By Erika Morphy CRM Buyer Part of the ECT News Network
07/10/08 10:56 AM PT
"Data security" may soon rank right up there alongside "military intelligence" as an oxymoron of the high-tech era. If it's not lost or stolen laptops, it's hackers breaking into sloppy networks -- or perhaps thousands of unwitting music lovers sharing sensitive corporate secrets along with the latest hot tracks.
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
Earlier this year, a careless employee at a Washington, D.C., area investment firm learned a painful lesson: Sharing files through peer-to-peer Web sites like
LimeWire can easily expose internal data in a corporate network. In this case, the employee worked for Wagner Resource Group, which counts several politically connected people, including U.S. Supreme Court Justice Stephen Breyer, among its clients.
The employee's actions revealed the personal data of Breyer and the firm's 2,000 or so other clients -- and the breach was not discovered for some six months, according to accounts.
More Than a Cautionary Tale
Presumably the data has been erased -- as best as possible -- and the clients notified of the breach.
Besides serving as a cautionary tale for employees to never use PCs at work for personal reasons, this incident highlights the little headway companies have made in securing their customer data.
Despite several well-publicized leaks of mammoth amounts of personal and customer data to the Web, security breaches are still all too common, Michael Wolfe, vice president of products and services data loss prevention solutions for Symantec (Nasdaq: SYMC), told CRM Buyer.
In this particular case, the exposure was the result of an employee being careless on the corporate network, he said. Others are due to intrusions with criminal intent. Regardless of motive, however, data losses -- including the Wagner case -- can be attributed to companies not educating employees about their security policies, not implementing adequate systems for their enforcement or, worst of all, not having such policies in place at all.
Companies need to take a multi-pronged approach to securing data, Wolfe said, that incorporates all of these elements.
Content-Monitoring Software
Monitoring what employees are doing may be the most urgent piece that companies need to address, said Phil Neray, vice president of marketing at
Guardium.
Many companies have established some type of security policy, at least on paper, he told CRM Buyer.
"What they haven't done is implement what Gartner (NYSE: IT) calls 'content monitoring software' -- products that examine network traffic and specific protocols to identify suspicious behavior," Neray said. "These products have been in the market for at least a few years, but it has only been recently that adoption has begun to take off."
This particular incident was bad, especially considering how long it took for the information to be taken down, he continued. "It could have been much worse though -- too many people still don't realize the dangers of using P2P networks. Now, can you imagine if this employee had worked for a credit card company or a bank or insurance company? It wouldn't have been a couple of thousands of names out there -- but tens or hundreds of thousands."
To be sure, there have been far too many data leakages that have resulted in such numbers of compromised accounts -- usually due to the theft of an unsecured laptop or an incursion from hackers. P2P file-sharing, though, is a surprisingly common culprit.
Bank Docs Deluge
The prevalence of inadvertent leaks of sensitive data through P2P sites is the focus of a study completed last year by Professor Eric Johnson at the Tuck School of Business at Dartmouth, with funding from the U.S. Department of Homeland Security.
Tens of thousands of sensitive bank documents are available through P2P networks, the researchers found. They turned up a bank spreadsheet, for example, that contained 23,000 business accounts including names, addresses, account numbers, companies, positions and relationship managers at the bank.
Of these documents, 79 percent were inadvertently shared by customers; 11 percent by bank employees; and 10 percent by suppliers such as IT vendors, auditors, consultants, and even landscapers and electricians.
5 Ways to Build an Indestructible Customer Data Fortress July 08, 2008
Retailers should use the standards set by the Payment Card Industry as a starting point when ensuring that their customer data is as secure as possible, suggests Kristin Lovejoy, IBM's director of corporate security strategy.
Related Stories
P2P and P4P: The Tangled Web We Weave May 07, 2008
The DCIA kicked off its P2P Media Summit on Monday with a panel discussion about P4P -- technology designed to ease the flow of peer-to-peer traffic by managing connections. Proponents of the system say it's no threat to privacy and proves that Net neutrality legislation isn't needed. But questions remain as to how much control P4P actually represents.
Comcast Steers for High Ground With P2P Bill of Rights April 16, 2008
Comcast moved from "no we didn't block traffic" to "we did, but we had to" to "we think there might be a better way, and yeah, OK, file-sharers have rights too" quicker than you could say "Net neutrality." Anyone care for a sip of self-regulation?
Related News Alerts
More by Erika Morphy
Ballmer Gives Shareholders - and Dell - Cause for Optimism November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Salesforce.com Pumps Up Volume of Workplace Chatter November 19, 2009
Salesforce.com has developed a collaboration platform that puts social networking to work. Salesforce Chatter facilitates employee collaboration on projects through Facebook-like profiles, status updates, feeds and groups. The question remains whether employees will be as open to social networking in the workplace as they are in their personal lives.