By Gene J. Koprowski TechNewsWorld
10/31/05 5:00 AM PT
"When you apply these survey results to everyday corporate life, you realize that millions of dollars and the future of these companies are at stake," said Bob Heard, chief executive officer of Credant Technologies, a data encryption technology developer. "Even a single security breach can send stock prices plummeting."
This fall, campus police at the University of California, Berkeley, retrieved a stolen notebook computer that contained a cache of prominent names, Social Security Numbers and other personal data. This wasn't a trove of just a few names, though, police said. Rather, there was information on nearly 100,000 students, alumni and applicants to Cal, one of the nation's most prestigious public universities.
There have also been thefts of notebook computers in the law library at Boston College, and a reward is being offered at Washington State University for information on a stolen computer. Personal technology from iPods to cell phones are regularly stolen from campus dorms, libraries and offices, but swiped laptops create the greatest security threat.
Major college campuses aren't the only place where notebook PCs are being boosted -- or even the most likely locale for a theft. Experts tell TechNewsWorld that laptop PCs are often stolen at work -- by other professionals.
Shocking Study
"Everyone knows to guard their devices when they're traveling, but the results we found about the office were quite shocking," said Bob Heard, chief executive officer of Credant Technologies, a data encryption technology developer based in Dallas.
Heard's firm conducted a poll that discovered that laptops are most commonly stolen from the office, accounting for 29 percent of all notebook disappearances globally.
Respondents to the survey indicated that their computers were stolen straight from their desks -- even though many were glued or even locked in place. Nearly 90 percent of those whose notebook computers were stolen reported to Credant that they had e-mail applications containing sensitive corporate information on the computers.
"When you apply these survey results to everyday corporate life, you realize that millions of dollars and the future of these companies are at stake," said Heard. "Even a single security breach can send stock prices plummeting."
'Sensitive and Confidential'
Other findings of the study of 16,700 professionals in Fortune 2000 firms included:
Ninety percent of those who reported a stolen laptop said that it contained "sensitive and confidential" corporate data;
Seventy five percent of those who reported stolen laptops said they did not have encryption on the hard drive, even though such measures are mandated by federal laws, like the Health Insurance Portability and Accountability Act (HIPAA), and state legislation in California;
About 10 percent of respondents said they used some kind of security to protect their laptop.
A number of security solutions -- from encryption to tracking -- are emerging to tackle the problem. One developer, IntelliTrack, has created a stealth signal that is described as the "lojack" of computer anti-theft devices. The software tracks stolen notebook computers through their serial port and IP address. Since most computers that are stolen are eventually used on the Internet again, the tracing device is said to be handy in recovering the stolen property.
Some companies have designed their own software which performs the same function as IntelliTrack's -- hunting down the criminals when they go online.
Encryption a Tactic
Another tactic is to use technology to encrypt all of the data stored on laptops, tablet PCs, and other mobile devices. So-called "intelligent" encryption is being used today to encrypt only the most sensitive data, a tactic that leaves more hard disk space available for business and productivity applications.
Still, once the technology has been stolen, it most likely is gone forever, at least as far as its original owner is concerned.
"Eighty two percent of all our survey respondents claim they have never recovered a stolen laptop," said Heard. "That's sensitive data floating out there in the wrong hands, potentially with the ability to destroy the trust of clients and topple a corporation."
Tough State Laws Won't Stop 'Phishing' Scams, Experts Say October 29, 2005
"[Phishing is] incredibly easy to do, the rewards are very high, and the chances of actually getting caught are still very low," said Naftali Bennett, chief executive officer of Cyota, Inc. "Until one or more of these factors change, I don't expect phishing attacks to decline."
Related Stories
Report: VoIP Sets Stage for Security Appliance Surge September 08, 2005
Irwin Lazar, senior analyst at The Burton Group, told TechNewsWorld that he has not witnessed market conditions that resemble what In-Stat is describing. In-Stat's report that 75 percent of companies that have implemented VoIP plan to replace their security appliances within the next year is optimistic, he said.
Report Suggests Security Software Attacks Increasing June 21, 2005
Yankee Group recommended quality assurance and penetration testing measures such as reviewing security designs early and often; integrating security tests into regular software builds; reviewing code base; and truly simulating the tactics of an attacker.
Companies Not Keeping Up With Network Security Needs June 21, 2005
Vernier President and CEO Simon Khalaf said that the survey revealed some "shocking" findings about companies' knowledge level about internal network security. "Companies did not realize how open their network and their systems are to attacks from within the company," he said.
Evil Twins a Menace to Wireless Security June 04, 2005
Once the wireless victim has connected to the illegitimate WiFi hotspot, the Evil Twin attacker can gain access to the user's log-on details, along with personal and confidential information that aids the attacker in identity theft and other illegal activities.
Network Security Evolving to Unified-Management Approach May 21, 2005
The cloaked combination of these three types of infections creates what security agents now call a blended threat. As the notion of unified threat management becomes widespread, more security companies are offering products that address a layered protection scheme in a suite of software and hardware combinations.
More by Gene J. Koprowski
Mobile Phone Network Operators React to WiFi Threat September 09, 2006
"From a strategic and financial standpoint, the routing of traffic through the IP network significantly enhances network quality and capacity, and reduces the OPEX (operational expenditures) that carriers expend on backhaul," noted ABI Research analyst Stuart Carlaw.
Apple's 'Special Event' Has Rumor Mill Churning September 06, 2006
Apple surprised technology journalists and Wall Street analysts Tuesday with an e-mail saying there would be a "special event" next week. Embedded within the Apple invitation is an interesting image of spotlights shining upon the Apple logo with the words, "It's Showtime," printed beneath it. This is giving many analysts a Hollywood kind of feeling.
Restless IT Workers Looking for New Jobs September 04, 2006
"Tech workers who stayed put in their jobs over several years of uncertainty in our industry are clearly looking to move on now that we're in a period of growth," said Neill Hopkins, vice president, skills development, CompTIA.