Showing posts with label ILP. Show all posts
Showing posts with label ILP. Show all posts

Friday, 31 October 2008

It might have been quiet on this blog for a while but elsewhere...

I know, I know, it has been a long while since I last posted to this blog! Thank you to all of you who have been checking in regularly.

It has been a busy six months both in terms of data loss instances and also for 3BView. In the case of the latter we have gained great new customers and partners in the intervening time ... you'll be able to find out more about some of them on our website - a new improved version of which is going live next week.

On the former: well watch this space. Many things to blog about, and I will be doing just that over the coming weeks.

Tuesday, 18 March 2008

Good eWeek article on DLP

EWeek has an interesting article comparing Database Activity Monitoring (DAM) with Data Leak Prevention (DLP).

In the article, Paul Proctor, a Gartner analyst who’s tracked this area for a while, says: “"Most every security monitoring technology would benefit from DLP content awareness, which is the ability to recognize sensitive content on the fly.” Yep, I’d agree with that.

Monday, 18 February 2008

Eli Lilly’s lawyers accidentally emails confidential info to New York Times

We’ve been here before, but this is a corker. All the pieces of a classic ILP mistake: the $1bn lawsuit, the external law firm accidentally emailing confidential information to the wrong person, and the fact that the wrong person happened to be a New York Times reporter. Oops.

Law firms, get yourself some ILP tools now, before it’s you!

Wednesday, 30 January 2008

Scottish council caught out by tracked changes

It’s that old classic: sending out a Word document with information you really, really don’t want to reveal left in tracked changes.

This time the metadata culprit is Aberdeenshire County Council, which managed to send out a report on waste management, containing incriminating details of problems in tracked changes that hadn’t made it into the final report.

Even worse than the information revealed is the inference that the council had covered up the information it didn’t like on the problems – and the press has certainly taken this line.

Saturday, 19 January 2008

That Jeremy Clarkson story

I know I’m coming a little late to this story and there’s been a lot of debate about it. In case you’ve not read about this: the UK TV presenter Jeremy Clarkson published his bank details in a newspaper column, in which he claimed the furore about lost personal details from the HRMC was a fuss about nothing. Of course, a kind soul promptly used the details to set up a direct debit payment from Clarkson’s account to a charity.

On reflection, you could argue that in fact the system works – the UK’s direct debit scheme provides safeguards to protect the consumer, and to refund any disputed money. In this kind of situation, no doubt Clarkson is covered financially.

But you could imagine a consumer being less than happy if, say, the money taken out of their account meant they went overdrawn, other payments bounced, and they then had to sort out the unholy mess.

And Clarkson himself says he only discovers the loss when he read his bank statement – how many people do that every month? And would they notice the loss if it was £50 not £500?

For me, it does highlight two important issues: firstly, the context in which personal data is used is important. As many commentators have said, Clarkson only divulged information that we give to anyone whenever we give them a cheque. But, he did so in a highly public way. “Security by obscurity” has long been a facet of protecting data, and shouldn’t be forgotten when risk is being assessed.

The second key point is that it’s much, much easier to not leak data in the first place, than to deal with the consequences even if there is no nominal financial risk. As I mentioned, the UK’s banks guarantee to refund any money that a consumer loses due to a mistake with a direct debit. In practice, I imagine it’s still a difficult process to go through, and can cause much inconvenience. It’s the same with any company’s data – you might theoretically not have any negative consequences of a leak, but managing the process when information goes missing can be time-consuming and costly.

Friday, 11 January 2008

Frank Abagnale tells the inside story on IT security

You might know him best from the Spielberg film “Catch Me If You Can”, but former fraudster Frank Abagnale has spent the last 30 years working with the FBI on improving security, and more recently this has included a big element of IT security.

There’s a good Q&A with him at ComputerWorld that’s worth reading, as he makes some interesting points about IT and financial security – not least that the internal threat to companies is more significant than external hackers.

Monday, 7 January 2008

Two good articles on security: user behaviour and balancing risk

Happy New Year! This seems a good opportunity to mention two good articles I read last year, but didn’t blog on at the time.

Firstly, Network World ran an article by Michael Osterman in June based on a survey of user behaviour. It’s short and to the point, but contains useful gems like the fact that 71% of users check work-related email from home on their own computer. Certainly confirms for me that we’re on the right lines to put our ILP protection on the email server, not on the desktop – if you’ve got server-based protection, you’re covered regardless of which PC is used.

Then this article in APC magazine contains some interesting views from Microsoft on why the security threat is often “overblown”, and how you need to balance the cost of a security measure against the perceived risk and the cost of any security problems that may arise. It’s common sense really, but worth remembering, and I’d add the point that you need to think about how long a solution may take before it’s up and running effectively; sometimes the simple and fast solutions are the best.

Saturday, 15 December 2007

PR agencies leaking data as much as the rest of us

Love or hate them, PR agencies are part of today’s business world. They do have a riskier position than most in the looking foolish stakes, though, as they are in frequent contact with journalists who will generally grab any opportunity they can to wind up their PR colleagues.

The latest one is a delightful example on Valleywag, the Silicon Valley gossip site – just look at all those tracked changes that were left in the email to the journalist from the PR.

But wait: it gets better. The PR sent an email threatening legal action if her original email wasn’t removed. Guess what? Valleywag ran that email too.

Thursday, 13 December 2007

Another day, another data breach

Amazing how many of these stories are coming out now in the UK about public sector data breaches, as public attention is so focussed on it at the moment.

This week, a healthcare trust managed to email a spreadsheet containing personal financial details of 1,800 employees to four medical organisations. Surely they’ve got ILP tools to stop them doing this? Maybe not…

The gory details are in the BBC’s report here.

Monday, 10 December 2007

New Scientist covers ILP

Well, nice to get some recognition for our area of technology in this article in New Scientist (subscription required, but you can read the first couple of paragraphs for free anyway).

To summarise the key points anyway: researchers at the Air Force Institute of Technology, Ohio are developing software to analyse the text of outgoing emails in companies, and flag the senders as “alienated” or “having clandestine, sensitive interests”. Sounds like what we’re doing at 3BView but it’s interesting stuff… there’s more here (New Scientist’s press release about their article).

Thursday, 29 November 2007

Former DuPont scientist jailed for information theft

Gary Min, a former DuPont scientist, has just been jailed for 18 months for stealing confidential information. He downloaded 22,000 abstracts and 16,000 full-text documents over a five-month period before leaving the company. He subsequently uploaded 180 of these DuPont documents onto a corporate laptop from his new employer, Victrex, a competitor of DuPont. The information was valued at over $400million.

Apparently most of these documents were unrelated to his job at DuPont. You have to wonder why it took DuPont so long to spot this pattern and report him to the FBI, and why he had access to so much information.

It’s not quite on the scale of the UK’s HMRC fiasco, but it raises a similar question: why do employees get access to such a large quantity of information that’s not related to their jobs?

Wednesday, 21 November 2007

You can’t steal what isn’t there

Yesterday’s story on the loss of 25 million child benefit records reminded me about the loss of more than 45 million customer records stolen from TJX, the parent company of retailer T.J. Maxx. The article, a while back, in Information Week describes it as the “largest breach of customer data”.

An interesting article, but the key point is right at the end: “With any luck, the TJX Effect will teach retailers this basic lesson: Thieves can't steal sensitive customer data if retailers aren't storing it.”

But governments have to store sensitive data -- they really do need to get things sorted, or the trust of the public will be lost forever.


Tuesday, 20 November 2007

The HMRC leak – unbelievable

Really, words fail me. I’ve just watched on TV the UK chancellor Alistair Darling tell the House of Commons that this massive data leak (25 million people’s bank details etc) is due to HMRC staff not following procedures. Pardon me? Apparently it was sent via unrecorded post on unencrypted CDs.

Liberal Democrat acting leader Vince Cable asked why the data was posted on CDs and why HMRC didn’t have an electronic means of sending the information securely. He’s got a point.

I’m sure we’ll learn more soon.

AT&T lawsuits rumbling on

AT&T is one of the highest profile companies that’s been publicly identified as having committed an ILP faux pas – letting the cat out of the bag about alleged collusion with the US government in alleged illegal wiretapping (the lawsuits are still going on – so I’m going to use the word ‘alleged’ as often as I can just in case).

They must be regretting this a LOT! There’s an interesting article in the Guardian about this case and the general topic of privacy and how it’s changing in the electronic world.

Tuesday, 13 November 2007

Google adds outbound email security features

Since they bought Postini recently, Google hasn’t wasted any time adding their email security features to Google Apps (even if it’s only on the “Premier Edition” so far).

The press release from Google says the new features will “Centrally manage all outbound content policy, including adding footers to every message based on business policy rules, blocking messages with specific keywords or attachments, and preventing emails with sensitive company information from being sent.”

I had a dig around the Google page linked to from the press release, and the Postini pages it directed me too, and couldn’t find anything too specific about the outbound email filtering it mentioned, but it’s encouraging for those of us at the ILP coalface that the behemoth of Google is recognising the need for ILP tools. Will be interested to see how it works…

Monday, 15 October 2007

Error by FTC gives away Whole Foods’ business secrets

This Sunday’s Observer newspaper in the UK carried a book review talking about innovative business practices that mentioned Whole Foods as an example of using new internet techniques (not sure if that includes your CTO criticising rivals online under a pseudonym?)

Anyway, it reminded me of the bizarre story from August: the Federal Trade Commission (FTC) managed to electronically file documents as part of a court case involving Whole Foods Market’s proposed $565 million takeover of Wild Oats Markets. The words looked redacted but were just shaded black.

The accidentally revealed portions included Whole Foods’ marketing strategies, and how it apparently negotiates with suppliers to drive up costs for Wal-Mart stores.

Guess what? The Associated Press managed to download the document before the FTC realised their mistake and replaced it with a clean version. The Washington Post has the full story here.

Come on guys, it’s not rocket science to avoid these mistakes. Is it?

Sunday, 7 October 2007

Company insiders are biggest IT security threat

According to the Computer Security Institute, the biggest threat to corporate IT security isn’t viruses, it’s insiders.

The CSI has released its 2007 “Computer Crime and Security Survey” – there’s a good write-up here and you can also download the full report (PDF).

The report is based on responses from IT security staff in U.S. businesses and government bodies. 59% of respondents reported “insider abuse of network access or e-mail”.

Saturday, 29 September 2007

MacUser covers data disasters and information leak prevention

The recent MacUser edition (14th September) has got a great article about potential data disasters from hidden data and emails. And guess what? 3BView gets a mention as we are the only metadata removal tool for Macs (as far as I’m aware).

The article doesn’t appear to be online yet, but MacUser’s site is here.

Tuesday, 25 September 2007

The financial view of ILP

Just a quick mention of my colleague Ges Ray, who’s also blogging on information leak prevention – in his case, on the financial technology site Finextra.

Ges’s blog has some interesting points, and the whole site is good reading for anyone interested in the financial sector.

Wednesday, 19 September 2007

Leaked emails reveal company’s secrets

Controversial P2P “mitigation” company MediaDefender has got itself into trouble when 700MB of internal emails were distributed on the Internet this weekend. It appears that an employee had forwarded all of his emails to a Gmail account, which has then been accessed by someone else.

According to this report, the emails gave away many secrets about the company’s operation, including evidence that MediaDefender had intentionally misled the outside world about some of its activities. The emails apparently also included financial details including salaries, Social Security numbers and home addresses of some of the company’s employees.

It’s a point that everyone must be familiar with, but it bears repeating: email is a dangerous thing. And it’s not rocket science to realise that having controls to filter and monitor emails going outside your company can help avoid this kind of problem.