I'll leave you with a question over the weekend. Can you guarantee that when your personal information is stolen and sold on any one of thousands of markets that thieves will be nice enough to only use it to open new credit accounts?
Our lives are literally controlled by two numbers, our Social Security number and our Drivers License number. When those two numbers are used by identity thieves records kept on you in any number of thousands of databases are corrupted. Once corrupted they are nearly impossible to correct, if you can find out which ones need correcting. Public records are then attached to your NCIC and credit reports driving down your FICO score. There goes your chance to get a raise, find a new job, get a loan, rent an apartment, and hundreds of other things that rely on your credit score and a clean record to determine your worthiness.
In the above scenario did anyone attempt to open a new credit account? Ladies and gentlemen, this is Identity Theft. Will a credit monitoring or credit freeze and alert service help you?
Unless something pressing happens in the next week I'm taking a few days off.
Friday, December 19, 2008
Tuesday, December 16, 2008
In my Opinion
Dear Reader,
This blog is a mix of facts, predictions, and yes, my opinions. I have never been accused of a lack of opinion. All of us have opinions but few of us have the temerity to state them. Going on record with your opinion will give away your real position and in a classic debate that could amount to capitulation, but in my blog I get to say what I feel.
Identity theft. That is the reason I began this column. I chose to approach the subject from the standpoint of the effects on business. But just as importantly, how a business should look at identity theft in my opinion, from a responsible and moral standpoint as well as a practical one.
When we are entrusted with something of value it should follow that we will do everything reasonable to protect it. If your next door neighbor asks you to look after his house, water the plants, bring in the mail, and feed the dog while he is away for a two week vacation, do you decide later on that only some of that matters? Is the dog not worthy of your attention, and maybe the neighbor won't mind if the plants die. Well, I hope you don't live next to me if you do. We all know the right position. If it matters to the neighbor we should have enough respect for him to pay equal attention to everything as though it was ours. That is the right thing to do. Now, if you go away would you then ask your neighbor to do the same for you? Of course. And you would expect him to be just as responsible as you were in protecting his home.
Can you see where this is headed? What is the difference between protecting your next door neighbors' assets and those of the people who work for you? Too many businesses think of identity theft in terms of protecting the intellectual property of the business. There is an entire legal industry surrounding IP (intellectual property). That is a subject for another day, and yes I have an opinion on that too.
While a company, or county, utility, university, etc. is caught up in covering it's rear end from computer fraud and data theft some hourly employee has posted all of the employees' Social Security numbers and home addresses in an email. Did that company take care of business? Absolutely not. Oh sure, they threw the IT Dept at it with a too small budget to install the data security program du jour around the servers, but have they trained the staff to never send sensitive and personally identifiable information in emails? Have they established a written policy delineating what constitutes sensitive information and making clear what the companies' procedures are to safeguard it? Not likely. A one hour staff training might have avoided that fateful email, or a host of other far too common errors in judgement that result in fines, audits, lawsuits, and even criminal prosecution. Can any business endure the public loss in confidence that will result from losing personal information? How about the sheer cost of litigation?
What if someone on staff experiences personal identity theft? Lets' say someone working in the county records office stole a few hundred records and among others they got one of your employees' personal information. Over the weekend they trundle down to the local flea market and sell their data loot for a couple of grand. The next week the buyers begin opening cell phone accounts, using the stolen SSN to obtain health insurance, employment, maybe a traffic ticket or two using your employees' ID. Has the company considered that the average identity theft victim spends an average of 15 work/weeks to clear up the fallout on their own? That's from from the FTC, who keeps track of such things. What does 15 work/weeks mostly during business hours away from the job look like to the company? What if ten of the employees are affected? How about twenty? Lets' see, what is twenty times 15 work/weeks?
Have you provided your employees with access to a serious identity theft program for themselves as a benefit? You see identity theft happens from all fronts. Don't forget what happens to your employees away from work can affect your business too. When you protect the personal information your company keeps you are protecting someone else, get it? When another company does it they are protecting you. But, hey that server is safe!
Have a great Holiday season, and do the right thing.
This blog is a mix of facts, predictions, and yes, my opinions. I have never been accused of a lack of opinion. All of us have opinions but few of us have the temerity to state them. Going on record with your opinion will give away your real position and in a classic debate that could amount to capitulation, but in my blog I get to say what I feel.
Identity theft. That is the reason I began this column. I chose to approach the subject from the standpoint of the effects on business. But just as importantly, how a business should look at identity theft in my opinion, from a responsible and moral standpoint as well as a practical one.
When we are entrusted with something of value it should follow that we will do everything reasonable to protect it. If your next door neighbor asks you to look after his house, water the plants, bring in the mail, and feed the dog while he is away for a two week vacation, do you decide later on that only some of that matters? Is the dog not worthy of your attention, and maybe the neighbor won't mind if the plants die. Well, I hope you don't live next to me if you do. We all know the right position. If it matters to the neighbor we should have enough respect for him to pay equal attention to everything as though it was ours. That is the right thing to do. Now, if you go away would you then ask your neighbor to do the same for you? Of course. And you would expect him to be just as responsible as you were in protecting his home.
Can you see where this is headed? What is the difference between protecting your next door neighbors' assets and those of the people who work for you? Too many businesses think of identity theft in terms of protecting the intellectual property of the business. There is an entire legal industry surrounding IP (intellectual property). That is a subject for another day, and yes I have an opinion on that too.
While a company, or county, utility, university, etc. is caught up in covering it's rear end from computer fraud and data theft some hourly employee has posted all of the employees' Social Security numbers and home addresses in an email. Did that company take care of business? Absolutely not. Oh sure, they threw the IT Dept at it with a too small budget to install the data security program du jour around the servers, but have they trained the staff to never send sensitive and personally identifiable information in emails? Have they established a written policy delineating what constitutes sensitive information and making clear what the companies' procedures are to safeguard it? Not likely. A one hour staff training might have avoided that fateful email, or a host of other far too common errors in judgement that result in fines, audits, lawsuits, and even criminal prosecution. Can any business endure the public loss in confidence that will result from losing personal information? How about the sheer cost of litigation?
What if someone on staff experiences personal identity theft? Lets' say someone working in the county records office stole a few hundred records and among others they got one of your employees' personal information. Over the weekend they trundle down to the local flea market and sell their data loot for a couple of grand. The next week the buyers begin opening cell phone accounts, using the stolen SSN to obtain health insurance, employment, maybe a traffic ticket or two using your employees' ID. Has the company considered that the average identity theft victim spends an average of 15 work/weeks to clear up the fallout on their own? That's from from the FTC, who keeps track of such things. What does 15 work/weeks mostly during business hours away from the job look like to the company? What if ten of the employees are affected? How about twenty? Lets' see, what is twenty times 15 work/weeks?
Have you provided your employees with access to a serious identity theft program for themselves as a benefit? You see identity theft happens from all fronts. Don't forget what happens to your employees away from work can affect your business too. When you protect the personal information your company keeps you are protecting someone else, get it? When another company does it they are protecting you. But, hey that server is safe!
Have a great Holiday season, and do the right thing.
Monday, November 24, 2008
Enough is Enough
In today's' post my friends at Ephemeralaw reminded us once again about something that I am keen on. Every day there is at least one more data breach to report. It's like the sports scores two days after a weekend of games, just a bunch of numbers, but those numbers are staggering. There are no shortages of articles about the latest huge server breach, records stolen from personnel files, or about some knucklehead accidentally posting a thousand names and SSNs on the Internet, or dumping reams of data into the trash. Is there anyone left to shock? By now it is safe to say that just about everyone has heard of identity theft. I think also that we have established that identity theft is here to stay, and that for as long as non-public personal information has value to someone other than the rightful owner, it will be stolen and used.
Once the number of stolen records hit 300 million, which it did this year after just 3 short years of tracking such things, the numbers begin to have little meaning. Eight years ago someone stole my identity by opening multiple accounts in my name, and had a very good time at my expense. I really didn't care how many millions of records had been stolen, or from which database mine was stolen for that matter. All I wanted was a solution to my problem. Back when it happened to me there was little help available. The laws had not yet been passed that would have given me the tools to deal with it, and certainly the proliferation of identity theft products and services did not yet exist.
Here we are at the end of 2008. Great identity theft products do exist now. The federal and state laws in place not only afford the victim with recourse, but mainly they point out directly to the companies and other data aggregators that they are responsible for the information they are entrusted with.
Ladies and gentlemen, there are no excuses. The companies should know what to do by now. And I don't mean simply throwing software at it. That never did work. All the software in the world will not affect a culture of insecurity. You have to change the habits of the individuals who handle the data. Security is a top down policy effort and education is the key to changing the way information is treated. And every individual needs a quality identity theft service. If someone decides not to opt for a good effective service and becomes a victim of identity theft, shame on them. An identity theft program is not insurance. It is the most direct way to protect the integrity of all of your records in thousands of databases throughout the country.
Happy Thanksgiving!
Once the number of stolen records hit 300 million, which it did this year after just 3 short years of tracking such things, the numbers begin to have little meaning. Eight years ago someone stole my identity by opening multiple accounts in my name, and had a very good time at my expense. I really didn't care how many millions of records had been stolen, or from which database mine was stolen for that matter. All I wanted was a solution to my problem. Back when it happened to me there was little help available. The laws had not yet been passed that would have given me the tools to deal with it, and certainly the proliferation of identity theft products and services did not yet exist.
Here we are at the end of 2008. Great identity theft products do exist now. The federal and state laws in place not only afford the victim with recourse, but mainly they point out directly to the companies and other data aggregators that they are responsible for the information they are entrusted with.
Ladies and gentlemen, there are no excuses. The companies should know what to do by now. And I don't mean simply throwing software at it. That never did work. All the software in the world will not affect a culture of insecurity. You have to change the habits of the individuals who handle the data. Security is a top down policy effort and education is the key to changing the way information is treated. And every individual needs a quality identity theft service. If someone decides not to opt for a good effective service and becomes a victim of identity theft, shame on them. An identity theft program is not insurance. It is the most direct way to protect the integrity of all of your records in thousands of databases throughout the country.
Happy Thanksgiving!
Wednesday, November 19, 2008
Employee Data More Vulnerable Than Constituent Data
Nov 14, 2008, By Hilton Collins in Government Technology
Personal information about employees is more than twice as likely to be compromised in government security breaches than is constituent data, according to an online survey released by consulting firm PricewaterhouseCoopers (PwC). The survey also found that most governments don't keep accurate inventories of where their data is stored in their organization.
PwC, in partnership with CIO and CSO magazines, conducted the Global State of Information Security 2008 survey from March 25 to June 26, 2008. It included more than 7,000 CEOs, chief financial officers, CIOs, chief security officers and other high-level respondents from 119 countries via e-mail. Five hundred fifty-three came from the public sector, but PwC would not disclose how many came from U.S. government.
Forty-two percent of the public-sector respondents reported that employee data was more likely to be impacted by security breaches than constituent data. Only 19 percent reported otherwise.
"My sense is that businesses, first and foremost, place priority on protecting their business information, which is the lifeblood of their organization," said Jack Johnson, a partner in the Washington federal practice at PwC. Johnson has previously been the chief security officer for the U.S. Department of Homeland Security, a position he held from 2003 until 2005. He was appointed by then-Homeland Security Secretary Tom Ridge. "It's not because they don't place a level of importance on employee data, but I think their priority is focused on their business information."
In his experience, more security controls are usually placed around business data than around employee data, so it's possible the path to employee data may be the one of least resistance for malicious hackers.
Other data from public-sector respondents indicates:
• 65 percent reported that their organizations didn't have accurate inventories of where personal data was collected, transmitted and stored;
• 76 percent reported that they didn't keep an inventory of third parties who handle constituent data when data sharing occurred, and 47 percent had established security baselines for external parties when handling such data;
• 70 percent believed that their users complied with privacy and information security policies, but 50 percent didn't audit or monitor the compliance, and 46 percent required employees to complete training on privacy practices.
"The organization, first and foremost, needs to perform a risk assessment around this data to determine which data is considered sensitive, or, in some cases, personally identifiable information," Johnson said. Once sensitivity and importance of data is assessed, organizations can proceed more coherently with protection in mind.
The report recommends that organizations take the following security actions:
1. Prioritize data and information assets according to risk level continuously - 27 percent of respondents said they did, 40 percent said periodically and 31 percent not at all.
2. Extend privacy protections to employee data, not just constituent data.
3. Establish a "culture of compliance" to ensure that employees adhere to organizational security protocols.
4. Develop an incident response plan to determine how to handle data breaches when they occur - 53 percent of respondents said their security policies didn't address incident response.
The report also had some good news - governments have improved in their information security efforts from two years ago.
• 65 percent of respondents had an overall information security strategy versus 42 percent in 2006.
• 75 percent employed a chief information security officer or a chief security officer, versus 56 percent in 2006.
• 72 percent leveraged secure remote access (VPN) vs. 61 percent in 2006. In a VPN, or virtual private network, security measures like encryption ensure that only authorized users can access the network
Personal information about employees is more than twice as likely to be compromised in government security breaches than is constituent data, according to an online survey released by consulting firm PricewaterhouseCoopers (PwC). The survey also found that most governments don't keep accurate inventories of where their data is stored in their organization.
PwC, in partnership with CIO and CSO magazines, conducted the Global State of Information Security 2008 survey from March 25 to June 26, 2008. It included more than 7,000 CEOs, chief financial officers, CIOs, chief security officers and other high-level respondents from 119 countries via e-mail. Five hundred fifty-three came from the public sector, but PwC would not disclose how many came from U.S. government.
Forty-two percent of the public-sector respondents reported that employee data was more likely to be impacted by security breaches than constituent data. Only 19 percent reported otherwise.
"My sense is that businesses, first and foremost, place priority on protecting their business information, which is the lifeblood of their organization," said Jack Johnson, a partner in the Washington federal practice at PwC. Johnson has previously been the chief security officer for the U.S. Department of Homeland Security, a position he held from 2003 until 2005. He was appointed by then-Homeland Security Secretary Tom Ridge. "It's not because they don't place a level of importance on employee data, but I think their priority is focused on their business information."
In his experience, more security controls are usually placed around business data than around employee data, so it's possible the path to employee data may be the one of least resistance for malicious hackers.
Other data from public-sector respondents indicates:
• 65 percent reported that their organizations didn't have accurate inventories of where personal data was collected, transmitted and stored;
• 76 percent reported that they didn't keep an inventory of third parties who handle constituent data when data sharing occurred, and 47 percent had established security baselines for external parties when handling such data;
• 70 percent believed that their users complied with privacy and information security policies, but 50 percent didn't audit or monitor the compliance, and 46 percent required employees to complete training on privacy practices.
"The organization, first and foremost, needs to perform a risk assessment around this data to determine which data is considered sensitive, or, in some cases, personally identifiable information," Johnson said. Once sensitivity and importance of data is assessed, organizations can proceed more coherently with protection in mind.
The report recommends that organizations take the following security actions:
1. Prioritize data and information assets according to risk level continuously - 27 percent of respondents said they did, 40 percent said periodically and 31 percent not at all.
2. Extend privacy protections to employee data, not just constituent data.
3. Establish a "culture of compliance" to ensure that employees adhere to organizational security protocols.
4. Develop an incident response plan to determine how to handle data breaches when they occur - 53 percent of respondents said their security policies didn't address incident response.
The report also had some good news - governments have improved in their information security efforts from two years ago.
• 65 percent of respondents had an overall information security strategy versus 42 percent in 2006.
• 75 percent employed a chief information security officer or a chief security officer, versus 56 percent in 2006.
• 72 percent leveraged secure remote access (VPN) vs. 61 percent in 2006. In a VPN, or virtual private network, security measures like encryption ensure that only authorized users can access the network
Monday, November 17, 2008
Encrypted Data
I want to pass along a link to a story posted by fellow bloggers "Ephemaralaw."
http://ephemerallaw.blogspot.com/2008/11/333000-unencrypted-records-exposed.html
The reason for this is to point out that data stored on servers should be encrypted going forward. This breach is a classic example of exactly why. By May 1st of next year every covered business, non-profit, school district, utility, college, and local government needs to have in place a policy to address data security and identity theft prevention and response. Within that written policy there needs to be language that effectively states "All sensitive information must be encrypted when it is stored in an electronic format." Since federal legislation leaves the door open by not mandating encryption it is incumbent on business to make encryption a standard practice.
It should be noted that new Massachusetts legislation requires all businesses to encrypt data stored on servers. Other states are sure to follow. The blog article points out also that HIPAA sees encryption as an addressable standard. There are rules for addressable standards that require risk management assessments. They then require reports showing why such steps were not taken.
What is regrettable in my opinion is that a lot of businesses seem to look at this as a chore and an expense, but encryption, along with other steps, will prevent data loss, identity theft and thereby offset risk from law suits. Isn't an estimated $48 Billion loss to business and individuals an expense? That is an FTC estimate of direct and indirect cost to American business from identity theft in 2007. In a time of economic crisis is the hemorrhaging of unnecessary expenses acceptable?
Aren't we supposed to be looking for ways to prevent identity theft? If so how are we going to stem the tide of data breaches and subsequent identity theft episodes if the business community ignores the obvious? A business must do everything that the resources of the business will allow. Is encryption such a chore that initiating an encryption program is not worth the effort? Consider the possible outcome from a data breach. The loss of one valued customer or a single law suit could be enough to shut down a small business, and would likely result in many times the cost of basic encryption procedures. Anyone who is following the stories of the Southern California wildfires can see what an out of control fire can do in a very few minutes. Data breach is no different. Besides a public loss in confidence the net effect of data breach is the out of control rampant growth of data theft and misuse. After all, it isn't someone elses' information at stake. It is ours, yours and mine.
John
http://ephemerallaw.blogspot.com/2008/11/333000-unencrypted-records-exposed.html
The reason for this is to point out that data stored on servers should be encrypted going forward. This breach is a classic example of exactly why. By May 1st of next year every covered business, non-profit, school district, utility, college, and local government needs to have in place a policy to address data security and identity theft prevention and response. Within that written policy there needs to be language that effectively states "All sensitive information must be encrypted when it is stored in an electronic format." Since federal legislation leaves the door open by not mandating encryption it is incumbent on business to make encryption a standard practice.
It should be noted that new Massachusetts legislation requires all businesses to encrypt data stored on servers. Other states are sure to follow. The blog article points out also that HIPAA sees encryption as an addressable standard. There are rules for addressable standards that require risk management assessments. They then require reports showing why such steps were not taken.
What is regrettable in my opinion is that a lot of businesses seem to look at this as a chore and an expense, but encryption, along with other steps, will prevent data loss, identity theft and thereby offset risk from law suits. Isn't an estimated $48 Billion loss to business and individuals an expense? That is an FTC estimate of direct and indirect cost to American business from identity theft in 2007. In a time of economic crisis is the hemorrhaging of unnecessary expenses acceptable?
Aren't we supposed to be looking for ways to prevent identity theft? If so how are we going to stem the tide of data breaches and subsequent identity theft episodes if the business community ignores the obvious? A business must do everything that the resources of the business will allow. Is encryption such a chore that initiating an encryption program is not worth the effort? Consider the possible outcome from a data breach. The loss of one valued customer or a single law suit could be enough to shut down a small business, and would likely result in many times the cost of basic encryption procedures. Anyone who is following the stories of the Southern California wildfires can see what an out of control fire can do in a very few minutes. Data breach is no different. Besides a public loss in confidence the net effect of data breach is the out of control rampant growth of data theft and misuse. After all, it isn't someone elses' information at stake. It is ours, yours and mine.
John
Friday, October 24, 2008
Wednesday, October 22, 2008
FTC Announces a Forbearance of the Red Flags Enforcement
Red Flags Rule Compliance Deadline Extended to
May 1, 2009
FTC Grants Six-Month Delay of Enforcement of 'Red Flags' Rule Requiring Creditors and Financial Institutions to Have Identity Theft Prevention Programs
The Federal Trade Commission will suspend enforcement of the new "Red Flags Rule" until May 1, 2009, to give creditors and financial institutions additional time in which to develop and implement written identity theft prevention programs.
NOTE: Today's announcement and the release of an Enforcement Policy Statement do not affect other federal agencies' enforcement of the original November 1, 2008 deadline for institutions subject to their oversight to be in compliance.Read the announcement: http://www.ftc.gov/opa/2008/10/redflags.shtm
This applies to all entities with oversight from the FTC only. All financial institutions with oversight from the federal banking and financial regulatory authorities still must be compliant by November 1st of 2008.
The FTC currently estimates that approximately 11 million entities from private business to municipalities, schools and universities, and non-profits are considered to have covered accounts and need to address the "red Flags" and initiate compliance steps relevant to each organization.
May 1, 2009
FTC Grants Six-Month Delay of Enforcement of 'Red Flags' Rule Requiring Creditors and Financial Institutions to Have Identity Theft Prevention Programs
The Federal Trade Commission will suspend enforcement of the new "Red Flags Rule" until May 1, 2009, to give creditors and financial institutions additional time in which to develop and implement written identity theft prevention programs.
NOTE: Today's announcement and the release of an Enforcement Policy Statement do not affect other federal agencies' enforcement of the original November 1, 2008 deadline for institutions subject to their oversight to be in compliance.Read the announcement: http://www.ftc.gov/opa/2008/10/redflags.shtm
This applies to all entities with oversight from the FTC only. All financial institutions with oversight from the federal banking and financial regulatory authorities still must be compliant by November 1st of 2008.
The FTC currently estimates that approximately 11 million entities from private business to municipalities, schools and universities, and non-profits are considered to have covered accounts and need to address the "red Flags" and initiate compliance steps relevant to each organization.
Subscribe to:
Posts (Atom)

