Showing posts with label data theft. Show all posts
Showing posts with label data theft. Show all posts

Tuesday, August 30, 2016

Study Finds Employees’ Security Hygiene Getting Worse Just As Ransomware Exposes Insider Negligence

Varonis-Sponsored Ponemon Institute Report Examines Widening Gap between End Users and IT Professionals as Data Breaches Increase

LONDON, UK -- August 30, 2016 -- At a time when ransomware and other attack techniques that exploit insider negligence become rampant, only 39 percent of end users believe they take all appropriate steps to protect company data accessed and used in the course of their jobs. This is a sharp decline from 56 percent in 2014, according to a new survey of more than 3,000 employees and IT practitioners across the U.S. and Europe. The report was conducted by the Ponemon Institute and sponsored by Varonis Systems, Inc.

Moreover, while 52 percent of IT respondents believe that policies against the misuse or unauthorised access to company data are being enforced and followed, only 35 percent of end user respondents say their organizations strictly enforce those policies.

The new release, "The Widening Gap between End Users and IT," compares end-user practices and beliefs with those of their colleagues in IT security and IT generalist roles. This new analysis draws from the same data released by Varonis and the Ponemon Institute August 9, 2016, in a report entitled "Closing Security Gaps to Protect Corporate Data: A Study of US and European Organisations," which found a sharp rise in the loss or theft of data, an increase in the percentage of employees with access to sensitive data, and the belief among participants that insider negligence is now the #1 concern for organizations trying to prevent these losses.

The survey results are derived from interviews conducted in April and May 2016, with 3,027 employees in the United States, United Kingdom, France, and Germany. Respondents included 1,371 end users and 1,656 IT and IT security professionals, in organizations ranging in size from dozens to tens of thousands of employees from a variety of industries including financial services, public sector, health care and life sciences, retail, industrial, and technology and software.

Among the key findings:
•    Sixty-one percent of respondents who work in IT or security roles view the protection of critical company information as a very high or high priority. In contrast, only 38 percent of respondents who are considered end users of this data believe it is a very high or high priority.
•    Asked about their organization's attitude on productivity vs. security, 38 percent of IT practitioners and 48 percent of end users say their organizations would accept more risk to the security of their corporate data in order to maintain productivity. 
•    Asked to agree or disagree that the protection of company data is a top priority for their CEO and other C-level executives, only 35 percent of end users agreed while 53 percent of IT professionals believe it is a top priority for senior executives.
•    Asked for the most likely causes of the compromise of insider accounts, 50 percent of IT practitioners and 58 percent of end users say negligent insiders. "Insiders who are negligent" was by far the most frequent response for both IT and end users, more than twice as common as "external attackers" and more than three times as common as "malicious employees."
•    End users are far more likely to attribute data breaches to insider mistakes than IT or security professionals. Seventy-three percent of end users say data breaches are very frequently or frequently due to insider mistakes, negligence or malice, while only 46 percent of IT respondents draw the same conclusions.

Dr. Larry Ponemon, Chairman and Founder of Ponemon Institute, a leading research center dedicated to privacy, data protection and information security policy, observed, "At a time when one would expect general improvement in end-user hygiene due to increased awareness of cyberattacks and security breaches, this survey instead found an alarming decline in both practices and attitudes. If an organization’s leadership does not make data protection a priority, it will continue to be an uphill battle to ensure end users' compliance with information security policies and procedures. Major differences between the IT function and end users about appropriate data access and usage practices make it harder to reduce security risks related to mobile devices, the cloud and document collaboration."

Yaki Faitelson, Co-Founder and CEO of Varonis, said, "Human error will always be a weak link in security. Insiders compromise security maliciously or accidentally and outside attackers continue to hijack the credentials and systems of employees, administrators, contractors, and executives. The only way to stem this tide is to implement controls on data access, monitor all activity and implement the most advanced user behavior analytics and alerting technologies throughout the organization."

NEW BOOK ON MITIGATING INSIDER THREATS

We'll be publishing "Walling Out the Insiders: Controlling Access to Improve Organizational Security" by Michael Erbschloe in February 2017. The book is grounded in the reality that many, if not most organizations have limited security budgets and security personnel. It

  • Explains security planning and management strategies in a manner that can be understood by security professionals as well as non-security managers and executives.
  • Provides long-term security design, implementation, and management methods to guide managers through the long process of achieving improved security.
  • Provides practical advice on how to determine security weaknesses and security needs.
  • Provides practical advice on how to select security vendors and service providers.
For more on the insider threat, read these articles:

The Insider Threat: A View from the Outside

Why Insider Threats Are Succeeding

The Top 10 Ways to Combat Insider Threats

Insider Threat Concepts and Concerns

Tuesday, April 26, 2016

Survey: Retail IT Professionals Confidence in Cyber Security Capabilities Increase as Data Breaches Rise

One-third of retail IT professionals say a data breach has occurred at their company

PORTLAND, Ore. - April 26, 2016 - Tripwire today announced the results of its 2016 retail cyber security survey. Conducted by Dimensional Research, the survey evaluated the attitudes of over 200 IT professionals in the retail sector and compared their responses to a similar survey Tripwire conducted in 2014.

According to a report by Arbor Networks, it takes retailers an average of 197 days to detect advanced threats on their networks. However, Tripwire’s 2016 survey found that ninety percent of the respondents believe they could detect a data breach on critical systems in one week or less. In 2014, seventy percent of respondents believed they could detect a breach in one week or less.

"Unfortunately, these results indicate that we can expect retail breach activity to continue in the future," said Tim Erlin, director of IT security and risk strategy. "The increase in confidence connected with speed of breach detection is particularly surprising, especially in combination with partial implementation of detection tools. Together these results indicate while retail organizations might feel better about their cyber security capabilities, there's still a long way to go to close the gap between initial compromise and detection."

Additional findings from the study include:
  • Seventy-five percent of the 2016 respondents believed they could detect a breach within 48 hours, compared with forty-two percent in 2014. 
  • Retail data breaches involving personally identifiable information (PII) have more than doubled since 2014. When asked if a data breach occurred at their organization where PII was stolen or accessed by intruders, one-third (thirty-three percent) of the respondents said, "yes," compared with fourteen percent in 2014. 
  • Implementation of breach detection technology has remained flat. In both 2014 and 2016, fifty-nine percent of the respondents said their breach detection products were only partially or marginally implemented. Both surveys defined breach detection as anti-virus software, intrusion detection systems, malware detection, white listing and file integrity monitoring.
  • •Companies with larger revenues monitor configuration parameters on critical payment assets less frequently. Sixty-five percent of respondents working for organizations with revenues of less than $100 million check their compliance at least weekly, and only fifty-five percent of respondents with revenues of more than $100 million answered similarly.

Trend Micro recently reported that malware that affects point-of-sale (POS) systems grew sixty percent in the third quarter of 2015 alone. According to Verizon's 2015 Data Breach Investigations Report, attacks on POS systems continue to be the top source of confirmed data breaches.

Erlin continued, "Partially implemented tools are a serious liability for information security. Organizations need to move from a checkbox approach to measuring gaps in their security coverage. If you're not monitoring one hundred percent of your endpoints, you're leaving room for attackers to gain a foothold."

Wednesday, March 23, 2016

Why Most Companies Are Easy Prey for Cyber Attackers


Alarming Data Reveals Why Most Companies Are Easy Prey for Cyber Attackers

LONDON, UK, March 22, 2016 – Varonis Systems, Inc. today revealed the results of a year of anonymous data collected during risk assessments conducted for potential customers on a limited subset of their file systems. The 2015 results show a staggering level of exposure in corporate file systems, including an average of 9.9 million files per assessment that were accessible by every employee in the company.

Of the insights gleaned from dozens of customer risk assessments conducted in mid-to-large enterprises prior to remediation, in a subset of each company’s file systems, Varonis found the average company had:
35.3 million files, stored in 4 million folders, meaning the average folder has 8.8 files
  • 1.1 million folders, or an average of 28% of all folders, with “everyone” group permission enabled –open to all network users
  • 9.9 million files that were accessible by every employee in the company regardless of their roles
  • 2.8 million folders, or 70% of all folders, contained stale data – untouched for the past six months
  • 25,000 user accounts, with 7,700 of them or 31% “stale” – having not logged in for the past 60 days, suggesting former employees, employees who changed roles, or consultants and contractors whose engagements have ended
The ‘everyone’ group is a common convenience for permissions when originally set up. That mass access also makes it astonishingly easy for hackers to steal company data.

Some individual companies’ lowlights that were gleaned from the Varonis risk assessments:
In one company, every employee had access to 82% of the 6.1 million total folders.
  • Another company had more than 2 million files containing sensitive data (credit card, social security or account numbers) that everyone in the company could access.
  • 50% of another company’s folders had “everyone” group permission and more than 14,000 files in those folders were found to contain sensitive data.
  • A single company had more than 146,000 stale users – accounts whose users had not logged in for the past 60 days.  That’s nearly three times more users than the average FORTUNE 500 company has total employees.
David Gibson, Vice President of Strategy and Market Development at Varonis, said, “Although this data presents a bleak look at the average enterprise’s corporate file system environment, the organizations running these risk assessments are taking these challenges seriously. Most of them have since implemented Varonis, embracing a more holistic view of the data on their file and email systems and closing these gaping, often unseen security holes before the next major breach causes heavy damage. Our software is able to provide a granular look at where sensitive data lives, where it is over-exposed within an organization, who is accessing that data, and how to lock it down. While that remediation process is running, our ability to start detecting and stopping many types of insider threats has been a major revelation for our customers.”

Monday, November 9, 2015

Anyone Hit by the Power Worm Will Lose the Data Forever

Today's news reports that a new kind of ransomware, called Power Worm, contains coding mistakes that means anyone hit by it will be unable to recover their files, even if they pay the ransom. The coding errors mean that the worm destroys the keys that could help recover any data that the worm did scramble.

Fred Touchette, Manager of Security Research at AppRiver has shared the following insights:

Q. Power Worm - could it be deliberate instead of a mistake?
"It’s unlikely that this was a deliberate mistake. Creating malware that simply destroys files would be much easier than adding that sort of "functionality" into an already complex ransomware variant."

Q. Linux.encoder - what makes this one different to all the others?
"One of the main differences is that it attacks websites. Until now the biggest target group was the home and business end user. It makes sense that this type of malware, including their potential targets, would continue to evolve."

Q. It feels as if there's been a spike in ransomware - would you agree? Any stats that substantiate this?
"There has been an obvious spike, but I don't have metrics specific to this type of attack."

Q. Why is ransomware increasing?
"Ransomware is increasing because it is working. Victims continue to pay these cyber criminals and in turn, the bad guys keep doing what's working so well for them."

Q. Should organizations ever pay a ransom? Assuming not, what should they do instead?
"No. Organizations should backup their files."

Q. What else can be done to rid yourself of ransomware? Is there anything?
"Yes, #1 back up your files. #2 Stop paying criminals. Avoiding 100% of the damage caused by ransomware is quite simple, by having a backup of one’s data, all that needs to be done in case of a ransomware infection is to restore said backups. Also, aside from ransomware attacks, there are a million other reasons that people should backup their systems, it’s kind of amazing that these attacks are working so well."

Monday, August 17, 2015

Protect Your Data: Top Ten “Need to Know” Tips


Protect Your Data: Top Ten “Need to Know” Tips

By Dietrich Benjes, VP UK, Ireland and Middle East, Varonis Systems, Inc.

With breaches happening on an almost daily basis, it's critical to establish rules and processes to keep your data safe and secure.  The following tips, designed to help you build a sustainable path towards data security, were inspired by the FTC.

Don’t Make Security an Afterthought

Think before you collect.  Is it necessary and does it add value to capture personal, sensitive information from your customers and prospects?  Or does it just open up additional risk?  If you absolutely need to collect sensitive information, don’t hold on to it longer than necessary.  Set an “end date” and follow through with securely destroying the info.  Security shouldn’t be reactive but proactive.

Stay in Control

If you need to hold on to sensitive data (it’s a business must), then how do you keep it safe from prying eyes – both inside and outside your organization?  Answer: limit access.  Does your summer intern need wide-open access to corporate IP to do her job?  Probably not. Implement a system for periodically reviewing entitlements to ensure people only have access to the information they need. Your auditors will thank you.

Passwords and Authentication, Please

You’ve got sensitive data and want to keep it safe. Requiring complex passwords (by the way, “password” is NOT complex) that include multiple elements (caps, numbers, minimum characters) and changing them on a quarterly basis makes it hard for hackers.   Even better: require two-factor authentication, disable access after a specific number of failed login attempts, and protect against authentication bypass to really “up” the proverbial ante.

Share It Securely

Sure, your internal network is secure. But what if you need to share your data outside the firewall? One way to do this securely is with a data file sync and share solution that works with your existing permissions and authentication infrastructure.

Who’s Knocking on Your Door?

Do you know who is accessing what computer at all times?  Probably not. So protect yourself – and your sensitive data – in a separate, secure place on your network.  Limit access. Even better, continuously monitor your file access activity with a solution that makes it easy to see and address suspicious, unusual behavior before it’s too late.

Remote Control

Isn’t telecommuting great? It allows employee freedom and increased productivity. But it can be a security nightmare. The key idea is to allow remote connections, but restrict the ability to re-login to other desktop and servers. We really want to make it difficult for hackers to leapfrog around your network. This can be accomplished by enhancing security of the Remote Desktop feature in Windows. You can read more about how to do it here. 

Keep It Under Wraps

Is your organization developing a hot new product or solution? Have you thought about how your customers will use it and whether it needs to be secure? Make sure your developers are up to scratch with Privacy by Design principles, and the latest best practices in safe coding. In addition, know thy platform security guidelines – no need to recreate the wheel. Finally, testing is key!  While not every threat can be anticipated, testing for common vulnerabilities ensure security at the gate.

Who’s Got Your Back?

You probably work with service providers and other contractors. But do they share your passion for security? Make sure your standards are being met by including your security requirements (for example, encryption, two-factor authentication, data retention limits) in contracts and service-level agreements. Remember to stay active and always monitor your controls to ensure that your security expectations are followed and your users aren’t inadvertently exploited.

Make a Plan, Stan

You’re secure – for now.  Unfortunately, security isn’t static and so to remain compliant you’ll need to stay on top of your systems and technology.  This means making a plan that includes monitoring third party software, performing updates, and faithfully implementing patches.  In addition, pay heed to security warnings and notifications!  Develop an action plan! If a vulnerability has been exposed, be proactive and take the steps necessary to protect your data!

Physical Security

Network security is critical. But what about computer hardware, as well as paper files and all the miscellaneous stuff that makes up a typical office environment? Does your company have a security policy for the non-virtual world? Rule #1: keep important papers and other physical IP in a secure place (locked file cabinets, secured server rooms, etc.).  Laptops should have secure-login and hardware-level password protection set. What about old computers, servers, tapes, and disk drives?  What may appear as trash to you could be a gold mine to hackers.  

Monday, June 8, 2015

Who Knows More about You – The US, or China?

While I suspect China lags the US in knowing about its citizens, China might be catching up quickly.

In light of last week's 4 million strong data breach, described as one of the largest thefts of government data ever seen, TK Keanini, CTO at Lancope, offers the following.

"Last Thursday night, U.S. officials said that the Office of Personnel Management (OPM) had suffered a breach. Data from four million current and former federal employees, across numerous government agencies, may have been stolen by Chinese hackers. It does not take a security expert to see a pattern taking place here. Most of the attacks allegedly from China over the past few years have gone after the personal information of US citizens, and there is no sign that this trend will diminish. It is fair to assume at this point in the game, China may have more accurate information on US citizens than the US itself. 

"The OPM manages security clearances for various government organisations. During that process, employees must provide extreme detail to every aspect of their life – which is in turn stored and kept in the same systems that were breached.
 
"Organizational confidence takes a long-time to build, but can (and is) eroded much more quickly. Governmental breaches put these trusted government organizations in the same light as all the recent private company breaches (like Target, Home Depot). Much like your personal medial history, the big difference here is the government has much more sensitive data about their victims, and the victims have no choice in sharing that data.

"This attack once again exemplifies the need for more security resourcing in the federal government and the need for a different more comprehensive approach to incident detection and response. The current methodologies have lead to this breach – not avoided them. Attacks are being detected much too late in the attack continuum. Effective security these days means detecting these threat actors as they operate and before they exfiltrate data. You can't win all the battles but all of these headlines suggest that we are still on the losing side.

"In particular, organizations need to categorize and isolate what they need to protect, place additional controls around that information, and meticulously log & monitor access to that encrypted data.
For example, some past advanced attacks have targeted Windows administrative accounts. Smart organizations have realized this, and created a separate isolated set-up for domain admin accounts, with additional security controls around them (like dual factor authentication, jump boxes that are the only place domain admin activity can occur and logging and monitoring of that separate set-up). This isn’t fast, easy or cheap, but organizations have been pushed into adding these controls by ongoing attacks.

"In addition, organizations need to leverage telemetry, and leave hackers no place to hide. If there is a blind spot on your network, someone will be hiding there. Find them and remove them in a way that they can't get back in. These types of incident detection and response approaches have been vastly under-funded in the past, but as these hacks increase, we will see a shift in focus. Until organizations get better at doing this, we can guarantee that the Chinese will continue to have better data on US citizens than anyone in this country does and this information superiority is what scares me the most."

Wednesday, January 7, 2015

5 Industries Devastated by Data Breaches in 2014

Truth be told, it's not just these industries that have been devastated. It's everyone one of us. Clearly, the law of unintended consequences applies here. Whatever the main motivation behind making all systems Internet facing, it seems now that it was the wrong thing to do. We're sorely ill-equipped to defend systems against well-funded people whose only purpose in life is own those systems.

Wednesday, December 10, 2014

Game Changer: Court Rules that Target Is Liable for Not Preventing Breach


From Brian Foster, CTO of Damballa:

Almost one year to the day after Target suffered a breach during peak 2013 holiday shopping, a Minnesota court just handed them a lump of coal. In a ruling announced on December 2, 2014, the court said that Target can be sued for failing to prevent their data breach. Their rationale was: Target can be viewed as negligent for failing to heed warnings from its FireEye prevention system and for disabling the inline blocking feature.

Let that sink in a moment.

As an enterprise security professional, ask yourself, Do you immediately take devices off your network when you receive an alert from a prevention tool? Do you ever automatically block a device because of one alert?

I assume you answered “no” to both questions. If I’m wrong, I would love to meet you and understand how you manage the herculean feat of not grinding your network to a halt and handcuffing business operations. 

In a brand new, not-yet-published, security survey conducted by the Ponemon Institute, respondents said they receive an average of 17,000 alerts per week and only 19% are reliable. The rest are false positives.

Put yourself in Target’s shoes. They paid $1.6 million for a system that was supposed to prevent advanced attackers. What they got was a lot of alerts lost in a sea of other alerts –meaningless unless correlated with other pieces of evidence.

Again, ask yourself, which one of 17,000 alerts would you know with certainty to pay attention to?

While comments from a vendor defending themselves and their ability to spot the malware may have made Target's security team seem like the Keystone Kops, fumbling around, carelessly not investigating alerts, this is hardly the case. According to Ponemon, the average sized security staff involved in malware detection and contain is 17.1 full-time headcount. And those staff on average have 7.9 years of professional experience in their field. It’s difficult to view this highly skilled group as clueless and purposefully negligent.

I’m certain the security team at Target would have prevented their attack if it were at all humanly possible. They had lots of expensive tools. They had a full-time Security Operations Center. Apparently, what they lacked was any degree of certainty that the alerts fired by their prevention tools were actionable.

The discussion about prevention versus detection has become escalated this year. The Target court ruling will likely make the discussion a lightning rod. Security experts will tell you they know their prevention system can’t stop advanced threats. They are designed to identify potentially suspicious activity by known ‘bad’ entities, not the unknown. Cyber criminals learned to outsmart those systems with ease.

Ask any CISO what keeps them up at night and they will tell you it’s the ‘unknowns.’ I imagine today’s court ruling will cause many CISOs to lose a few hours more sleep tonight.

Tuesday, December 9, 2014

New Survey Shows Widespread Employee Access to Sensitive Files Puts Critical Data at Risk


It's been 18 months since Snowden demonstrated the inability of the Puzzle Palace to identify and mitigate internal threats. Now, a new survey from Varonis Systems and the Ponemon Institute suggests--not surprisingly--that most organizations are having difficulty balancing the need for improved security with employee productivity demands. Employees with needlessly excessive data access privileges represent a growing risk for organizations due to both accidental and conscious exposure of sensitive or critical data.

Thursday, February 6, 2014

Data Privacy Day Tips


I have to confess that I was unaware that Data Privacy Day was last week.

Data Privacy Day occurs every year on January 28 and is intended to remind us to more carefully consider our privacy choices throughout the year.

Computer users are encouraged to think about privacy choices the next time a new online profile is created, or load an app on a phone, or sign up for a frequent shopper card at your favorite retail establishment.

“And with the big data movement hell bent on collecting as much information about us whenever possible, apparently innocuous or unimportant details can be pieced together in new and surprising ways,” said Chester Wisniewski, senior security advisory at Sophos.

Following are three simple privacy diet tips from Sophos to help trim the fat and protect user’s privacy:

1. Turn off geolocation, and leave it off.
Whether you're a Twitter user, a soldier in a war zone, or a fugitive from the law, geolocation can carry serious unintended consequences even when it's used on purpose.

Users have to be careful to avoid being tripped up by a steady supply of less-than-honest app writers. Geolocation data has been silently hoovered up and sent home by phone software as diverse as flashlights and mobile apps for kids.

2. Turn off Wi-Fi. Turn it on when you need it.
To trim the next few privacy pounds dieters need to turn off Wi-Fi on their smartphones, tablets and laptops. You can still use Wi-Fi but you have to switch it on when you need it and turn it off again when you don't.

As it searches for networks to join, your phone will offer up the names of Wi-Fi networks you've used previously. Many Wi-Fi networks are named after the places where they're located, so that your phone's electronic greeting can read like a history of where you've been. Alongside the networks it's joined your phone will also broadcast its MAC address almost constantly. Commercial organizations have begun to show serious interest in that little unique ID because it can be used just like a cookie to track and profile your movement in the real world.

3. Log out when you have finished
Dieters on the Privacy Plan should log out of any system they've finished with. Stopped using your laptop? Log out. Checked your bank balance? Log out. Done updating your Facebook status? Log out. Everything you've used but haven't logged out of is an open back door that leaves your privacy at the mercy of Clickjacking attempts, Cross-Site Referral Forgery attacks, social media tracking beacons and people just sitting at your keyboard when you're not there.

“Data Privacy Day is the perfect time to think about all the computing devices and gadgets you use, including smartphones and tablets,” said Rebecca Herold, an information security and privacy expert, internationally recognized as "The Privacy Professor," and author of  Managing an Information Security and Privacy Awareness and Training Program, now in its second edition. “Many people don’t realize these devices are continually collecting personal information about the user, such as where you work or attend school, travel, shop … the list goes on. Everyone should be aware of the information they are putting out there and the data being collected without their knowledge or consent.

“As we embark on 2014, we truly are in a new and expanding ‘Internet of Things’ where numerous amounts of data are being collected every day. All individuals, businesses and government organizations should make privacy a priority by being educated about new, expanding data collection points and put appropriate protections in place to protect personal information,” added Herold.
Herold encourages all consumers to ensure they aren’t giving away too much information when their personal data is collected, and she believes they have the right to demand that the entities collecting their information are protecting it and using it properly.

Friday, October 18, 2013

GAO: Centers for Medicare and Medicaid Services Needs to Pursue a Solution for Removing Social Security Numbers from Cards

The GAO recommends that CMS initiate an IT project to develop a solution for SSN removal and incorporate such a project into plans for ongoing IT modernization initiatives. HHS agreed with GAO's recommendations, if certain constraints were addressed. However, GAO maintains that its recommendations are warranted as originally stated.

What they really need to do is de-identify and anonymize data.

Of course, we have books that will help solve the problem.

Guide to the De-Identification of Personal Health Information 

In this book Khaled El Emam, the founder and CEO of Privacy Analytics, Inc., offers compelling practical and legal reasons why de-identification should be one of the main approaches to protecting patients’ privacy, this book outlines a proven, risk-based methodology for the de-identification of sensitive health information. It situates and contextualizes this risk-based methodology and provides a general overview of its steps. The book supplies a detailed case for why de-identification is important as well as best practices to help you pin point when it is necessary to apply de-identification in the disclosure of personal health information.

The Complete Book of Data Anonymization: From Planning to Implementation

Data anonymization provides a systematic and integrated approach to privacy protection that goes far beyond simple data-masking or network security from external or internal theft. In book, Balaji Raghunathan of Infosys Ltd. discusses the analysis, planning, set-up, and governance, this timely manual illuminates the entire process of adapting and implementing anonymization tools and programs to increase the success of privacy protection in vulnerable organizations. Providing a 360 degree view of data privacy protection, it details data anonymization patterns, automation/tool capabilities, and the key factors for success in disguising the person behind the data.

Monday, November 28, 2011

Ease of theft of IRS refunds has eveyone doing it

This is a scary story from the Miami Herald about street criminals joining scammers to steal IRS refunds, as well as identities, with ease. Imagine killing a postman on his rounds to get the master key to condo mailboxes. The arrest and conviction rate is certainly higher for street crimes than for cybercrimes. Evidently the ease of the former make it attractive nevertheless.