NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 


Wed, Aug 27, 2008 16:41 EDT

It’s Time to Think Differently About Protecting Data

Topic: Enterprise Management

Current Rating: 5 Comments: 0

Introduction

The recent rash of high profile security breaches, data loss incidents and associated fraud highlights the fact that the security industry is failing to meet the threats organizations face when it comes to protecting the lifeblood of their business – their data and their customer’s data. As the threats of data loss continue to increase, it’s time for IT, CIOs, CEOs, Boards and security practitioners around the world to fundamentally reexamine their approach to security; and, instead make security a strategic, enterprise-wide initiative focused on protecting the most valuable asset: the data.

Protecting Data Within the Corporation

The value, quantity and mobility of data has increased to a level where any lost or stolen laptop or mobile device can lead to a significant loss of highly sensitive information. The recent examples of data loss are numerous and well-publicized. At Anheuser-Busch, a stolen laptop exposed 90,000 employees’ Social Security numbers and home addresses. At Countrywide Financial, a former employee compromised 2 million records, including Social Security Numbers of mortgage applicants which were then sold for profit to Internet thieves. At TJX, and other retail companies, the largest recorded data breech story continues to grow with the current count exceeding 100 million credit card users affected and has cost TJX and Visa over $40M in settlement costs. These examples represent the tip of a growing iceberg.

An analysis of these breaches points to a combination of vulnerabilities and threats. Networks are porous – given the mobility of data there is no effective “network perimeter” to protect. Computers are porous – given the size and complexity of the Windows environment and applications, it’s impossible to protect against all system vulnerabilities. In spite of a myriad and confusing array of security products – anti-virus, firewalls, host intrusion protection, network monitoring, etc. – corporate systems are becoming infected and compromised at an alarming rate, due in no small part to the growing sophistication and syndication of hackers and cybercriminals.

In addition to the external criminal threat, threats arise from insiders having access to increasing amounts of sensitive information. The risk of employees stealing information is real. A research chemist at DuPont who downloaded 22,000 sensitive documents prior to accepting a job at a competitor ended up pleading guilty to trying to steal $400M worth of company trade secrets. An employee of Ferrari stole trade secrets and took them to a rival competitor, McLaren. Luckily, by having the appropriate data controls in place, Ferrari was able to identify the breech and effectively prosecute the case to the tune of a $100M fine against McLaren, the largest in Formula One history.

Certainly, very little insider behavior is purposely malicious. However, through a lack of knowledge of information policies, improper training, perceived expediency or simple negligence, insiders can put sensitive data at risk. In addition, new information security demands arise as business models evolve. Ever-expanding supply chains, the growth in off-shoring and outsourcing, and the move to put more services and data online bring new potential for exposure.

The security industry is focused on the wrong problem. Data loss is not an infrastructure or network problem; it’s about protecting a company’s information where it’s at the greatest risk – whenever and wherever it is in use. It is only at the point of use where data can be effectively controlled. The challenge – and where the focus should be – is on expanding the coverage of effective information controls that can be applied where data is used. These controls need to be extended to anywhere and everywhere sensitive information exists and is used – this includes going beyond the corporate network; beyond the VPN;

You do not have flash or javascript support.
Average (1 vote)
5
 
Start a Conversation
Click to post

Got something to say? We want to hear it! Click the Post button to get started. GO»

EXPERT ADVICE
See our roster of experts.

Advice & Opinion from more than 97 of IT's most insightful thinkers.

advertisement

  PARTNERS       WEBCASTS    
 

From Laggard to Leader: Transforming the Data Center

This webcast offers an understanding of how customers are transforming their data centers, the successes and challenges of each approach, and how IT can become the driver to provide real business value and competitive advantage.

Sponsored by HP  Register for this Webcast »

 

Raising the Bar on Business Service Delivery

Applications drive every business, but as networks become more complex and dynamic, performance has become a key tenant in service delivery. In this CIO webcast, Forrester and Fluke Networks offer advice and best practices for ensuring high delivery with better application performance.

Sponsored by Fluke  Watch this webcast. »

 

Conquering Information Management Challenges: Turning tacit knowledge into actionable insight

It's no surprise that enterprises are adopting strategies to aggregate data into actionable intelligence. This research paper explores how leading enterprises are rising to the challenge - from imposing structure to developing an information management framework.

Sponsored by BearingPoint  Read this White Paper »

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

CIO Viewpoints on Exchange 2007 Risks and Mitigation Strategies

Knowing where your peers have found limits and workarounds in areas including high availability, archiving, recovery, compliance, e-Discovery and storage growth can be essential in planning your successful Exchange 2007 migration.  Read More »

 

Where's the CIO? -- The Missing Link in Your SOA Strategy

In this webinar, you'll hear why the time is now to grow the value you've achieved at a project level to an enterprise-wide ROI, how to do it, and what role the CIO can play to make your SOA strategy a success....  Read More »

 

Data Protection: Challenges for the Traveling User

Business today often involves traveling to meet with customers and partners directly...  Read More »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

 
NEWSLETTER

Sign-up for the Blogs & Discussion Newsletter

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Spend less. Get hosted UC. Get cash back. It's easy under a Cypress

Predict the future with HP Insight Power Manager

Log onto Hitachi True Stories, films inspired by the next great achievement

Earn PROFESSIONAL DOCTORATE Part-Time, Online at Syracuse University's iSchool

Make IT Work As One@novell.com

Predict the future with HP Insight Power Manager

HP LaserJet P4014n printer starting at $799 after $100 IS. www.hp.com

CIO Starter Kit includes useful resources created by top CIOs. Free Download>>

The Business of Managing Content: Xythos Document Management & Microsoft SharePoint

Virtualization Benchmark and TCO Analysis-Read Now

White Paper: Scaling Down HPC for Smaller Organizations

White Paper: Never Enough Compute Power?

Microsoft Windows Vista Cost and Benefit Estimator

White Paper: Efficient Desktop Application Management

White Paper: Take your Call Center to the Next Level

Is Your WLAN Helping You Comply with Security Guidelines of the PCI Standard?

White Paper: Improve Employee Efficiency and Reduce Telecom Costs

White Paper: Green Issues for Networking

New IDG Survey Results on Data Center Automation

A CISO's Guide to Application Security

Operational Excellence Is Key to Maximizing IT Investments

Learn how companies are changing how they reach out to their most profitable customers.

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

The Customer Communications Management Platform - Key Functionality and Best Practices

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Affordable technology-no compromise. HP server solutions

SOA Educational Library at the TIBCO SOA Resource Center

CIO Viewpoints: Migrating to Exchange 2007

Thrive during global disruption. Cisco video featuring Juan Enriquez

A new level of interoperability. Make IT Work As One@novell.com

Protect data-HP All-in-One and Disk-Based systems

Businesses Transform with VMware Virtualization

Download the free CIO Starter Kit to access useful resources created by top CIOs

Leveraging Social Computing Technologies for ERP Applications

Server Virtualization Benchmark Results

Learn to Leverage Maximum Computing Power

Windows Vista: Essential Benefits and Deployment Strategies

Best Practices: Safe and Secure Hardware Asset Recovery

White Paper: Migrating to Windows Vista and Microsoft Office 2007 Together

White Paper: Enabling Next Generation IP Communications

White Paper: A Cohesive Network Security Approach

Why Your Firewall, VPN, and IEEE Aren't Enough to Protect Your Network

Dramatically boost network capacity and speed-up to 600 Mbps

White Paper: The Roadmap to Data Center Automation

17 Ways to Reduce Cost in IT

Learning from BPM Leaders

A fresh look at the impact of customer intimacy.

Webcast: Mitigate Operational Risk- Real Answers for Tough Times

Laptop Security: Where Do CIOs See Weaknesses?

Paving the Way for Trusted Collaboration