IT Jobs

Did you know? Techworld now offers an IT Jobs section with hundreds of jobs! Current job listings are now available for Software Developers, Web Developers, Application Engineers, Project Managers, Graduate opportunities and more. Apply for your new IT job today!

Insider data leakage

Consultancies get in on the act

Finding out your perimeter security is about as effective as a sieve is a chastening experience. Monster.com is the latest IT service company to suffer large-scale leakage of sensitive data from its disk drives. Not surprisingly the major IT consultancies are offering guidance and advice on how to deal with the data breach problem, and focusing on insider leak prevention (ILP).

Symantec and Accenture have an alliance that includes looking at ILP issues. They state, "It is hoped customers will use Accenture and Symantec's Security Transformation Services, to build and implement data security projects for organisations grappling with the increasing complexity of managing risk in their IT environment."

Both Forrester and Accenture have ILP awareness-raising efforts underway.

Forrester

Forrester has a focus on information leak prevention (ILP) with a Forrester Wave study released last year which looked at several vendors.

Thomas Raschke is a Forrester senior analyst specialising in the subject of data leakage. He views the insider threat as being serious, that is employees, people inside the perimeter, deliberately or accidentally revealing sensitive information. They may lose laptops or remove information on USB sticks. Rashke says: "it's down to users making mistakes or acting intentionally. The traditional external security focus doesn't work," as it tries to keep bad people out.

In the insider threat situation companies need to think of extrusion prevention, not intrusion prevention. He says that there have been several US start ups in the last couple of years with: "ILP products applying policies based on content and context. They aim to deny data movement in an illegitimate business context."

However, it is still very early days in this new IT product sector.

The problem is that: "You need to know what to protect in order to protect it." He says that traditionally IT data security is a security officer problem but that, in instances such the Monster one above, it rapidly becomes a CEO-level problem.

There is a difficulty in scaling the size of the problem represented by ILP. Raschke has no financial cost estimates of such data loss and says that the reputational damage can be severe. He says: "The banks can't afford it."

There is a difficulty with accepting this assertion as no authority can identify banks or other financial institutions who have lost customers in any numbers through ILP. For example, there is no evidence that Nationwide in the UK has suffered any customer loss because of its publicised data breaches. Banks are used to being resented and disliked by their customers

Apparently though, TK Maxx has suffered customer loss since its major data breach in the USA, both in its online and in its bricks-and-mortar businesses. This was a gigantic breach with 45.7 million credit and debit card details stolen from the site. However, this was due to intrusion, not internal leakage. So while ILP must be theoretically a potentially serious problem there is no reasonably satisfactory estimate of the actual size of the problem.

This point is worth bearing in mind as Raschke's prescription for dealing with it is large scale: "We're moving to putting protection around the data itself, like a wall around the data itself. ILP impacts people, processes and technology."


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Storage news

HP tool offers continous laptop backup

Set it and forget.

Intel fixes drive bricking firmware update for flash drives

Company to re-release SSD software

IBM offers Lotus Symphony on Keepod USB devices

Thin USB device uses VMware to provide secure access to the Lotus suite

Sun claims record-breaking storage array

Says Storage 7000 is fastest on the planet

Related Storage reviews



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Unlock the power of the mainframe

This whitepaper presents the notion of CICS as an integration hub based on a component-based, service-oriented architecture supporting Web services. Highlights will review the challenges and contrasted support for Web services natively in CICS.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Ride the express lane in the journey to speed ITIL adoption

Explore the challenges in making the journey to ITIL and the criteria for selecting consulting services
By following ITIL practices, your IT organisation will become more closely integrated with the business. We recommend making the journey to ITIL in a sequence of six incremental steps, the phases of which are driven through execution of a strategic transformational roadmap.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *