5 million each for notification of their customers about the theft, settlements to those customers, legal defense, compliance adjustments and loss of business.

In contrast to this report CEO of Alliance Data Systems, Epsilon's parent company, Ed Heffernan says he sees no meaningful cost or liability stemming from the incident and that they will not see the customer churn that often follows a breach. 

Although Heffernan believes he will not see significant costs as a result of the breach, the widely known act could hold weighty impacts to Epsilon and even Alliance Data’s brand. If Epsilon is lucky, the company has the potential to escape any non-compliance fines, but this does not mean they will be free of detrimental brand impact. Brand losses are approximately 49% of the cost of a data breach and Heffernan may not be taking this into account when he states that the cost will not be meaningful.

If you were a company who needed third party email services, would you want to do business with a company that had more than a million customer records at risk? Probably not.  A tactical data loss prevention strategy may have saved this company, and those customers affected by the breach the trouble this breach has presented.

Wednesday, March 30, 2011

Lost Laptop Exposes 13,000 Oil Spill Victims

According to a BP spokesman the laptop was lost on March 1 by an employee on routine business travel.


The laptop held unencrypted information including the names, Social Security numbers, addresses, phone numbers, and dates of birth of people who filed claims related to the Deepwater Horizon accident that occurred last spring.


"The lost laptop was immediately reported to law enforcement authorities and BP security, but has not been located despite a thorough search," BP said Tuesday. They added that the device was equipped with a tool that would allow them to disable the system under certain circumstances. No further details on the nature of the circumstances that would be required to be met were given.


Unfortunately lost laptops containing sensitive personal data are lost every day, and even more commonly when traveling. In Ponemon's "Billion Dollar Lost Laptop Study" the institution found that of laptops lost 46% contained confidential data, and only 30% of those laptops were encrypted, as shown below. Encryption is not the only method used to protect confidential data on a laptop, but it is one of the most easily implemented and trusted ways to protect your company's and customer's sensitive data.




Wednesday, January 12, 2011

Hot Topic: Smartphone Security

Cell phones have come a long way, from the Gordon Geckko 80's brick phone to today’s smartphones which are essentially pocket-sized computers.  Cell phones are no longer "just" a phone, they help us organize our lives, stay in touch via social networking, waste time. As more and more people adopt "smartphones" it is becoming an enticing frontier for hackers everywhere. Smartphone security is going beyond protecting against physical loss.  Many organizations that have employees who use smartphones to store company data often overlook simple security measures that are standard for any laptop or any other device with access to the internet.  

There are many companies that see this space for what it is, a relatively un-penetrated market with room for growth. Virtualization giant VMWare has partnered with smartphone manufacturer LG and they have begun building a smartphone with two virtualized machines, one for work and one for personal usage. These machines would be completely isolated from one another and allow an organization to support, distribute, and secure one type of smartphone while allowing employees to use the phone for personal use as well without risking exposing company data. Internet security firm Check Point Software found in a global survey that 64% of organizations are concerned that the growth in remote users will result in exposure to sensitive data and as a result are looking to encrypt and protect mobile devices. Smartphone manufacturers have also begun building proprietary encryption for their phones, or partnering with encryption companies. The gold standard for secure, encrypted smartphones is Blackberry which has been deemed secure for use in some of the highest levels of government.

Moral of the story is, protect yourself against these developing threats by installing anti-malware software on your smartphone and beware inherent threats when downloading mobile apps and clicking on mysterious links on social networking sites. Treat your cell phone like you treat your laptop, after all, the delineation between these devices is getting fuzzier and fuzzier.