Access and Feeds

Security: 2011 – 'Year of the Breach'

By Dick Weisinger

Collin J. Zick, lawyer at Foley Hoag LLP,  wrote on the blog Security, Privacy and the Law that 2011 is shaping up to be the “Year of the Breach“.   Zick lists the following major breaches that have occurred so far this year:

Epsilon: loss of customer email addresses
RSA:  loss of security tokens
Citigroup: loss of credit card numbers
Sony: loss of customer data
Sega: loss of customer data
ADP: loss of benefits-administration data
But that is only an abbreviated list.  Other high-profile breaches include:
Bank of America – data breach related to check scam
Texas Comptrollers Office – loss of personal identifying information
New York Yankees – loss of personal identifying information for fan base
Fox Entertainment – loss of personal identifying information

And the list seems to go on.  Tom Murphy, chief strategy officer at Bit9, said that  “Breaches that occurred in the first half of 2011 have changed the rules of security by exposing high profile companies like RSA, Sony, Lockheed Martin and numerous others.  Our data finds that companies are increasingly worried about advanced persistent threat attacks, but they continue to engage in risky behaviors. Companies are gambling on a losing game by failing to put security policies in place. It’s not a case of if a breach will occur, but when and how severe.”

How are the breaches caused?  A 2011 Data breach report by Verizon found the following breakdown for breach incidents:

  • 50% – Hacking
  • 49% – Malware
  • 29% – Physical Attack
  • 17% – Privilege misuse
  • 11% – Social tactics

But while high-profile attacks have gotten the attention of many IT organizations.  The Bit9 security report finds that many IT organizations are overlooking some basic security measures that leave themselves vulnerable.   The report found that as many as 60 percent of IT organizations rely on the ‘honor system’ for enforcing written security policies.  Two-thirds of companies have no restrictions on downloads — and of those companies, 40 percent were found to have computers infected with spyware and one-third had malware.

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*