NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 


Wed, Aug 27, 2008 16:41 EDT

It’s Time to Think Differently About Protecting Data

Topic: Enterprise Management

Current Rating: 5 Comments: 0

Introduction

The recent rash of high profile security breaches, data loss incidents and associated fraud highlights the fact that the security industry is failing to meet the threats organizations face when it comes to protecting the lifeblood of their business – their data and their customer’s data. As the threats of data loss continue to increase, it’s time for IT, CIOs, CEOs, Boards and security practitioners around the world to fundamentally reexamine their approach to security; and, instead make security a strategic, enterprise-wide initiative focused on protecting the most valuable asset: the data.

Protecting Data Within the Corporation

The value, quantity and mobility of data has increased to a level where any lost or stolen laptop or mobile device can lead to a significant loss of highly sensitive information. The recent examples of data loss are numerous and well-publicized. At Anheuser-Busch, a stolen laptop exposed 90,000 employees’ Social Security numbers and home addresses. At Countrywide Financial, a former employee compromised 2 million records, including Social Security Numbers of mortgage applicants which were then sold for profit to Internet thieves. At TJX, and other retail companies, the largest recorded data breech story continues to grow with the current count exceeding 100 million credit card users affected and has cost TJX and Visa over $40M in settlement costs. These examples represent the tip of a growing iceberg.

An analysis of these breaches points to a combination of vulnerabilities and threats. Networks are porous – given the mobility of data there is no effective “network perimeter” to protect. Computers are porous – given the size and complexity of the Windows environment and applications, it’s impossible to protect against all system vulnerabilities. In spite of a myriad and confusing array of security products – anti-virus, firewalls, host intrusion protection, network monitoring, etc. – corporate systems are becoming infected and compromised at an alarming rate, due in no small part to the growing sophistication and syndication of hackers and cybercriminals.

In addition to the external criminal threat, threats arise from insiders having access to increasing amounts of sensitive information. The risk of employees stealing information is real. A research chemist at DuPont who downloaded 22,000 sensitive documents prior to accepting a job at a competitor ended up pleading guilty to trying to steal $400M worth of company trade secrets. An employee of Ferrari stole trade secrets and took them to a rival competitor, McLaren. Luckily, by having the appropriate data controls in place, Ferrari was able to identify the breech and effectively prosecute the case to the tune of a $100M fine against McLaren, the largest in Formula One history.

Certainly, very little insider behavior is purposely malicious. However, through a lack of knowledge of information policies, improper training, perceived expediency or simple negligence, insiders can put sensitive data at risk. In addition, new information security demands arise as business models evolve. Ever-expanding supply chains, the growth in off-shoring and outsourcing, and the move to put more services and data online bring new potential for exposure.

The security industry is focused on the wrong problem. Data loss is not an infrastructure or network problem; it’s about protecting a company’s information where it’s at the greatest risk – whenever and wherever it is in use. It is only at the point of use where data can be effectively controlled. The challenge – and where the focus should be – is on expanding the coverage of effective information controls that can be applied where data is used. These controls need to be extended to anywhere and everywhere sensitive information exists and is used – this includes going beyond the corporate network; beyond the VPN;

You do not have flash or javascript support.
Average (1 vote)
5
 
Start a Conversation
Click to post

Got something to say? We want to hear it! Click the Post button to get started. GO»

EXPERT ADVICE
See our roster of experts.

Advice & Opinion from more than 108 of IT's most insightful thinkers.

  PARTNERS       WEBCASTS    
 

Preparing for the Next Cyber Attack

Ensure you are up-to-speed on the latest security technologies available to keep your network safe in this Executive Guide. Get a thorough assessment of the corporate security threat landscape. Protect your network with data leakage protection, NAC and other technologies explained in this report.

Sponsored by Qwest  Read this Executive Guide »

 

Cloud Building: 8 Ingredients for Internal Clouds

Cloud computing: a fundamentally new way to deploy IT services and functions cost-effectively and quickly. Learn how the VMware vCloud initiative dramatically improves how consumers access their information and experience applications as well as the 8 ingredients to get you going.

Sponsored by VMWare  Read this White Paper »

 

Investing in Business Analytics Technology

You're thinking now is the time to take the plunge into business analytics, but you still have some unanswered questions. This research summary addresses the most common questions and concerns surrounding the successful launch of a business analytics initiative. It also includes real-world examples of organizations already getting return on their investment.

Sponsored by SAS  Read this White Paper »

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

Improving Transparency and Accuracy in IT Cross Charging

During this Webcast you'll learn how KBC Group implemented SAP BusinessObjects Profitability and Cost Management and realized many benefits.   View Now »

 

Cost Savings and Risk Reduction with Effective Systems Management

Join us and see how Novell can help you respond to today's economic challenges by increasing productivity, reducing costs and aligning IT initiatives with overall business goals.  View Now »

 

Capitalize on Your SAP Content

Learn ways to improve your content management by viewing these Open Text webinars today.  View Now »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

 
NEWSLETTER

Sign-up for the Blogs & Discussion Newsletter

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Introducing the new HP ProLiant G6 server family

Accenture: Outsourcing for Competitive Advantage. More...

Better spam protection with Postini for just $1/user/mo

Introducing the new HP ProLiant G6 server family

infoBOOM! - The Mid-Sized Company CIO's Exclusive Community

Accenture IT Consulting: Logical meets technological. More . . .

The Fraudster Economy Model: Operating a Business in the Underground

Trade in your old laser printer and get up to $1000 back!

Taking the Service Desk to the Next Level

Revolutionizing Enterprise Application Deployment

Why Data Loss is Increasing--and What You Can Do About It

Data Loss Prevention: A Better Way to Approach Security

Learn how to managing client systems in the enterprise.

Build a High-Performance Open Web Platform

Mid-Sized Company CIO Community: infoBOOM!

Enterprise PBX Comparison Guide

Getting Value from Outdated Networking Equipment

Losing Ground: 2009 TMT Global Security Survey

Stop Application Fraud at the Source with Device Reputation

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

Learn how to save 30% through project & portfolio management.

How Open Source is Changing the Face of Enterprise Software

8 Key Ingredients to Building an Internal Cloud

Accenture IT Consulting: Enabling high performance. More...

Top Five CIO Challenges

Insight makes it easy to spend your Microsoft subsidy check.

Five minute business analytics assessment. Immediate results.

Dangerous Collaboration Practices: 5 Ways IT Can Minimize Risk

Accenture: Outsourcing for uncertain times. Click to learn more.

The Case for Investing in Business Analytics Technology. Read white paper.

Live Webinar: Applying Business Analytics. Click here to learn more

Seven Ways ITIL Can Help You in an Economic Downturn

Developing A Dynamic, Real-Time IT Infrastructure

Maximizing the Business Value of the PC Infrastructure

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Cloud Computing: Read about VMware's compelling vision & set of products

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

How Interactive Viewer Reduces the Effort to Meet Visualization Requirements

Top-line Performance that's Bottom-line Efficient

White Paper: 8 Key Ingredients to Building an Internal Cloud

Read about virtualization and consolidation effort best practices

Building the Virtualized Enterprise with VMware Infrastructure

The Global Marketplace Today: Strategies for Tough Times

Top 10 Business and IT Drivers for the Wealth Management Sector

5 Steps to Automating Accounts Payable

Bottom-Line Benefits of Virtualization