Showing posts with label Ponemon. Show all posts
Showing posts with label Ponemon. Show all posts

Wednesday, June 22, 2011

Mansfield, Ohio -- Area Agency on Aging: Breached due to Lost Laptop

On June 3, an employee of the Area Agency of Agency in Mansfield, Ohio had a laptop stolen from their car. This resulted in the exposure of personal data related to 43,000 customers.  The laptop was assigned to a Passport case manager. The personal data was health related in nature and also contained the  personal contact information of 35,000 related clients' personal representatives.  


According to a report in The Morning Journal  the Area Agency on Aging had the following response to the Breach:


“The Area Agency on Aging understands the importance of safeguarding our consumer’s personal information and takes that responsibility very seriously,” said Duana Patton, chief executive officer. “We deeply regret that this incident occurred, and we have already taken steps to ensure our laptops are properly equipped to secure personal information from unauthorized access in the future.” 


Unfortunately many organizations take a reactive approach to encrypting endpoint devices such as laptops and cell phones that may contain sensitive information. 


Oil giant BP, had a similar incident this spring in which an employee lost their laptop during routine business travel. The laptop contained  unencrypted personal data such as names, social security numbers, and dates of birth for over 13,000 people who submitted claims with the company after last years oil spill. 


According to Ponemon's "Cost of a Lost Laptop" report, a lost or stolen, unencrypted laptop, will cost an organization $20,000 more than if an encrypted laptop is lost or stolen. Read the full Ponemon report here: Cost of a Lost Laptop Study - Ponemon

77% Of Business Experienced Data Loss Last Year

A survey of over 2,400 IT security administrators conducted by Check Point and Ponemon reveals 77% of businesses experienced data loss last year. This number does not correlate with the number of reported breaches, but with increasing stringency of compliance regulations, we may begin to see more and more reported breaches.

The study’s research shows organizations are struggling with the growing set of security priorities and limited employee awareness about corporate security policies. Over 55 percent of companies surveyed are using more than seven vendors to perform security tasks. Because of this, organizations struggle with minimizing TCO and maximizing performance.

Approaching security with a holistic view of an organization’s technology is the first step in enforcing better protection. This helps to determine where risks can reside. Security is more than a simple technology solution. Aligning IT security with business needs requires a combination of policies, people and enforcement.

Wednesday, March 30, 2011

Lost Laptop Exposes 13,000 Oil Spill Victims

According to a BP spokesman the laptop was lost on March 1 by an employee on routine business travel.


The laptop held unencrypted information including the names, Social Security numbers, addresses, phone numbers, and dates of birth of people who filed claims related to the Deepwater Horizon accident that occurred last spring.


"The lost laptop was immediately reported to law enforcement authorities and BP security, but has not been located despite a thorough search," BP said Tuesday. They added that the device was equipped with a tool that would allow them to disable the system under certain circumstances. No further details on the nature of the circumstances that would be required to be met were given.


Unfortunately lost laptops containing sensitive personal data are lost every day, and even more commonly when traveling. In Ponemon's "Billion Dollar Lost Laptop Study" the institution found that of laptops lost 46% contained confidential data, and only 30% of those laptops were encrypted, as shown below. Encryption is not the only method used to protect confidential data on a laptop, but it is one of the most easily implemented and trusted ways to protect your company's and customer's sensitive data.




Wednesday, February 16, 2011

DLP Webinar Topics

For those of you who participated in any of our past webinars, thank you. We hope you have enjoyed them. For those of you who have not attended yet, we have our final webinar scheduled for Feb. 24th at 1:30 PM EST.

The purpose of this blog is to allow past and future webinar attendees to provide us with topics they would like to see discussed. Simply reply to this post with your suggestions.

The topic next week is DLP Buyers Guide: What You Need to Look for in a Solution.  If you have specifics within this topic you would like to know about, let us know.

We are looking forward to hearing from you next week! Register using the link above or the link on the right hand side of the blog.

Friday, February 4, 2011

Can You Afford the Cost of Non-Compliance?

The Ponemon Institute recently released a study titled “The True Cost of Compliance.” This study uncovered the average cost of compliance for organizations is $3.5 million and the cost of non-compliance is nearly $9.4 million. These numbers vary from industry to industry, but the averages accounted for a $5.8 million dollar difference in compliance vs. non-compliance. 
Compliance involves following all privacy and data protection laws and regulations and policies that are designed to protect individuals’ sensitive and confidential information. Costs necessary for compliance include staff to support a risk strategy and enabling technologies to decrease risk. Costs that can occur due to non-compliance include brand losses, legal costs, public relations costs, auditing, consulting, and more.

Some of the most important, but also most difficult, requirements to obey are the Payment Card Industry (PCI) standards, the various state data breach notification acts, the European Union Privacy Directive, and Sarbanes-Oxley (SOX).  Do you know what regulations your organization has to follow? Use the Regulation Finder in the DLP Toolkit to determine which regulations and guidelines you must observe.
What sounds better to you, paying the cost to comply, or approximately 2.65 times the cost of compliance in the event of a data breach? You are not invincible. In 2010, over 16 million records were breached and over $3 billion was spent on remediation.  Do not become a part of this statistic.  Start creating a risk strategy today.