Lessons learned from corporate security breaches
Computerworld - With information security breaches in the U.S. now reported at a rate of one every three days, corporate privacy and security officers need to take stock about what's happening and what they can do about it.
So what's going on? According to the Privacy Rights Clearinghouse (PRC), 61 U.S. organizations have reported exposures of personal information in the past 180 days. PRC keeps the best list of breaches reported since February's watershed incident at ChoicePoint, where criminals obtained 145,000 customer accounts and sparked a series of congressional hearings on the subject of data security.
What's at the root of these breaches? The PRC reports that the leading cause is external hackers, accounting for half of the incidents. A quarter resulted from stolen laptops and computers. Dishonest insiders, lost backup tapes and negligent employees and business processes accounted for the remaining quarter (see table 1).
And I think we've seen only the beginning of this phenomenon. Why's that? Two reasons. Nineteen states have now joined California in requiring organizations to notify individuals if their Social Security numbers, driver's license numbers, financial account numbers or other sensitive information is exposed to unauthorized people (see table 2). Companies effectively must now notify all U.S. residents of breaches affecting their sensitive information, so this notification phenomenon is here to stay.
The second reason is that companies are still learning how to detect and report these breaches. A 2005 Ponemon Institute survey of corporate privacy practices found that only a third of companies use a formal process to monitor and report security breaches. As companies improve these procedures, they'll be reporting more incidents (see Opinion: After a privacy breach, how should you break the news?).
What'll be the impact of a continuing stream of publicized security breaches? It won't do anything good for customer confidence. A Conference Board survey released in June reported that 41% of customers are purchasing less online than a year ago because of security fears (see Survey: Consumers growing wary of buying online). Trends like this affect all companies, even those with solid security.
But the impact will be greatest on those companies experiencing major publicized breaches. For its part, ChoicePoint has registered $11.4 million in charges related to its security breach (see ChoicePoint says data theft cost it $6M) and endured a sustained, $6 drop in its share price. CardSystems International, which suffered an external hack that exposed 40 million customer accounts, is facing financial ruin following the loss of its Visa and American Express clients (see Visa, Amex cut ties with processing firm hit by security breach).


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Intelligent Systems: Unlocking Hidden Business Value with Data
- An intelligent system enables data to flow across an enterprise infrastructure, spanning the devices where valuable data is gathered from employees and customers,...
- The Executive Buyer's Guide to Project Portfolio Management
- The Innotas Executive Buyer's Guide provides you with a concise overview of Project Portfolio Management (PPM) and delivers important buying criteria to help...
- Eight Considerations for Evaluating Disk-Based Backup Solutions
- In the past, the movement from tape- to disk-based backup has been less compelling due to the expense of storing backup data on...
- ExaGrid Helps U.S. Federal Government Agencies Reduce Backup Windows and Improve Data Protection
- The U.S. Government has been the largest user of tape-based backup systems since the 1970s. Most agencies have begun to deploy disk storage...
- Centralized Virtual Desktop Eases PC Procurement, Deployment, and Management
- Centralized virtual desktop, or CVD, is a form of server-based computing. CVD utilizes a server-grade hypervisor to host multiple unique and isolated client... All Privacy White Papers
- A Road Map for Best Practice Social Media Acceptable Use Policy
- Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Banking on the Mainframe
- This presentation will look at banking application issues and provide examples on how banks and financial market clients are responding to these challenges.
- Banish Poor Application Performance: Eliminate Business Disruptions, Increase End User Productivity
- End User Experience, 30-Min Webinar
Wed. Feb. 22nd ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Spear Phishing and the Modern Cyber Attack
- Learn how IT teams can protect against spear phishing tactics. Harry Sverdlove, chief technology officer of Bit9 offers a frank discussion about spear... All Privacy Webcasts