Showing posts with label data breaches. Show all posts
Showing posts with label data breaches. Show all posts

Monday, July 20, 2009

If you only read one article on Information Security...

[... this is it]

Actually, this is a bit unfair because after reading this one article, you'll be compelled to read more.

Richard Bejtlich's article sums this up nicely. He links to another blog post by Verizon Business.

I have some issues with Verizon Business's annual report but it is probably the most important document on Information Security to be published.

My one criticism of the Verizon Business Breach Report is that it shows credit card data to be more at risk than anything else. I was never sure if this is because it is easier to abuse than other data (such as Intellectual Property) or is just easier to detect when it is abused. According to the article, it is the latter. IP is leaving our companies, we just don't know it.

When a whole bunch of credit card information is stolen then the banks track which credit cards are abused. They are good at this and they slowly work out where all the credit cards were used together. So, if 5 credit cards were all used at a specific shop and then end up being abused that points to that shop having had an information breach. In the case of IP, there is no bank tracking abuse so you have to track it yourself... and companies are really bad at that.

The other point which I found quite amazing is that very few times when a PC is lost, is it used for fraud. End point encryption is cheap and easy to apply so it should be done, but most information is lost, not through assets being lost but through network attacks.

Monday, March 23, 2009

The Victorian Police Have Issues (Ironic Post)

[The irony in this article is so lovely, it has to be shared]

The Age newspaper reports that a leaked memo from inside the Victorian Police (Australia) department says that their IT systems are risky.

The article lists a whole bunch of "Availability" risks such as backups failing and the like. It doesn't really go into details about how information security can be compromised although it does list the kind of information that the police have on hand which is very confidential.

The wonderful part is that the article says: 'A police spokeswoman said the force believed its IT applications were secure and there was a "full back-up regime across all our services as well as disaster recovery for core applications".'

My question is ... if the Victorian Police are secure, as they claim to be, how did a highly confidential memo with the ability to cause massive amounts of embarrassment to the department get leaked to the press?

Tuesday, March 3, 2009

Pepsi is not desperate.

[The other side to my prediction. Why I still believe it will happen but why it hasn't happened just yet.]

As per usual, the Securosis guys are smack bang on the pulse and deliver some interesting reading.

The take-away quote from the article is this:

[J] ust because the employee walked out with the information does not necessarily mean that the company suffered a loss. That data has to be used in some manner that affects the value of the company, or results in lost sales.
The Securosis blog entry links to an article about a Coke employee trying to sell Intellectual Property (IP) to Pepsi. Pepsi said "no thanks" and helped Coke who tipped off the FBI who made 3 arrests.

My feeling is that cyber criminals (hackers) are getting desperate. The average price of a credit card on the black market has dropped to the point where it is not worthwhile trading in credit cards anymore. The new currency will be intellectual property. The problem with IP as opposed to credit card data is that credit cards are easy - there are any number of buyers and the consequences are still not too harsh.

Intellectual Property really would only benefit the competitors of a company so there are not so many buyers for the information. And that company would need to act on the information that they get, otherwise it is not worthwhile.

The Coke/Pepsi example is not very technical - it sounds like the employee stuffed files in her bag but it is still a breach. The thing is that there are few companies that would benefit from Coke's private documents. There are fewer that would take the risk in acting on stolen information. Pepsi was not interested in taking the chance.

I think that my prediction still stands but it requires a desperate employee who has access to valuable information. And a desperate competitor that will use the information offered to them. There will probably be a middle-man orchestrating the transaction. Big money will be paid out for the information and the original company will suffer in some way - market share, share price, loss of tender, etc.

I don't think it will be widespread but it may get ISOs around the world thinking "that could be my CEO with egg on his face apologizing to shareholders about losing IP"

Thursday, August 16, 2007

Calif-online-crime Law

According to CSO merchants in California may end up liable for data breaches.

I think this is a good thing but I also think it is a bad thing.

Its good because a lot of large companies pay lip service to Information Security and don't take it seriously enough. This will make sure that they do. It is good because it is not the poor customer who takes the risk when he does his shopping.

Its bad because it attacks companies for essentially being victims of crime. Not does the company suffer from the crime itself but it suffers from the after effects of the crime.

On the other hand, (I think we are up to 3 by now) there is always a risk in doing business and especially a risk of crime, it has just moved online now. Companies make good profits or else they would not be doing what they are doing so they need to offset some profits into protecting themselves and their customers' information from the criminals rather than ignoring the issues and pushing the risk onto the very customers that give them money.

I guess its kinda like me locking my expensive car and keeping the keys in my pocket but borrowing a friend's cheap car and leaving it unlocked and motor running in the street because, hey, its not my car.

This law is receiving strong opposition but I think it will be passed. If it is you can bet that somehow the cost will be passed on to the customers who will pay for protecting their own information.