Corporate Ethics Must Change, Says Matwyshyn. A Wharton School professor says that corporations will have to adapt to increasing consumer savvy when it comes to the role of information security in business dealings, reports Forbes. At Defcon last week, privacy expert and Wharton professor of legal studies and business ethics Andrea Matwyshyn said: "Companies need to be aware that their customers are going to start asking questions about their security and what they're doing." Matwyshyn studies corporate law and information technology. She says even though they are not required to disclose their security procedures to consumers, big businesses should inform customers about their security practices and threats, adding that if corporate ethics don't change, legislators might step in.
While it is true that businesses are not required to disclose security procedures and methods, the public still has the last say in this. When you go to work for a company, enter into an agreement or contract with another business, invest in or simply do business with them you have the right to expect that they are handling your personal information in a responsible manner. And you have the right to NOT get involved with a business that does not take this seriously. If covered by the Red Flags Rule you can ask to see their identity theft prevention and response policy. I have been to bank branches for speaking engagements since Nov 1st of '08 where the branch manager had no idea of the banks policy nor what the policy document looked like. Banks were to be in compliance prior to November 1st of '08. The bottom line is this. If you are one of the people who are waiting for the government to fix the problem you are not going to get any satisfaction. We are empowered to make businesses take the responsible route when it comes to data security. We live in a society where lawyers throw cases of client files in dumpsters, and personnel departments email sensitive personal info to one another without any sort of encryption or protection, and employees that lose laptops and thumb drives containing unencrypted NPI on a regular basis. These are just a few of the "mistakes" companies make daily, and do not include the intentional acts of theft of paper files, flash drives, and CD ROMS by underpaid, laid-off or disgruntled employees needing extra cash.
If a business does not address this issue head on by training and honestly assessing internal risk they are playing with fire. There is no limit in company size either. EVERY business regardless of size must take heed. This is a real issue with real consequences and businesses are the prime source of data.
Thursday, August 6, 2009
Tuesday, August 4, 2009
Government Employees' Names, SSNs Exposed
HELLO!?
U.S. Commerce Department employees have been notified that their sensitive personal information was exposed last month, reports the Washington Post. The names and Social Security numbers of 27,000 were on an Excel spreadsheet that a National Finance Center employee sent to a co-worker via unencrypted e-mail, the report states. The department is making arrangements to track for identity theft resulting from the breach and is urging employees to monitor their credit reports.
I repeat, your information is out there and used, or misused each and every day of the week.
No one can prevent accidents or mistakes from happening, just as you cannot prevent intentional acts of data theft. If you have a comprehensive ID theft early warning and restoration service working for you, you can be assured that no matter how your personal information gets in the hands of the wrong people that they cannot ruin your life. The damage is very limited and correctable.
U.S. Commerce Department employees have been notified that their sensitive personal information was exposed last month, reports the Washington Post. The names and Social Security numbers of 27,000 were on an Excel spreadsheet that a National Finance Center employee sent to a co-worker via unencrypted e-mail, the report states. The department is making arrangements to track for identity theft resulting from the breach and is urging employees to monitor their credit reports.
I repeat, your information is out there and used, or misused each and every day of the week.
No one can prevent accidents or mistakes from happening, just as you cannot prevent intentional acts of data theft. If you have a comprehensive ID theft early warning and restoration service working for you, you can be assured that no matter how your personal information gets in the hands of the wrong people that they cannot ruin your life. The damage is very limited and correctable.
Thursday, July 30, 2009
Network Solutions Begins a Damage Control Effort
If anyone still has reservations as to whether or not to have some sort of identity theft mitigation service one only needs to consider the following.
Following disclosure of a data breach that may have compromised the credit card data of more than 573,000 patrons of small commercial Web sites, Internet domain administer and host Network Solutions has initiated a crisis response effort. Reaching out to its clients affected by the breach, Network Solutions has offered assistance in helping sites notify those customers whose credit card data may have been compromised, including offering credit monitoring services. Network Solutions spokesperson Susan Wade told DMNews, "Unfortunately, something like this could happen to any online business, so we're just letting our customers know that we're there for them, we will help them as much as we can, and we take this issue very seriously."
It is important to recognize that identity theft can and often does raise its ugly head in many different ways. Our information is out in the world and used by thousands of businesses and government agencies constantly. It doesn't take a statistician to see that the odds are that your information will be compromised, and likely many times. Why then would anyone want to gamble that they won't become the victim of the most difficult crime in history. Difficult you say? When identity theft strikes records are corrupted with false information. There is no one source to use to correct them and once corrupted the onus is on the victim to prove that they have been victimized. When the data says one thing how are you going to prove otherwise? Most victims spend years trying to correct their health or SSN files or DMV or insurance records, or any number of files that are used to shape who we are perceived to be in the official and public eye.
Having a service which will not only shortcut the crime but most importantly go to work for you to correct those records no matter how or when they have been corrupted by misuse of your personal data. It is also in the best interest of each and every employer to make such a service available to all of their employees. An employee distracted by this kind of problem cannot concentrate on work or maintain a healthy attitude for as long as they are dealing with an identity theft episode.
Following disclosure of a data breach that may have compromised the credit card data of more than 573,000 patrons of small commercial Web sites, Internet domain administer and host Network Solutions has initiated a crisis response effort. Reaching out to its clients affected by the breach, Network Solutions has offered assistance in helping sites notify those customers whose credit card data may have been compromised, including offering credit monitoring services. Network Solutions spokesperson Susan Wade told DMNews, "Unfortunately, something like this could happen to any online business, so we're just letting our customers know that we're there for them, we will help them as much as we can, and we take this issue very seriously."
It is important to recognize that identity theft can and often does raise its ugly head in many different ways. Our information is out in the world and used by thousands of businesses and government agencies constantly. It doesn't take a statistician to see that the odds are that your information will be compromised, and likely many times. Why then would anyone want to gamble that they won't become the victim of the most difficult crime in history. Difficult you say? When identity theft strikes records are corrupted with false information. There is no one source to use to correct them and once corrupted the onus is on the victim to prove that they have been victimized. When the data says one thing how are you going to prove otherwise? Most victims spend years trying to correct their health or SSN files or DMV or insurance records, or any number of files that are used to shape who we are perceived to be in the official and public eye.
Having a service which will not only shortcut the crime but most importantly go to work for you to correct those records no matter how or when they have been corrupted by misuse of your personal data. It is also in the best interest of each and every employer to make such a service available to all of their employees. An employee distracted by this kind of problem cannot concentrate on work or maintain a healthy attitude for as long as they are dealing with an identity theft episode.
Wednesday, July 29, 2009
Red Flags Rule Enforcement Deadline Extended
The Federal Trade Commission has again extended the enforcement deadline for the Red Flags Rule, according to an agency press release. Creditors and financial institutions now have until November 1, 2009 to come into compliance with the rule, which was mandated by the Fair and Accurate Credit Transactions Act of 2003. Meanwhile, the commission will redouble efforts to educate businesses affected by the rule on what they must do to comply. The Red Flags Rule requires entities to implement programs for identifying, detecting and responding to harbingers of identity theft, or "red flags."
Go to www.ftc.gov/redflagsrule for more information regarding your business.
Go to www.ftc.gov/redflagsrule for more information regarding your business.
Friday, July 24, 2009
Will the Third Try be a Charm for Federal Breach Notification Law?
The following article was in today's privacy bulletin. Since the first state breach notification law went into effect in 2003 in California, 43 other states have enacted their own versions creating a worthwhile but patched together set of regulations that are at best vague, and contain huge lapses so that a company experiencing a breach can likely get away without any sort of notification to potential victims. Hopefully this legislation will contain enough bite to be effective. Only when we see transcripts of the bill will we know if we are headed in the right direction or for another legislative compromise. Thresholds for notification need to include not only electronic breaches and large scale hacks of computer servers, but also theft and misuse of paper records, and need to provide for smaller incidents. Only by creating effective notification laws can businesses be held accountable to the public who expect their information to be reasonably safe.
Vermont Senator Patrick Leahy (D) has reintroduced the Personal Data Privacy and Security Act, the third attempt by Congress to pass a federal data breach law that would pre-empt the 44 individual state data breach laws and create a single response and notification standard in the U.S. InternetNews reports that in a statement, Leahy said the bill addresses serious consumer privacy and data security issues and vowed that, "Passing this comprehensive data privacy legislation is one of my highest legislative priorities as chairman of the Judiciary Committee."Full Story
Vermont Senator Patrick Leahy (D) has reintroduced the Personal Data Privacy and Security Act, the third attempt by Congress to pass a federal data breach law that would pre-empt the 44 individual state data breach laws and create a single response and notification standard in the U.S. InternetNews reports that in a statement, Leahy said the bill addresses serious consumer privacy and data security issues and vowed that, "Passing this comprehensive data privacy legislation is one of my highest legislative priorities as chairman of the Judiciary Committee."Full Story
Monday, July 13, 2009
Who Needs High Tech Information Security Measures?
Whenever I see articles about the latest high tech "solution" for data loss I can't help but to think about the vast number of data breaches that result from situations such as the one below.
Just as there is no one form of data theft there is no one type of solution.
Medical records, including names, credit card numbers, Social Security numbers and cancelled checks were found in a dumpster behind a Salt Lake City shoe distribution center last week, reports KUTV News. At least some of about 20 boxes that Salt Lake City police confiscated appear to have come from a now-closed chiropractic office. KUTV reports that surveillance footage showing two people unloading materials into the dumpster exists. Disposing of medical records in this way is a violation of state law, according to the Utah Attorney General's office, and could lead to a $2,500 fine per patient record.
Full Story
Train your staff, train your staff, train your staff. This kind of an incident happens too often due to a lack of understanding of the law and simple common sense in protecting records from falling into the wrong hands.
Most ID theft that results from breaches of information at companies occurs when an employee walks out with the data with the intention of selling it, not to open credit card accounts. While the thief may be caught the data is long gone with other parties. Once the information is sold it can proliferate in a matter of days across the world.
A lack of understanding of the value of employee personal information as well as customer information has led to more identity theft incidents than any other cause.
Just as there is no one form of data theft there is no one type of solution.
Medical records, including names, credit card numbers, Social Security numbers and cancelled checks were found in a dumpster behind a Salt Lake City shoe distribution center last week, reports KUTV News. At least some of about 20 boxes that Salt Lake City police confiscated appear to have come from a now-closed chiropractic office. KUTV reports that surveillance footage showing two people unloading materials into the dumpster exists. Disposing of medical records in this way is a violation of state law, according to the Utah Attorney General's office, and could lead to a $2,500 fine per patient record.
Full Story
Train your staff, train your staff, train your staff. This kind of an incident happens too often due to a lack of understanding of the law and simple common sense in protecting records from falling into the wrong hands.
Most ID theft that results from breaches of information at companies occurs when an employee walks out with the data with the intention of selling it, not to open credit card accounts. While the thief may be caught the data is long gone with other parties. Once the information is sold it can proliferate in a matter of days across the world.
A lack of understanding of the value of employee personal information as well as customer information has led to more identity theft incidents than any other cause.
Friday, July 10, 2009
What is a privacy policy, and what is an identity theft policy? What's the difference?
Good morning all. I have been noticeably absent from my column duties while I took care of some other projects, and fitting in a short vacation.
Very often when I speak with business owners especially in the small to mid-sized organizations I find that a lot of them either confuse a company privacy policy with identity theft, or believe that an identity theft policy is an outgrowth of a privacy policy or statement.
In very general terms the two are not the same and in fact address two different issues. A privacy policy deals with either company intellectual property or customer information. Any business that collects customer information in the course of doing business must have a privacy policy that informs the customer as to how their information is used and protected, and encryption procedures for transactions. That falls largely under the direction of the Payment Card Initiative, PCI DSS rules to protect the public from fraud resulting from purchase transactions. Also, customers are protected by other state and federal laws suchas the FTC Act and FCRA that prohibit companies from distributing personal information without regard to personal privacy without first notifying the client of their intent. That issue is being hotly debated again due to the proliferation of social networking websites. Another area of privacy policy is the protection of company secrets, proprietary information regarding how a business operates and its plans and strategies. While the distribution and misuse of personally identifiable information (PII) is highly regulated by consumer law, protecting company secrets are internal policies. Businesses engaged in technological and scientific research and development often have non-disclosure agreements with employees to protect that kind of information. Employees who violate those agreements are subject to termination, and possible prosecution as a breach of contract.
Identity Theft policy addresses the area of PII data loss, a definition of what is considered by the company to be PII, the various forms the company uses to store and use PII, and finally the procedure a company has put into place to respond to breaches and to protect the individuals who might be affected and are at increased risk of identity theft resulting from a company breach. This policy must address not only the data it keeps on its clients but also of the employees personnel records, and also must address the identity theft policies of any contractor or service provider who might have access to that information. Vendors can include not only outsourced HR, payroll, insurance and Benefits brokers, but also cleaning services, construction contractors, and even parking services, any business that has the potential of obtaining PII.
It isn’t my intention to delineate what the law is or provide legal advice in these areas but instead to provoke thought on the part of businesses. With new legislation such as GLB, FACTA, and now the Red Flags Rule under FACTA, the banking regulators and the FTC have made it clear that in order to stem the tide of identity theft and the company data breaches that result in the majority of identity theft, business needs to take certain steps proactively to prevent breaches and to respond quickly and effectively when they do occur.
Every company is different and therefore needs to take the steps that are most effective for that organization. It all begins with an honest risk assessment on the part of each company to find the weak links in information security, and to train the staff on their responsibilities. Establishing a clear identity theft policy is the roadmap every responsible business uses to lay out everyone’s duties, and how the business will handle data breaches. The FTC auditors investigating companies who have experienced these breaches are most interested in seeing what a business did to protect the information before the breach. A proactive identity theft policy is good policy, and good business.
Very often when I speak with business owners especially in the small to mid-sized organizations I find that a lot of them either confuse a company privacy policy with identity theft, or believe that an identity theft policy is an outgrowth of a privacy policy or statement.
In very general terms the two are not the same and in fact address two different issues. A privacy policy deals with either company intellectual property or customer information. Any business that collects customer information in the course of doing business must have a privacy policy that informs the customer as to how their information is used and protected, and encryption procedures for transactions. That falls largely under the direction of the Payment Card Initiative, PCI DSS rules to protect the public from fraud resulting from purchase transactions. Also, customers are protected by other state and federal laws suchas the FTC Act and FCRA that prohibit companies from distributing personal information without regard to personal privacy without first notifying the client of their intent. That issue is being hotly debated again due to the proliferation of social networking websites. Another area of privacy policy is the protection of company secrets, proprietary information regarding how a business operates and its plans and strategies. While the distribution and misuse of personally identifiable information (PII) is highly regulated by consumer law, protecting company secrets are internal policies. Businesses engaged in technological and scientific research and development often have non-disclosure agreements with employees to protect that kind of information. Employees who violate those agreements are subject to termination, and possible prosecution as a breach of contract.
Identity Theft policy addresses the area of PII data loss, a definition of what is considered by the company to be PII, the various forms the company uses to store and use PII, and finally the procedure a company has put into place to respond to breaches and to protect the individuals who might be affected and are at increased risk of identity theft resulting from a company breach. This policy must address not only the data it keeps on its clients but also of the employees personnel records, and also must address the identity theft policies of any contractor or service provider who might have access to that information. Vendors can include not only outsourced HR, payroll, insurance and Benefits brokers, but also cleaning services, construction contractors, and even parking services, any business that has the potential of obtaining PII.
It isn’t my intention to delineate what the law is or provide legal advice in these areas but instead to provoke thought on the part of businesses. With new legislation such as GLB, FACTA, and now the Red Flags Rule under FACTA, the banking regulators and the FTC have made it clear that in order to stem the tide of identity theft and the company data breaches that result in the majority of identity theft, business needs to take certain steps proactively to prevent breaches and to respond quickly and effectively when they do occur.
Every company is different and therefore needs to take the steps that are most effective for that organization. It all begins with an honest risk assessment on the part of each company to find the weak links in information security, and to train the staff on their responsibilities. Establishing a clear identity theft policy is the roadmap every responsible business uses to lay out everyone’s duties, and how the business will handle data breaches. The FTC auditors investigating companies who have experienced these breaches are most interested in seeing what a business did to protect the information before the breach. A proactive identity theft policy is good policy, and good business.
Subscribe to:
Posts (Atom)

