Showing posts with label awareness training. Show all posts
Showing posts with label awareness training. Show all posts

Wednesday, June 6, 2007

Back from the dead ... and more concerned than ever!

So this blogging is harder to keep up with than I expected. I can't believe it's June already. Let me catch you up quickly on the last month:
  • My company has gone through significant growth - our unique approach to security and risk assessments has really caught on and we're hiring people as quickly as we can find them. If you're a CISSP or have a similar background, please call me!
  • I have attended several regional trade shows and conferences over the past month. Some were security related, but most were not. As a result, I have spent a lot of time talking with people who are not "security experts".
  • I have also spent significant time speaking with IT directors and leaders in local and regional government bodies.

And after a month of talking and listening, listening and talking, here's what I see:

  • Everyone seems to accept that security issues are real and that they are at risk.
  • If you haven't been breached, the risk you're under is acceptable. I would be a rich man if only I had a dollar for every version of, "it won't happen to me" that I have heard.
  • The security threats - particularly in the area of social engineering - are becoming more prevelent and are attacking smaller and smaller organizations. I recently ran into the president of a company in rural Pennsylvania - Amish country - whose A/R person was deceived into giving away banking information. They are a 24 person company.

Folks - what's it going to take?!?! At some point, this is going to become irresponsible behavior to keep ignoring these issues. (In fact, California is currently considering forcing companies who have been breached to cover all costs for consumers and businesses who have to deal with their information being compromised)

This blog REALLY isn't intended to be a commercial for my company. But it drives me crazy that we have the resources and ability to help protect you, your company and your customers - but you won't let us. (obviously, I don't direct that to our customers - you guys I love!) :-)

I know this sounds like a rant - and it is - but it's also a plea. As a business owner, you have a responsibility to protect your customers. Do the right thing. Your I.T. people don't have the depth - trust me - they don't. It's not their fault - I'm sure they do a great job keeping the business running. But security is a full time job and they just don't have the time.

So bring in a professional organization. If you don't like me or Pervasive Solutions - no problem. I'll even recommend some others for you if you want. But find someone you can trust and have them help you. At a minimum, here are the things you should be doing every 9 - 12 months:

  • End-user security awareness training: help your employees understand the importance of security and the threats that they may face.
  • External network vulnerability assessment: find out what risks exist on your network
  • Network and server configuration assessment: help your I.T. team build security into your infrastructure instead of trying to bolt it on afterwards
  • Policy & procedure review: establish and review your security policies and procedures, both for your I.T. team and your company as a whole, to set expectations and protect the company from compliance and litigation risks

I know these may sound like a lot. But I assure you, they aren't. For only a few thousand dollars per year, you can cover 80% of your risk with just these four steps. Certainly, I would suggest that you eventually conduct complete, thorough security and compliance risk audits which will dig deep. But don't worry about that now. Just do the basics. If you do, you'll be ahead of your peers who are still burying their head in the sand.

It's like the old joke, "if we get chased by a bear, I don't have to outrun the bear - I just have to outrun you." Make your company a smaller target - sure, you'll still be a target - but there will be bigger targets all around you.

Saturday, April 21, 2007

Insurance Industry Apathy

So I attended and exhibited at I-Day this week. Buffalo, NY! Woo-hoo! Over 1,500 members of the insurance industry from upstate NY, northern Ohio and western Pennsylvania. And do you know what I came away with? The biggest lesson I learned was that the average insurance agent isn't the slightest bit concerned with the privacy and security of their clients' information. These were agents and brokers of MAJOR insurance companies - and they were neither aware of requirements like GLBA and breach notification laws, nor were they interested in learning about them.

As a consumer of both business and individual insurance policies of all sorts, I was mortified that there was such apathy concerning whether my personal information was safe.

I suppose it shouldn't be that surprising. Agents are sales people and they have one thing in mind. But they make most of their money from recurring revenue - policies that continue to renew without the agent lifting a finger. If that's the case, you would think (or at least, I would think) that the privacy of their clients' information would be important to them. Well, at least on that day, it wasn't as important to them as the bloody mary station down the hall.

During the event, I have to admit, I was more than a little annoyed by these people who seemed to care so little about their clients. But a day removed from it now, my frustration has moved from the individual agents to the companies and brokerages that they work for. It is the employer who has the responsibility to build this awareness and concern into their employees. Yes, I want my sales people spending their time selling. But there is no excuse for a large insurance company who doesn't regularly address security and compliance issues with their employees, brokers and agents.

So I petition all of you, whether you're Allstate, Farmers, Liberty Mutual, AIG, Progressive, State Farm, Nationwide, The Hartford or Geico - PLEASE take awareness more seriously. Your agents have NO IDEA what their responsibilities are. Shoot, they don't even know what threats are out there and what regulatory requirements apply to them. PLEASE help them to protect our data. PLEASE help them to CARE about protecting our data. And PLEASE do it soon. Because right now, they are prime targets for security breaches. After what I saw this week, if I was a social engineering criminal, your agents would be my first stop.

Josh

Friday, March 23, 2007

Data Leakage: How can you prevent it?

Would it surprise you if I told you that far more than 50% of all security breaches stem from internal sources? It's true. At the end of the day, your employees pose far greater risks to your security than do any external risks.

If you are anything like most of the business owners I speak to, you're thinking, "Not MY employees. I can trust my team." Of course you can trust your team - to a point. But the fact of the matter is that security holes and breaches occur primarily due to lapses in good security practices by company employees.

Sometimes these are malicious acts, but most often, they are accidental. They come from the receptionist who leaves his password on a sticky-note under his mouse pad ... or the software engineer who leaves her laptop in the back of her unlocked car while she runs into the supermarket ... or the executive who emails files with sensitive information to her home email address so she can be productive over the weekend.

Now ask yourself again - could any of these situations happen to you?

"Data leakage" is the industry term that is used to describe these types of breaches. While you and your employees may not realize that you're doing anything dangerous, your company's and clients' data is exposed. As a business owner, you have a responsibility under law (and general ethical behavior) to adequately protect your sensitive data. So how can you prevent data leakage?

Awareness
The most important aspect to preventing data leakage is training your employees regarding behaviors that could lead to leaks. Proper training will help employees to:
  • Understand how leaks occur
  • Internalize how those leaks create risk for the company, their clients and themselves
  • Accept responsibility for preventing leaks from their own behavior and helping other employees to avoid risky behavior as well
  • Alert appropriate management should they identify potential data leaks, whether malicious or accidental

This training is necessary for ALL employees - not just your IT team. Whether they work on the loading docks, in a cube or in the corner office, each of your employees can help protect the company from data leakage.

Technology
While training is the most important aspect of preventing data leakage, there are technology solutions that can help:

  • Email Controls. These solutions include limiting outgoing attachment sizes, lexicons that analyze outgoing email for confidential information and email encryption tools. The point is, most email traffic is inherently insecure. So the first step is to limit the sending of confidential data to a bare minimum, and second, to protect that data as it is sent.
  • Device Controls. Often times, malicious data leakage occurs when an employee downloads confidential data to an easily transportable device - like a USB key drive. Your IT administrators can regulate use of these devices to prevent such incidents from occurring.
  • Data Controls. Most importantly, your confidential data should only be accessible by employees who MUST have access to it - and then they should only have access to the specific data that they need. Too often, we discover databases and systems where people throughout the organization are given carte blanche permissions to access anything and everything. You should be regularly reviewing who has access to what resources and whether they still require such access.

Policies & Procedures
Finally, you need to establish a documented set of security policies and procedures. This should be a comprehensive collection of materials that establish the do's and don't's for how your employees treat confidential materials. Documenting these policies and making them available to your employees accomplishes several key goals:

  • You underscore to your employees how critical security issues are to the business and set a consistent expectation for employee behavior
  • You provide an easily accessible resource should an employee have a question - this is especially important following the awareness training described above
  • You create a document trail that protects you from some liability in the event that an incident occurs and provides a basis for employee discipline when necessary

Data leakage has injured many, many companies - from Fortune 500 enterprises to 5-person financial advisers and physician practices. It's not expensive to protect yourself - it just requires a commitment on your part, some hard work and, for many mid-size companies, the assistance of a knowledgeable advisor. If you feel your company may be at risk, send me an email and we can talk further about steps you can take to protect yourself.

Josh