Showing posts with label data leakage. Show all posts
Showing posts with label data leakage. Show all posts

Tuesday, August 9, 2016

Data Theft Rising Sharply, Insider Threats Cited as Leading Cause



New Study: Data Theft Rising Sharply, Insider Threats Cited as Leading Cause

New Ponemon Institute Report Finds Most Employees Have Too Much Access, Multiplying Damage When Accounts Are Compromised

London, UK, August 9, 2016 – Three out of every four organizations have been hit by the loss or theft of important data over the past two years, a sharp increase since 2014, according to a new survey of more than 3,000 employees and IT practitioners across the U.S. and Europe. The report, released today, was conducted by the Ponemon Institute and sponsored by Varonis Systems, Inc.

The rise in data loss and theft, according to the survey, is due in large part to compromises in insider accounts that are exacerbated by far wider employee and third-party access to sensitive information than is necessary, and by the continued failure to monitor access and activity around email and file systems – where most confidential and sensitive data moves and lives. 

The survey report, “Closing Security Gaps to Protect Corporate Data: A Study of U.S. and European Organisations,” resulted from interviews conducted in April and May, 2016, with 3,027 employees in the United States, United Kingdom, France, and Germany.  Respondents included 1,371 end users and 1,656 IT and IT security professionals, in organizations ranging in size from dozens to tens of thousands of employees from a variety of industries including financial services, public sector, health care and life sciences, retail, industrial, and technology and software.
Among the key findings:
  • Seventy-six percent of IT practitioners say their organization experienced the loss or theft of company data over the past two years. This is a significant increase from 67 percent of IT respondents who gave the same response in the 2014 study conducted by Ponemon for Varonis.
  • IT respondents say insider negligence is more than twice as likely to cause the compromise of insider accounts as any other culprits, including external attackers, malicious employees or contractors.
  • Seventy-eight percent of IT people are very concerned about ransomware, a type of malicious software that that blocks access to files until a sum of money is paid. Fifteen percent of organizations have experienced ransomware and barely half of those detected the attack in the first 24 hours.
  • Eighty-eight percent of end users say their jobs require them to access and use proprietary information such as customer data, contact lists, employee records, financial reports, confidential business documents, or other sensitive information assets. This is sharply higher than the 76 percent recorded in the 2014 study.
  • Sixty-two percent of end users say they have access to company data they probably shouldn’t see.
  • Only 29 percent of IT respondents report that their organizations enforce a strict least-privilege model to ensure insiders have access to company data on a need-to-know basis.
  • Only 25 percent of organizations monitor all employee and third-party email and file activity, while 38 percent do not monitor any file and email activity.
  • Thirty-five percent of organizations have no searchable records of file system activity, leaving them unable to determine, among other things, which files have been encrypted by ransomware.
Dr. Larry Ponemon, Chairman and Founder of Ponemon Institute, a leading research center dedicated to privacy, data protection and information security policy, observed, "Despite all the technology available and the spike in highly publicised attacks, data breaches continue to rise. The most valuable data featured in most breaches is unstructured data such as emails and documents. When emails and files are surfaced, they tend to cause scandal, forcing the breach to have a lasting effect on the company’s reputation. This survey raises key points as to why hackers are able to maximise impact – too many employees have too much access, beyond what they need to do their jobs. On top of this, when employees access valuable data and their activity is not tracked or audited, it becomes far too easy for an external hacker or a rogue insider to get away unnoticed.”

Yaki Faitelson, Co-Founder and CEO of Varonis, said, “Right now we’re in a technology arms race with hackers and insider threats. Unnecessarily excessive internal access combined with a lack of monitoring and auditing sets organizations up for disaster. Sony Pictures, the Panama Papers and the recent Democratic National Committee intrusions all concerned the theft of files and emails that were not protected well enough from insider threats or outside attackers that compromised insider credentials, causing major damage to those organizations and their reputations. These new findings, alongside the fallout from those breaches, should keep executives awake at night. What will be the straw that makes businesses focus their efforts on protecting their precious information assets? Varonis is helping thousands of organizations around the world address these challenges, prepare for and stop ransomware and other malicious threats that get inside and impersonate insiders.”

Wednesday, March 23, 2016

Why Most Companies Are Easy Prey for Cyber Attackers


Alarming Data Reveals Why Most Companies Are Easy Prey for Cyber Attackers

LONDON, UK, March 22, 2016 – Varonis Systems, Inc. today revealed the results of a year of anonymous data collected during risk assessments conducted for potential customers on a limited subset of their file systems. The 2015 results show a staggering level of exposure in corporate file systems, including an average of 9.9 million files per assessment that were accessible by every employee in the company.

Of the insights gleaned from dozens of customer risk assessments conducted in mid-to-large enterprises prior to remediation, in a subset of each company’s file systems, Varonis found the average company had:
35.3 million files, stored in 4 million folders, meaning the average folder has 8.8 files
  • 1.1 million folders, or an average of 28% of all folders, with “everyone” group permission enabled –open to all network users
  • 9.9 million files that were accessible by every employee in the company regardless of their roles
  • 2.8 million folders, or 70% of all folders, contained stale data – untouched for the past six months
  • 25,000 user accounts, with 7,700 of them or 31% “stale” – having not logged in for the past 60 days, suggesting former employees, employees who changed roles, or consultants and contractors whose engagements have ended
The ‘everyone’ group is a common convenience for permissions when originally set up. That mass access also makes it astonishingly easy for hackers to steal company data.

Some individual companies’ lowlights that were gleaned from the Varonis risk assessments:
In one company, every employee had access to 82% of the 6.1 million total folders.
  • Another company had more than 2 million files containing sensitive data (credit card, social security or account numbers) that everyone in the company could access.
  • 50% of another company’s folders had “everyone” group permission and more than 14,000 files in those folders were found to contain sensitive data.
  • A single company had more than 146,000 stale users – accounts whose users had not logged in for the past 60 days.  That’s nearly three times more users than the average FORTUNE 500 company has total employees.
David Gibson, Vice President of Strategy and Market Development at Varonis, said, “Although this data presents a bleak look at the average enterprise’s corporate file system environment, the organizations running these risk assessments are taking these challenges seriously. Most of them have since implemented Varonis, embracing a more holistic view of the data on their file and email systems and closing these gaping, often unseen security holes before the next major breach causes heavy damage. Our software is able to provide a granular look at where sensitive data lives, where it is over-exposed within an organization, who is accessing that data, and how to lock it down. While that remediation process is running, our ability to start detecting and stopping many types of insider threats has been a major revelation for our customers.”

Wednesday, December 9, 2015

Changing Human Behavior Is the Key to Thwarting Cyber Threats in 2016


London (UK) - 08 December 2016 - PhishMe today offered three predictions for the threats it believes UK organizations will battle in 2016:

1. Phishers Will Continue to Divide and Conquer

Phishing has been the number one attack vector for over five years and 2016 will be no different.

Rohyt Belani, CEO of PhishMe explains his thinking, "We, as an industry, have lagged in engaging employees to be a part of the organization’s security posture. For decades, enterprises have focused on traditional security awareness techniques like computer-based training (CBT) that simply don't work; they have no sustained impact on behavioral change. At PhishMe, we have succeeded in helping our customers engage their employee base by turning them into informants of suspicious emails, providing such employees with the necessary tools to report the same in a frictionless manner, and then most importantly in providing the incident response teams at these organizations a solution to rapidly triage these reports and operationalize the attack intelligence obtained. The human is no longer the weakest link for our customers; they are the strongest asset."

2. Focus Will Move Back to Prevention of Breaches, Rather than Detection after the Fact

While prevention of individual infections is almost impossible, preventing the breach of confidential and proprietary data as a result is paramount.

"The industry gave up. They surrendered and turned to post-breach detection and mitigation because the hackers were winning," explains Scott Greaux, VP Product Management at PhishMe, "With average time to detection still over 200 days this approach hasn't worked either and I think in 2016 we will see the focus shift again. System infections will occur, and at the moment there's no silver bullet to change this, but we need to prevent these infections from translating to large data breaches. That means conditioned email users will play a key role, providing the timely and actionable threat intelligence thus minimizing attacker dwell times, that will help prevent breaches in 2016."

3. All Forms of Trust Will be Abused

It seems that criminals listen to the advice given to people about cybercrime and turn it around in a bid to thwart defenses. The traditional wisdom was 'don't click links or open attachments from un-trusted sources.' In 2015, the increase in attacks targeting email is primarily about abusing those trust relationships. In 2016, other forms of trust are going to be under attack. Passwords stored in browsers, especially on mobile devices and 'Bring Your Own Device' phones and tablets will be a big target. 

The advice from Gary Warner, Chief Threat Scientist at PhishMe is that, "This year we need to be encouraging the adoption of two factor authentication and 'unknown device' alerting as never before – including on internal systems.  In another area of trust, a malware compromised workstation logs in to the corporate systems with the same power as an authorized user. Big data breaches are largely enabled by the concept that certain users should be allowed to 'See Everything' and this must be reeled back to 'see only some things' or 'see anything,' but only at reasonable volumes."

With increased reporting of suspicious activity, advances in threat analysis to enable better campaign identification, and raising the shield by challenging all of the 'trust' assumptions made, organizations can make 2016 a safer year.

Thursday, December 3, 2015

U.S. Presidential Campaign Will be Affected by a Cyber Attack, and Other 2016 Predictions


It's the of the year for predictions of how bad the security environment will be for the coming year.  Here are predictions from David Gibson, VP of strategy and market development at Varonis. By the way, focusing on end-user education and monitoring is long overdue. I don't think it's hyperbole to say, "Insiders are the new malware."

1. The U.S. Presidential campaign will be affected by a cyber attack.  
Hillary Clinton's private email server has already brought cybersecurity into the U.S. Presidential race. In 2016, a cyberattack will strike the campaign, causing a major data breach that will expose donors' personal identities, credit card numbers, and previously private political preferences. Imagine being a donor with an assumption of anonymity. Or a candidate whose “ground game” depends on big data analytics about voter demographics and factors affecting turnout – data that turns from an asset to a liability if it isn't protected. The breach will affect the campaign not only as a setback for the unfortunate candidate or party affected, but by bringing the issue of cybersecurity prominently into the campaign as a major issue that is closely related to geopolitical threats such as the spread of terrorism. Campaign data is a gold mine for hackers (donor lists, strategies, demographics, sentiment, opposition research), and an event like this will serve as another wake-up call to the U.S. government that cybersecurity needs to be a continual, central focus and investment at the highest levels. The candidate who demonstrates knowledge and command of cybersecurity threats and government readiness will win the election.
  
2. The frequency of public data breaches will increase substantially.
The Identity Theft Resource Center (ITRC) reports a total of 641 data breaches recorded publicly in 2015 through November 3. Most organizations know this number represents the tip of the iceberg. The frequency of known data breaches will increase in 2016, due not only to increasing privacy and breach disclosure laws but also the increasing failure of traditional perimeter-focused security investments to protect valuable data. Employees' use of mobile devices and companies' migration of IT workloads to the cloud will also contribute to a sharp rise in breaches. Over time, this should help to shift priorities toward investing in more proactive data-centric protection, but it's likely things will become worse before they get better.

3. End-user education and monitoring will become the focal point of data security efforts.
Insiders are the new malware. Executives and IT professionals are becoming as afraid of their own employees – as innocent vessels for outside attackers with dangerous levels of access to sensitive data – as they are of outside attackers. Companies will turn to the importance of end-user education in 2016 as they realize that, no matter how intensely they invest in security, they hit a dead end if their users don’t drive by the rules of the road. They need to be involved in the security processes, observe classification and disposition policies (that need to be defined) and know to stop clicking on phishing emails. Employees are crucial to the security process, and have more power in controlling it than they realize. You can't patch users but you can educate them. You can also monitor and analyze how they use data to spot unwanted attacks.

4. At least five more C-level executives will be fired because of a data breach.
In recent years we have seen the careers of several top executives suffer in the wake of cyber attacks. Target CEO Gregg Steinhafel and CIO Beth Jacob, U.S. Office of Personnel Management Director Katherine Archuleta, Sony Pictures' Amy Pascal and others were either fired or forced to resign after massive data leaks cost their organizations money, customers and credibility. This will accelerate in 2016.  Blame for data breaches is shifting from IT to the C-suite. Data impacts every facet of an organization. If management is not investing in and focusing heavily on securing data and its use, it is now understood that they are putting the entire company and its stakeholders at risk.

5. Increasing false positives in data security bring to light the need for limited, accurate information.
Organizations will get much more serious about how much data they collect and their deletion efforts. When Target suffered its massive breach during the 2013 holiday season, the alerting capabilities of its IT team had generated months of warnings.  Still, no one caught it. This remains a common problem today. Why? The plethora of security tools installed in most companies overwhelms IT security. Their teams are strapped and the amount of false positives generated by exponentially growing volumes of information cause these teams to miss crucial vulnerabilities. In 2016, smart IT teams will focus on signal-to-noise ratio improvements in the analysis and alerting solutions they deploy.

Tuesday, November 17, 2015

The Threat Within: 3 Out of 4 Companies Affected by Internal Information Security Incidents


Costly cyberattacks are now almost routine for businesses, but while many organizations are focusing on external attackers, it's important to also look at threats from within. According to the IT Security Risks Survey conducted by Kaspersky Lab and B2B International, 73% of companies have been affected by internal information security incidents. The survey also found that the largest single cause of confidential data losses is by employees (42%). Read more here.

Monday, October 26, 2015

10 Facts You Need to Know About Data Breaches

2014 was dubbed as "the year of the data breach." With many new data breaches dominating the headlines in 2015, including Anthem, the White House, banking attacks, and the latest employee data theft at the US federal government, one can only imagine what the name for 2015 will be: the year of even more data breaches? According to the Ponemon Institute, 43% of companies experienced a data breach in 2014. Not only is the number of data breaches rising, the number of records stolen per breach is increasing as well as the cost per stolen record. It is apparent that current security measures are not sufficient to protect organizations from data breaches. This article highlights the top 10 most interesting, remarkable and troubling facts about data breaches.

Thursday, September 10, 2015

Top 3 Factors Driving the Rise in Data Breaches



It comes as no surprise that the number of companies falling victim to data breaches is on the rise. These stories are making headlines, and making CEOs and employees alike nervous that they will be the next victim. As computers are getting faster, so are hacking attempts. Hackers are now more capable than ever to implement their plans. This article outlines the top three factors that are contributing to the rise of data breaches.

Monday, August 17, 2015

Protect Your Data: Top Ten “Need to Know” Tips


Protect Your Data: Top Ten “Need to Know” Tips

By Dietrich Benjes, VP UK, Ireland and Middle East, Varonis Systems, Inc.

With breaches happening on an almost daily basis, it's critical to establish rules and processes to keep your data safe and secure.  The following tips, designed to help you build a sustainable path towards data security, were inspired by the FTC.

Don’t Make Security an Afterthought

Think before you collect.  Is it necessary and does it add value to capture personal, sensitive information from your customers and prospects?  Or does it just open up additional risk?  If you absolutely need to collect sensitive information, don’t hold on to it longer than necessary.  Set an “end date” and follow through with securely destroying the info.  Security shouldn’t be reactive but proactive.

Stay in Control

If you need to hold on to sensitive data (it’s a business must), then how do you keep it safe from prying eyes – both inside and outside your organization?  Answer: limit access.  Does your summer intern need wide-open access to corporate IP to do her job?  Probably not. Implement a system for periodically reviewing entitlements to ensure people only have access to the information they need. Your auditors will thank you.

Passwords and Authentication, Please

You’ve got sensitive data and want to keep it safe. Requiring complex passwords (by the way, “password” is NOT complex) that include multiple elements (caps, numbers, minimum characters) and changing them on a quarterly basis makes it hard for hackers.   Even better: require two-factor authentication, disable access after a specific number of failed login attempts, and protect against authentication bypass to really “up” the proverbial ante.

Share It Securely

Sure, your internal network is secure. But what if you need to share your data outside the firewall? One way to do this securely is with a data file sync and share solution that works with your existing permissions and authentication infrastructure.

Who’s Knocking on Your Door?

Do you know who is accessing what computer at all times?  Probably not. So protect yourself – and your sensitive data – in a separate, secure place on your network.  Limit access. Even better, continuously monitor your file access activity with a solution that makes it easy to see and address suspicious, unusual behavior before it’s too late.

Remote Control

Isn’t telecommuting great? It allows employee freedom and increased productivity. But it can be a security nightmare. The key idea is to allow remote connections, but restrict the ability to re-login to other desktop and servers. We really want to make it difficult for hackers to leapfrog around your network. This can be accomplished by enhancing security of the Remote Desktop feature in Windows. You can read more about how to do it here. 

Keep It Under Wraps

Is your organization developing a hot new product or solution? Have you thought about how your customers will use it and whether it needs to be secure? Make sure your developers are up to scratch with Privacy by Design principles, and the latest best practices in safe coding. In addition, know thy platform security guidelines – no need to recreate the wheel. Finally, testing is key!  While not every threat can be anticipated, testing for common vulnerabilities ensure security at the gate.

Who’s Got Your Back?

You probably work with service providers and other contractors. But do they share your passion for security? Make sure your standards are being met by including your security requirements (for example, encryption, two-factor authentication, data retention limits) in contracts and service-level agreements. Remember to stay active and always monitor your controls to ensure that your security expectations are followed and your users aren’t inadvertently exploited.

Make a Plan, Stan

You’re secure – for now.  Unfortunately, security isn’t static and so to remain compliant you’ll need to stay on top of your systems and technology.  This means making a plan that includes monitoring third party software, performing updates, and faithfully implementing patches.  In addition, pay heed to security warnings and notifications!  Develop an action plan! If a vulnerability has been exposed, be proactive and take the steps necessary to protect your data!

Physical Security

Network security is critical. But what about computer hardware, as well as paper files and all the miscellaneous stuff that makes up a typical office environment? Does your company have a security policy for the non-virtual world? Rule #1: keep important papers and other physical IP in a secure place (locked file cabinets, secured server rooms, etc.).  Laptops should have secure-login and hardware-level password protection set. What about old computers, servers, tapes, and disk drives?  What may appear as trash to you could be a gold mine to hackers.  

Friday, December 5, 2014

Varonis Perspective on the Sony Breach


This is an amazing story. It's all about not paying attention in Security 101. In the following unattributed analysis, Varonis adds detail and insight on this breach. 

FROM VARONIS:

While we have few details on the Sony Pictures attack itself, this very public breach—or pwning in hacker slang--has shown the extent of the actual exposure—it is massive. The always informative Krebs knows, at this point, as much as the rest of us—possible North Korean connection and perhaps the use of destructive erase-all malware. That’s not to say this incident hasn’t revealed significant insights about our collective data security practices: don’t think the Sony incident doesn’t apply to you!

Krebs provides a link to the sprawling Sony directory hierarchy. This should definitively settle any doubt about the scope of this thing.

There are a few points to make. 

Unlike the big-box retailer incidents, this breach is not, for the most part, about personally identifiable information or PII. Certainly, there are employee social security numbers, email addresses, passwords, and health identifiers that are now out there for the world to see. But the Sony breach does not involve millions of consumer records and the subsequent issuing of new credit card numbers along with subscriptions to credit monitoring services.
This incident, though, is centered on sensitive data, perhaps even valuable IP, which was found in the 25 gigabytes of file data scooped up by the hackers. The leaked information should look all too familiar to any worker in a larger organization: readable files and emails, or, as we like to refer to it, unstructured, human-generated data.  So we’re talking employee salaries, financial data, internal presentations, company information under NDA, legal memos, the CEO’s private notes, and on and on. 

We should add that plain-text user passwords were found in files named, um, passwords. They certainly violated the "prime directive" on credentials.

From a broader perspective, we expect this is just one very public instance of a problem that can be found in enterprises globally. The amount of human-readable formation is growing exponentially. These documents live in file shares, intranets and in email as attachments, where far too many people have far more access than they really need, and usage is rarely monitored or analyzed for abuse.

No one should be casting any stones: we have all been or are Sony.

As we’ve seen in other breaches, the compromise of one employee email account can expose troves of sensitive data.  It’s likely the hacker harvested credentials —not necessarily of privileged admins or power users-- through PtH and other techniques. With their group memberships and access rights, combined with a loosely permissioned file system, they had a panoramic view of the Sony data landscape.

How did the situation get to be so dire?  Consider these two very common business-as-usual scenarios:

Scenario 1: A folder, containing sensitive data, becomes accessible to large group of people
A folder on your network share is used by your HR department—it might even be someone’s "home drive." At some point, someone makes the folder accessible to a broad group of people (this happens a lot), and it’s forgotten. Usage information about this folder (who is opening, creating, deleting, changing, moving files) isn’t tracked or analyzed (this is the norm).

Over time, sensitive files—say salaries, financial data, etc.—accumulate in these publicly sharable folders. No one really thinks about it, but everyone knows that a certain presentation or spreadsheet is just there so there's no need to formally request the data from the relevant owner. It's a data exposure incident waiting to happen, requiring a hacker to gain access to an average users' credentials—a simple phish mail often will do.

Scenario 2: Company emails become web browser enabled and gets hacked
You’ve enabled web browser access to your email system (try mail.yourcompany.com or owa.yourcompan.com if you're wondering), so anyone can log into their email from anywhere with only their password. Usage information about your email system is not tracked or analyzed (you can’t see who is sending or reading email or reading and marking them as unread, etc. – this is also the norm). The hacker gains the password of the email account—maybe by just guessing it.  Now the attacker can log in and read all the executive’s email (including the attachments) without leaving his home – and no one will know. Again, very valuable information—merger talks, new customers—in readable formats.

Another Teachable Moment
As Sony’s hackers gained access to more than just passwords, but movie budgets, salaries, social security numbers, health care information and so much more, the Sony breach provides us with yet another teachable moment. It reminded us all the importance of proper access controls, identification of sensitive data – who has access, who is using it, where it’s overexposed to the everyone group and who it belongs to, as well as implementation of real-time alerts.

Thursday, February 6, 2014

Data Privacy Day Tips


I have to confess that I was unaware that Data Privacy Day was last week.

Data Privacy Day occurs every year on January 28 and is intended to remind us to more carefully consider our privacy choices throughout the year.

Computer users are encouraged to think about privacy choices the next time a new online profile is created, or load an app on a phone, or sign up for a frequent shopper card at your favorite retail establishment.

“And with the big data movement hell bent on collecting as much information about us whenever possible, apparently innocuous or unimportant details can be pieced together in new and surprising ways,” said Chester Wisniewski, senior security advisory at Sophos.

Following are three simple privacy diet tips from Sophos to help trim the fat and protect user’s privacy:

1. Turn off geolocation, and leave it off.
Whether you're a Twitter user, a soldier in a war zone, or a fugitive from the law, geolocation can carry serious unintended consequences even when it's used on purpose.

Users have to be careful to avoid being tripped up by a steady supply of less-than-honest app writers. Geolocation data has been silently hoovered up and sent home by phone software as diverse as flashlights and mobile apps for kids.

2. Turn off Wi-Fi. Turn it on when you need it.
To trim the next few privacy pounds dieters need to turn off Wi-Fi on their smartphones, tablets and laptops. You can still use Wi-Fi but you have to switch it on when you need it and turn it off again when you don't.

As it searches for networks to join, your phone will offer up the names of Wi-Fi networks you've used previously. Many Wi-Fi networks are named after the places where they're located, so that your phone's electronic greeting can read like a history of where you've been. Alongside the networks it's joined your phone will also broadcast its MAC address almost constantly. Commercial organizations have begun to show serious interest in that little unique ID because it can be used just like a cookie to track and profile your movement in the real world.

3. Log out when you have finished
Dieters on the Privacy Plan should log out of any system they've finished with. Stopped using your laptop? Log out. Checked your bank balance? Log out. Done updating your Facebook status? Log out. Everything you've used but haven't logged out of is an open back door that leaves your privacy at the mercy of Clickjacking attempts, Cross-Site Referral Forgery attacks, social media tracking beacons and people just sitting at your keyboard when you're not there.

“Data Privacy Day is the perfect time to think about all the computing devices and gadgets you use, including smartphones and tablets,” said Rebecca Herold, an information security and privacy expert, internationally recognized as "The Privacy Professor," and author of  Managing an Information Security and Privacy Awareness and Training Program, now in its second edition. “Many people don’t realize these devices are continually collecting personal information about the user, such as where you work or attend school, travel, shop … the list goes on. Everyone should be aware of the information they are putting out there and the data being collected without their knowledge or consent.

“As we embark on 2014, we truly are in a new and expanding ‘Internet of Things’ where numerous amounts of data are being collected every day. All individuals, businesses and government organizations should make privacy a priority by being educated about new, expanding data collection points and put appropriate protections in place to protect personal information,” added Herold.
Herold encourages all consumers to ensure they aren’t giving away too much information when their personal data is collected, and she believes they have the right to demand that the entities collecting their information are protecting it and using it properly.

Friday, October 18, 2013

GAO: Centers for Medicare and Medicaid Services Needs to Pursue a Solution for Removing Social Security Numbers from Cards

The GAO recommends that CMS initiate an IT project to develop a solution for SSN removal and incorporate such a project into plans for ongoing IT modernization initiatives. HHS agreed with GAO's recommendations, if certain constraints were addressed. However, GAO maintains that its recommendations are warranted as originally stated.

What they really need to do is de-identify and anonymize data.

Of course, we have books that will help solve the problem.

Guide to the De-Identification of Personal Health Information 

In this book Khaled El Emam, the founder and CEO of Privacy Analytics, Inc., offers compelling practical and legal reasons why de-identification should be one of the main approaches to protecting patients’ privacy, this book outlines a proven, risk-based methodology for the de-identification of sensitive health information. It situates and contextualizes this risk-based methodology and provides a general overview of its steps. The book supplies a detailed case for why de-identification is important as well as best practices to help you pin point when it is necessary to apply de-identification in the disclosure of personal health information.

The Complete Book of Data Anonymization: From Planning to Implementation

Data anonymization provides a systematic and integrated approach to privacy protection that goes far beyond simple data-masking or network security from external or internal theft. In book, Balaji Raghunathan of Infosys Ltd. discusses the analysis, planning, set-up, and governance, this timely manual illuminates the entire process of adapting and implementing anonymization tools and programs to increase the success of privacy protection in vulnerable organizations. Providing a 360 degree view of data privacy protection, it details data anonymization patterns, automation/tool capabilities, and the key factors for success in disguising the person behind the data.

Monday, July 22, 2013

US information leakage shows sloppiness in managing secrets

An interesting piece in Japan News in defense of Snowden and, by implication, Bradley Manning, Julian Assange, and others. I wonder if Snowden ever read about Kim Philby and how much he enjoyed life in the worker's paradise after fleeing England? It's a cold, lonely life.

Speaking of insider threats, you might want to take a look at Managing the Insider Threat: No Dark Corners. It identifies new management, security, and workplace strategies for categorizing and defeating insider threats.

Monday, July 2, 2012

3 Risks of Failing to Monitor Internet Usage

Could your business cope without Internet access? Would you still be able to do business? It is unlikely that you could survive for long without an Internet connection. Yet, few businesses understand the risks of failing to monitor Internet usage.

Employees downloading files, social engineering attacks, bandwidth consumption and negatively impacted productivity can all result from the misuse of employee Internet access privileges. Many of these risks can be mitigated by using software to monitor Internet usage over your network, and to apply proactive security measures to stay secure.

Let’s take a look at the three most common pitfalls and how they can be avoided by Internet monitoring software.

Decreased Productivity
Not all employees understand the concept of “Internet privileges”, and some may interpret it more loosely as “carte blanche to surf the web all day.” In addition, some employees like to use high-speed corporate networks to download large files, such as movies. Not only does this activity put the company at legal risk, but large downloads can also devour bandwidth and cause a loss of productivity across your network.

Good software can allow you to monitor Internet usage, providing the granular management of Internet access controls for your employees. This allows you to control their browsing habits and prevent abuse to ensure your system runs at peak performance. In addition, Internet monitoring software can also allow you to set bandwidth thresholds and block streaming media to ensure you retain control of Internet traffic passing through your network.

Malicious Files and Viruses
Unauthorized downloads and malicious websites can result in infected PCs. Not only does that put your confidential data at risk, but it can also result in system downtime to clean out the infection and restore your network to a secure state.

Employees may also attempt to download and install patches for work-related software, which could destabilize your network if those patches are not tested and approved. Compatibility issues can arise with your existing setup, resulting in administrator resources being used to fix a problem that shouldn’t have arisen in the first place.
By using software to effectively monitor Internet usage you can control which files can be downloaded by users. Software can also be used to scan files that are allowed onto the system with multiple antivirus engines, thus ensuring they are safe. In addition, sites that are off limits can be blocked, keeping your network safe from a variety of attack vectors.

Phishing Attacks
Websites that are masquerading as legitimate sources can lure employees into a false sense of security. They may be tricked into revealing confidential information, or even inadvertently give away access codes that could leave your system open to attack.
By filtering websites and monitoring HTTPS traffic to prevent malware masquerading as safe software, you can keep your network better protected against such risks. In addition some software that can monitor Internet usage will also block access to known phishing websites based on updateable databases of known attack sites.

By failing to monitor Internet usage you can leave your company exposed to considerable risks. Few businesses can afford a loss of productivity, or having their bandwidth resources gobbled up by employees making personal use of the network. Worse still, infection from malware or viruses as a result of failing to control downloads can leave your system completely down.

By deploying software to monitor Internet usage you can keep a careful eye on your network and control its usage to ensure it always runs at peak performance, while also providing an extra layer of protection against attack. The question now is, is it worth the risk to remain without it?

**********
This guest post was provided by Peter Wisner on behalf of GFI Software Ltd. GFI is a leading software developer that provides a single source for network administrators to address their network security, content security and messaging needs. Learn more about why you need to monitor Internet usage.

Friday, September 23, 2011

Dog bites man

Another new survery, another yawn. The latest poll reveals that email main source of data leaks in organizations. This is largely due to policy violations. Policies are good, but they don't trump human nature. I suspect even the best awareness training isn't sufficient to slay this beast. One benefit of these surveys is that they get companies in the news.