Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

February 24, 2009

Employee Suing Starbucks For Poor Security & Laptop Theft

Here's an interesting progression in how to address the growing data breaches that occur largely from ignored, overlooked, and/or inadequate security practices...

 
Continue reading Employee Suing Starbucks For Poor Security & Laptop Theft...

January 19, 2009

Business Info Fact Of The Day: Most Personnel Do Not Protect Laptop Information

The Ponemon Institute seems to have been busy doing surveys throughout the world recently!

According to three separate research surveys they did in the U.S., Canada and the U.K. they report within the BNA Privacy and Security Law Reports (subscription required) about "The Human Factor in Laptop Encryption" many interesting findings. The following are some of the high-level summary statements; see the full reports for some very interesting statistics and analysis:

 
Continue reading Business Info Fact Of The Day: Most Personnel Do Not Protect Laptop Information...

December 29, 2008

Insider Threat Example: 19,000 Pieces Of Computer Equipment Stolen; Why Didn't Someone Notice?

Okay, this story begs the question, why didn't someone at the Naval Research Laboratory notice disappearing equipment...?

 
Continue reading Insider Threat Example: 19,000 Pieces Of Computer Equipment Stolen; Why Didn't Someone Notice?...

August 30, 2008

Laptop Containing PII of 1 Million+ People Sold On eBay for $141

I've been doing a lot of work with data retention and disposal policies and procedures lately, remembering the silly things I have read about with regard to organizations getting rid of their computers, such as selling their computers on eBay when they no longer need them...without removing the information! This is certainly not a phenomenon that is confined to the U.S.

Lo and behold, another situation has happened where an organization sold their old computer on eBay...for a bargain at £77 ($141), and it contained a a huge amount of personally identifiable information (PII), including credit card applications, on what is reported to be as many as over 1 million customers. Here are a few excerpts from the report in Forbes...

 
Continue reading Laptop Containing PII of 1 Million+ People Sold On eBay for $141...

July 15, 2008

630,000+ Laptops Lost at Airports Each Year!

My good friend Alec sent me some great links to statistics about the numbers of laptops lost at airports each year...thanks Alec! :)

Here they are...

 
Continue reading 630,000+ Laptops Lost at Airports Each Year!...

June 20, 2008

Six Ways Organizations Can Lessen Mobile Computing Risks

Geesh, every single day there is at least one news report about a stolen or lost mobile (laptop, notebook, PDA, Blackberry, etc.) computer! Today one of the reports was about a laptop computer, containing cleartext information about 11,000 hospital patients, that was stolen from a doctor's home in Staffordshire, U.K.

A couple of days ago I posted the first section from the second article in my "IT Compliance in Realtime" journal issue for June.

Here's the second section from that article...

 
Continue reading Six Ways Organizations Can Lessen Mobile Computing Risks...

June 18, 2008

Mobile Computing Security Problems Exist Throughout the World

Every day, literally, I read news reports about lost or stolen laptops. Today is no exception. The news report, "A Misconfigured Laptop, a Wrecked Life," chronicles how one man had his first work laptop stolen, and then he was fired when the second work laptop he was issued as a replacement was found to have pornography on it...either it was pre-loaded when he got it, or lack of prevention software allowed someone to remotely load it on his computer while he was online.

 
Continue reading Mobile Computing Security Problems Exist Throughout the World...

March 25, 2008

Yet Another Stolen Laptop With Clear Text Patient PII

Yet another in a long procession of laptop thefs, "Stolen laptop contains personal info of 2,500 patients".

Here are the first few paragraphs...

 
Continue reading Yet Another Stolen Laptop With Clear Text Patient PII...

March 6, 2007

How Good are the Security Practices for "America's Most Admired Companies 2007"?

Yesterday CNN reported the results of the FORTUNE 2007 survey of business people for the companies, in any industry, they admired most.

The rankings were based upon 8 key score areas:

 
Continue reading How Good are the Security Practices for "America's Most Admired Companies 2007"?...

February 18, 2007

VA Suspends Medical Research Following Most Recent Breach Until Security Certification Is Obtained

Saturday, 2/17/07, it was widely reported that the U.S. Veterans Affairs (VA) was suspending "activities at seven specialized research centers across the country after an unprotected computer hard drive disappeared from one of the facilities in Alabama last month."

 
Continue reading VA Suspends Medical Research Following Most Recent Breach Until Security Certification Is Obtained...

line

Rebecca Herold's Bio:

Rebecca Herold, CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for the past two decades. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the world's best privacy experts and on their list of the best privacy consulting firms in both 2007 and 2008. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 13th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.