Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Virus and Vulnerability Roundup
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Data breach at Progressive highlights insider threat

An employee, later fired, improperly accessed data on foreclosed properties
 

Sign up to receive Security Resource Alerts

April 06, 2006 (Computerworld) -- A recent case in which an employee at Progressive Casualty Insurance Co. wrongfully accessed information on foreclosure properties she was interested in buying highlights again the dangers posed to corporate security by insiders.

Progressive officials today confirmed that the company sent out letters in January to 13 people informing them that confidential information, including names, Social Security numbers, birth dates and property addresses had been wrongfully accessed by an employee who has since been fired.

Michael O’Connor, a spokesman for the Mayfield Village, Ohio-based company, said officials were alerted to the situation when a local woman complained about receiving calls from a Progressive agent inquiring about her house being under foreclosure.

“What happened was that the former employee, who purchased foreclosure property, wrongly used the information in a real estate database,” O’Connor said. Though there was no actual hacking involved to get at the data, her actions constituted a violation of Progressive’s code of ethics, O’Connor said.

“We investigated the situation, the employee was terminated, and we alerted the people whose data was accessed,” he said, adding that the matter was resolved in January.

Such incidents underscore the threat posed to corporate data by malicious insiders and by workers who accidentally leak sensitive information, said Phil Neray, a vice president at Guardium Inc., a Waltham, Mass.-based vendor of database security products. “Most companies have done a good job with perimeter security” and are now finding out they need similar controls internally, Neray said.

The trend is behind a growing need for tools that help companies monitor, detect and audit all activity going on inside networks, databases and applications, he said.

One such tool from Reconnex Corp. has been helping Sirva Inc., a Westmont, Ill.-based provider of relocation services with more than 7,000 employees worldwide, keep tabs on its intellectual property and other sensitive data while the company goes through a series of divestitures.

“One of the things that happens after a divestiture is that people take the stuff they are working on to their new companies,” and Sirva needed a way to prevent that, said Chuck Shmayel, vice president of infrastructure and security at the company. Reconnex’s appliance sits at Sirva’s network-egress points in each of its four data centers and monitors traffic to ensure that confidential information doesn’t exit its networks, either by accident or design.

“As a relocation service, we handle a lot of confidential information on behalf of our customers, and we want to make sure it's protected,” he said.

Implementing specific controls for monitoring what’s flowing out of enterprise networks can go a long way towards mitigating accidental and deliberate data leaks, said Mark Moroses, senior director of technical services at Maimonides Medical Center in Brooklyn, N.Y.

As an entity covered by the Health Insurance Portability and Accountability Act, Maimonides is required by law to have controls for securing protected health information (PHI). The hospital is using Reconnex’s appliance to detect PHI leaving its networks in an unauthorized fashion, Moroses said.

“From our point of view, the insider threat comes from people either knowingly or unknowingly damaging our reputation” by leaking sensitive information, Moroses said. “Patients come here for AIDS tests and for pregnancy tests that they don’t want to share” with other people, he said. “A patient is not going to come to our hospital if they think we are not doing everything to protect their information. So our reputation is paramount because it affects our bottom-line business."




Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"Debian, the popular Linux distribution has just been shown to have made an all-time stupid security goof-up. They managed to..." Read more...
"Houston area overrun by ants -- no, not atomic mutants. Sorry. Maybe even worse. At least you could kill Them..." Read more...
Read more Security posts or See all Blogs
Tools circulate that crack Debian, Ubuntu keys
Former Microsoft manager offers free fix for XP SP3 'endless reboot'
Can Icahn take on the Yahoo board and win?
More top stories...
DNS trouble knocks NSA off Internet
Developers confirm, explain why they're avoiding Windows Vista
NASA moves to save computers from swarming ants
Specialists have retrieved about 99% of the data on a disk drive on board the crashed space shuttle Columbia. Don't miss the photographs of the recovered drive.
These big ideas were supposed to revolutionize technology, but they never actually appeared. In a few cases, you'll be glad they didn't.
Nearly 20 years after the first Internet worm, Steven J. Vaughan-Nichols takes stock of the malware/anti-malware landscape and spotlights how the two sides are approaching the battle.
Though some thought it was released too soon, Mac OS X 10.5 has matured into a solid operating system, says reviewer Michael DeAgonia.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Enterprise-Class Security Zone
Enterprise Solutions Zone
The File Data Management Zone
Grid Computing on Windows Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Storage Virtualization Zone
The Data Center Management Zone

Ads by TechWords

See your link here
Long Tail Supplier Collaboration - What's In It For You?
Long Tail Supplier Collaboration - What's In It For You?
Download this webcast, free, compliments of Sterling Commerce
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Universal Threat Management - Because Conventional UTM is Not Enough!
Get this white paper now!
(Source: Juniper Networks) This white paper, written by Mark Bouchard of Missing Link Security Services, examines the challenges confronting today's enterprises with respect to managing threats on a network. It also discusses the need for "Universal Threat Management", which is a security solution approach for all physical locations within an enterprise that require threat protection.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Six Support Issues That Keep Execs Awake at Night
Spam Spikes: A Real Risk to Your Business
The New Foundation of Storage: Xiotech's Intelligent Storage Element
View more whitepapers 

2008 Internet Security Trends Report
For a time, security controls designed to manage spam, viruses, and malware were working. Loud, high-impact attacks abated. But, as a result of this success, the threats they protected against were forced to change. In 2007, many of these threats underwent significant adaptation. Malware went stealth, and the sophistication increased.

Download this white paper 
Multi-layer Spam Defense Architectural Overview
Today’s spam attacks have become too sophisticated for earlier-generation spam systems. These systems share a common weakness – relying heavily on analyzing content that can easily be manipulated by spammers. State of the art anti-spam systems must go beyond content examination and analyze messages in the full context in which they are sent.

Download this white paper 
Data Loss Prevention Best Practices
Data loss prevention (DLP) is a serious issue for companies, as the number of incidents (and the cost to those experiencing them) continues to increase. Whether it’s a malicious attempt, or an inadvertent mistake, data loss can diminish a company’s brand, reduce shareholder value, and damage the company’s goodwill and reputation.

Download this white paper