{"id":2452,"date":"2011-10-06T07:00:38","date_gmt":"2011-10-06T15:00:38","guid":{"rendered":"http:\/\/www.formtek.com\/blog\/?p=2452"},"modified":"2011-10-06T07:00:38","modified_gmt":"2011-10-06T15:00:38","slug":"security-2011-year-of-the-breach","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/security-2011-year-of-the-breach\/","title":{"rendered":"Security: 2011 &#8211; &#039;Year of the Breach&#039;"},"content":{"rendered":"<p><a title=\"Collin J. Zick\" href=\"http:\/\/www.foleyhoag.com\/people\/attorneys\/zick-colin.aspx\" target=\"_blank\">Collin J. Zick<\/a>, lawyer at Foley Hoag LLP,\u00a0\u00a0wrote on the blog <a title=\"Year of the Breach -- 2011\" href=\"http:\/\/www.securityprivacyandthelaw.com\/2011\/06\/articles\/cybersecurity-cybercrime\/2011-the-year-of-the-breach\/\" target=\"_blank\">Security, Privacy and the Law<\/a> that 2011 is shaping up to be the &#8220;<em>Year of the Breach<\/em>&#8220;. \u00a0 Zick lists the following major breaches that have occurred so far this year:<\/p>\n<div id=\"_mcePaste\"><a title=\"Epsilon Data Breach\" href=\"http:\/\/www.zdnet.com\/blog\/btl\/epsilon-data-breach-whats-the-value-of-an-email-address\/46915\" target=\"_blank\">Epsilon<\/a>: loss of customer email addresses<\/div>\n<div id=\"_mcePaste\"><a title=\"RSA Security Breach\" href=\"http:\/\/www.bloomberg.com\/news\/2011-06-08\/emc-s-rsa-security-breach-may-cost-bank-customers-100-million.html\" target=\"_blank\">RSA<\/a>: \u00a0loss of security tokens<\/div>\n<div id=\"_mcePaste\"><a title=\"Citigroup data breach\" href=\"http:\/\/money.cnn.com\/2011\/06\/09\/news\/companies\/citi_credit_card_security_breach\/index.htm\" target=\"_blank\">Citigroup<\/a>: loss of credit card numbers<\/div>\n<div id=\"_mcePaste\"><a title=\"Sony Data Breach\" href=\"http:\/\/www.technewsworld.com\/story\/72520.html\" target=\"_blank\">Sony<\/a>: loss of customer data<\/div>\n<div id=\"_mcePaste\"><a title=\"Sega data breach\" href=\"http:\/\/blog.alertsec.com\/2011\/06\/video-game-maker-sega-the-latest-victim-of-data-breach\/\" target=\"_blank\">Sega<\/a>:\u00a0loss of customer data<\/div>\n<div id=\"_mcePaste\"><a title=\"ADP data breach\" href=\"http:\/\/www.programbusiness.com\/News\/ADP-Looking-Into-Data-Breach-of-One-its-Clients\" target=\"_blank\">ADP<\/a>: loss of benefits-administration data<\/div>\n<div><\/div>\n<div>But that is only an abbreviated list. \u00a0Other high-profile breaches include:<\/div>\n<div><\/div>\n<div><span style=\"color: #333333; font-family: Georgia; line-height: 21px;\"><a title=\"Bank of America\" href=\"http:\/\/www.infosecurity-us.com\/view\/18237\/insider-data-breach-costs-bank-of-america-over-10-million-says-secret-service\/\" target=\"_blank\">Bank of America<\/a> &#8211; data breach related to check scam<\/span><\/div>\n<div><span style=\"font-family: Georgia; color: #333333;\"><span style=\"line-height: 21px;\"><a title=\"Texas Comptroller Office\" href=\"http:\/\/www.dallasnews.com\/news\/state\/headlines\/20110411-breach-in-texas-comptrollers-office-exposes-3.5-million-social-security-numbers-birth-dates.ece\" target=\"_blank\">Texas Comptrollers Office<\/a> &#8211; loss of personal identifying information<\/span><\/span><\/div>\n<div><span style=\"font-family: Georgia; color: #333333;\"><span style=\"line-height: 21px;\"><a title=\"New York Yankees\" href=\"http:\/\/itacidentityblog.com\/new-york-yankees-experience-a-data-breach-who-is-next\" target=\"_blank\">New York Yankees<\/a> &#8211; loss of personal identifying information for fan base<\/span><\/span><\/div>\n<div><span style=\"font-family: Georgia; color: #333333;\"><span style=\"line-height: 21px;\"><a title=\"Fox Entertainment breach\" href=\"http:\/\/www.msnbc.msn.com\/id\/43027482\/ns\/technology_and_science-security\/\" target=\"_blank\">Fox Entertainment <\/a>&#8211; loss of personal identifying information<\/span><\/span><\/div>\n<p>And the list seems to go on. \u00a0<a title=\"Tom Murphy at Bit9\" href=\"http:\/\/www.linkedin.com\/in\/tomjmurphy\" target=\"_blank\">Tom Murphy<\/a>, <a title=\"Bit9 report on Security\" href=\"http:\/\/www.techjournalsouth.com\/2011\/08\/despite-year-of-the-hack-risky-security-behavior-common\/\" target=\"_blank\">chief strategy officer at Bit9<\/a>, said that \u00a0&#8220;Breaches that occurred in the first half of 2011 have changed the rules of security by exposing high profile companies like RSA, Sony, Lockheed Martin and numerous others. \u00a0Our data finds that companies are increasingly worried about advanced persistent threat attacks, but they continue to engage in risky behaviors. Companies are gambling on a losing game by failing to put security policies in place. It\u2019s not a case of if a breach will occur, but when and how severe.&#8221;<\/p>\n<p>How are the breaches caused? \u00a0A <a title=\"Verizon 2011 Data Breach Report\" href=\"http:\/\/www.verizonbusiness.com\/resources\/reports\/rp_data-breach-investigations-report-2011_en_xg.pdf\" target=\"_blank\">2011 Data breach report by Verizon<\/a> found the following breakdown for breach incidents:<\/p>\n<ul>\n<li>50% &#8211; Hacking<\/li>\n<li>49% &#8211; Malware<\/li>\n<li>29% &#8211; Physical Attack<\/li>\n<li>17% &#8211; Privilege misuse<\/li>\n<li>11% &#8211; Social tactics<\/li>\n<\/ul>\n<p>But while high-profile attacks have gotten the attention of many IT organizations. \u00a0The <a title=\"Bit9 Security Report\" href=\"http:\/\/www.bit9.com\/files\/Survey_Bit9_Endpoint_August_2011_FINAL.pdf\" target=\"_blank\">Bit9 security report<\/a> finds that many IT organizations are overlooking some basic security measures that leave themselves vulnerable. \u00a0 The report found that as many as 60 percent of IT organizations rely on the &#8216;honor system&#8217; for enforcing written security policies. \u00a0Two-thirds of companies have no restrictions on downloads &#8212; and of those companies, 40 percent were found to have computers infected with spyware and one-third had malware.<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-2011-year-of-the-breach%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Collin J. Zick, lawyer at Foley Hoag LLP,\u00a0\u00a0wrote on the blog Security, Privacy and the Law that 2011 is shaping up to be the &#8220;Year of the Breach&#8220;. \u00a0 Zick lists the following major breaches that have occurred so far<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/security-2011-year-of-the-breach\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-2452","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/2452","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=2452"}],"version-history":[{"count":0,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/2452\/revisions"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=2452"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=2452"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=2452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}